Enterprise security tooling assumes it can scan aggressively and patch on a schedule. Control networks do not allow either. Our security practice works within those constraints instead of against them.
Where we start
- Passive asset discovery, which does not put traffic onto fragile equipment
- A current-state assessment mapped to IEC 62443-2-1 and 62443-3-3
- A prioritised remediation plan with an owner and a date against each item
What we build
- Network segmentation between enterprise, operations and control zones, with documented conduits
- Monitoring tuned to industrial protocols, so an engineering change is not reported as an intrusion
- Secure remote access for vendors, with session recording and time-bound approval
- Incident response runbooks written for the plant, and rehearsed with the people who would use them
Certification
Meridian's security practice is certified to IEC 62443-2-4. Our assessment reports are written to stand up to a regulator or an insurer, and we will say plainly when a finding cannot be remediated without a production outage.