Critical Infrastructure · OT / SCADA · AI Security
Architecture for systems that cannot fail quietly.
Bridging electrical engineering and enterprise security architecture: designing and delivering national grid intelligence, AI security for operational technology, OT/SCADA security and cloud infrastructure for national-scale critical infrastructure, where availability is a public safety obligation.
01: Mandate
Design authority across domains usually split between four architects.
Cloud platform, OT/SCADA security, on-premises infrastructure and cyber governance: held as a single accountable scope at a national energy market operator, under SOCI Act, AESCSF, ASD Essential 8, ISM, IRAP and NIST CSF obligations.
-
OT/SCADA & Grid Intelligence
Agent-based intelligence architecture for OT field networks: securing AI/ML-driven anomaly detection integrated with Azure/Edge cloud infrastructure.
-
AI security in OT
Agent-based intelligence and AI/ML anomaly detection introduced into national-scale OT field networks without compromising determinism, control-plane integrity or real-time throughput.
-
Critical infrastructure
Architectural controls shaped by safety constraints and operational volatility across energy, utilities, and defence sectors.
-
Cloud governance at scale
Enforceable guardrails across multi-account and multi-subscription estates: Azure and AWS at sovereign and regulated scale.
02: AI security in OT
Bringing AI into national grid operations without giving it the controls.
Agent-based grid intelligence across a national energy market's OT field networks: AI/ML anomaly detection integrated with Azure IoT Edge and cloud infrastructure, without compromising determinism, control-plane integrity or real-time throughput. The intelligence layer is designed to see everything and change nothing.
Key decisions
-
Agent-based architecture scoped to observation and anomaly detection: no control plane write access from intelligence layer.
-
Azure IoT Edge deployed at field network boundaries: local inference with selective cloud telemetry to preserve latency and sovereignty requirements.
-
IEC 62443 zone and conduit model applied to AI/ML integration points, treating intelligence pipelines as new attack surfaces requiring explicit boundary controls.
-
Purdue model assessed and adapted for cloud-connected OT: hybrid architecture acknowledging where the traditional model breaks down at scale.
-
Security zoning designed for assured degradation: loss of intelligence capability must not impair core grid operations.
Further
03: Programs
Scale, authority and outcomes. Details abstracted where sensitivity applies.
-
Autonomous Operations: Rail & Haulage
Safety-critical IT/OT security architecture across autonomous haulage and rail monitoring systems at major mining operations: OT field network security, ICS boundary controls, and remote access architecture.
-
National Infrastructure Assurance
Full-stack security architecture across cloud, OT, and on-premises infrastructure for a national critical infrastructure operator: SOCI Act, ASD Essential 8, IRAP, and NIST CSF aligned.
-
MMO Platform: Persistent Online World
Principal architecture for a massively multiplayer online game: a persistent, real-time world under unpredictable load, spanning cloud infrastructure, security architecture, payments and complex partner integrations.
-
Digital Health Outcomes Platform
Regulated digital health platform spanning cloud foundations, security posture, and NHS-aligned integration constraints.
04: Standards
Designed against the frameworks the regulator will actually ask about.
-
The international series for industrial automation and control system security.
-
NIST's guide to operational technology security.
-
The Australian Energy Sector Cyber Security Framework.
-
Security of Critical Infrastructure Act 2018 and its risk management program obligations.
-
The Australian Government Information Security Manual.
-
The NIST Cybersecurity Framework.
05: Writing
Long-form essays on security architecture for critical infrastructure.
-
The Holy Grail of Zero Trust in a Hybrid IT OT Environment
Which zero trust principles survive contact with operational technology, and which will break your control systems if you apply them. Identity, segmentation and encryption reconsidered for hybrid IT/OT estates.
-
Challenges in a World of Machine Learning and AI
Adversarial machine learning meets industrial control. Training-time poisoning, inference-time evasion and model extraction against OT anomaly detection, with the architectural and operational controls that build in robustness.
-
Edge Security and the Challenges of the Energy Transition
The traditional grid had thousands of controllable assets; the smart grid has millions. Securing distributed energy resources, virtual power plants and edge devices at a scale the existing security architecture was never designed for.