Skip to content
Amar JanduArchitecture

Critical Infrastructure · OT / SCADA · AI Security

Architecture for systems that cannot fail quietly.

Bridging electrical engineering and enterprise security architecture: designing and delivering national grid intelligence, AI security for operational technology, OT/SCADA security and cloud infrastructure for national-scale critical infrastructure, where availability is a public safety obligation.

  • CISSP
  • ISA/IEC 62443
  • AAISM
  • TOGAF

01: Mandate

Design authority across domains usually split between four architects.

Cloud platform, OT/SCADA security, on-premises infrastructure and cyber governance: held as a single accountable scope at a national energy market operator, under SOCI Act, AESCSF, ASD Essential 8, ISM, IRAP and NIST CSF obligations.

  • D1

    OT/SCADA & Grid Intelligence

    Agent-based intelligence architecture for OT field networks: securing AI/ML-driven anomaly detection integrated with Azure/Edge cloud infrastructure.

  • D2

    AI security in OT

    Agent-based intelligence and AI/ML anomaly detection introduced into national-scale OT field networks without compromising determinism, control-plane integrity or real-time throughput.

  • D3

    Critical infrastructure

    Architectural controls shaped by safety constraints and operational volatility across energy, utilities, and defence sectors.

  • D4

    Cloud governance at scale

    Enforceable guardrails across multi-account and multi-subscription estates: Azure and AWS at sovereign and regulated scale.

All six domains →

02: AI security in OT

Bringing AI into national grid operations without giving it the controls.

Agent-based grid intelligence across a national energy market's OT field networks: AI/ML anomaly detection integrated with Azure IoT Edge and cloud infrastructure, without compromising determinism, control-plane integrity or real-time throughput. The intelligence layer is designed to see everything and change nothing.

Key decisions

  1. 01

    Agent-based architecture scoped to observation and anomaly detection: no control plane write access from intelligence layer.

  2. 02

    Azure IoT Edge deployed at field network boundaries: local inference with selective cloud telemetry to preserve latency and sovereignty requirements.

  3. 03

    IEC 62443 zone and conduit model applied to AI/ML integration points, treating intelligence pipelines as new attack surfaces requiring explicit boundary controls.

  4. 04

    Purdue model assessed and adapted for cloud-connected OT: hybrid architecture acknowledging where the traditional model breaks down at scale.

  5. 05

    Security zoning designed for assured degradation: loss of intelligence capability must not impair core grid operations.

Further

04: Standards

Designed against the frameworks the regulator will actually ask about.

  • ISA/IEC 62443

    The international series for industrial automation and control system security.

  • NIST SP 800-82

    NIST's guide to operational technology security.

  • AESCSF

    The Australian Energy Sector Cyber Security Framework.

  • SOCI Act

    Security of Critical Infrastructure Act 2018 and its risk management program obligations.

  • ISM

    The Australian Government Information Security Manual.

  • NIST CSF

    The NIST Cybersecurity Framework.

All 10 standards, and how each is applied →

05: Writing

Long-form essays on security architecture for critical infrastructure.

  • 20 minutes

    The Holy Grail of Zero Trust in a Hybrid IT OT Environment

    Which zero trust principles survive contact with operational technology, and which will break your control systems if you apply them. Identity, segmentation and encryption reconsidered for hybrid IT/OT estates.

  • 20 minutes

    Challenges in a World of Machine Learning and AI

    Adversarial machine learning meets industrial control. Training-time poisoning, inference-time evasion and model extraction against OT anomaly detection, with the architectural and operational controls that build in robustness.

  • 20 minutes

    Edge Security and the Challenges of the Energy Transition

    The traditional grid had thousands of controllable assets; the smart grid has millions. Securing distributed energy resources, virtual power plants and edge devices at a scale the existing security architecture was never designed for.