Skip to content
Amar JanduArchitecture

About

Enterprise architecture, from the plant floor up.

I work at the intersection of enterprise architecture and operational infrastructure: the place where a decision made in a cloud landing zone eventually reaches a programmable logic controller, and where the assumptions of enterprise IT stop being harmless.

My background is in electrical engineering, and I came to security architecture through operational technology rather than the other way around. That order matters. It is the difference between treating a control system as an unusually stubborn server and understanding it as the thing standing between a physical process and an uncontrolled failure.

Most of my work has been in energy, manufacturing and mining, with further programmes in regulated health, financial services and a massively multiplayer online game platform. The common thread is consequence: environments where architecture carries regulatory and operational weight, and where availability is a public safety obligation rather than a service-level target.

Increasingly, that work is about AI. I have designed agent-based grid intelligence for a national energy market (AI/ML anomaly detection running across OT field networks, integrated with edge and cloud infrastructure), and the hard part was never the model. It was keeping the intelligence layer on the right side of the control boundary, treating every AI integration point as a new attack surface under ISA/IEC 62443, and making sure that when the AI fails, the grid does not notice.

How I work

  • P1

    Consequence before likelihood

    In critical infrastructure the question is not how probable an event is, but what it does when it happens. Threat models that rank by likelihood alone under-weight exactly the scenarios that matter most.

  • P2

    The first six months decide the next twenty years

    Architectural decisions taken early in a modernisation programme determine the security posture of the resulting system for its entire service life. Those decisions are too often made before a security architect is in the room.

  • P3

    Availability is a safety obligation

    OT inverts the enterprise priority order. A control system going offline is not lost productivity; it can mean uncontrolled pressure in a pipeline or failed protection logic at a substation. The architecture has to reflect that inversion, not tool around it.

  • P4

    Design for assured degradation

    Systems fail. What matters is whether they fail inside a boundary you chose. Loss of an intelligence or analytics capability must never impair the core operation it observes.

  • P5

    AI earns its place in OT narrowly

    Machine learning belongs where it demonstrably beats simpler methods (anomaly detection, predictive maintenance) and never with write access to the control plane. The model itself is a new attack surface, and has to be threat-modelled as one.

Sectors

Energy
National energy market operations: electricity dispatch and gas markets, agent-based national grid intelligence, and the OT field networks underneath them.
Mining
Autonomous haulage and rail monitoring at major operations, where IT/OT separation is a safety control before it is a security one.
Health
Regulated digital health platforms and large-scale public health transformation, with security and governance alignment as delivery constraints.
Financial services
Cross-border acquisition integration and regulated transformation: control convergence across jurisdictions.
Online games (MMO)
Principal architecture for a massively multiplayer online game: a persistent, real-time world under unpredictable load, with payments and partner integrations inside the security boundary.

The programme record →

Credentials

  • CISSP Certified Information Systems Security Professional ISC²
  • ISA/IEC 62443 ISA/IEC 62443 Cybersecurity Expert ISA
  • AAISM Advanced in AI Security Management ISACA
  • TOGAF The Open Group Architecture Framework The Open Group

Designed against

  • ISA/IEC 62443
  • NIST SP 800-82
  • AESCSF
  • SOCI Act
  • ISM
  • ASD Essential Eight
  • IRAP
  • NIST CSF
  • NIST SP 800-53
  • NIST SP 800-207

How each standard is applied →