Capability
Architecture Domains
Domains represented through recurring responsibilities and decision patterns across programmes, rather than a list of technologies.
Specialist depth
OT/SCADA security & Grid Intelligence architecture
- Agent-based intelligence architecture for OT field networks: securing AI/ML-driven anomaly detection integrated with Azure/Edge cloud infrastructure.
- Security zoning, network segmentation, and OT/IT boundary controls for national-scale energy market and grid operations systems.
- IEC 62443 zone and conduit design, Purdue model assessment, and cloud-connected OT architecture patterns for distributed field networks.
- Threat modelling and architectural controls for SCADA, EMS, DCS, and AMI environments under operational volatility and real-time availability constraints.
Specialist depth
AI security in OT & national infrastructure
- Agent-based intelligence and AI/ML anomaly detection introduced into national-scale OT field networks without compromising determinism, control-plane integrity or real-time throughput.
- Intelligence layers scoped to observation (no control-plane write access) and designed for assured degradation, so loss of AI capability never impairs core grid operations.
- ISA/IEC 62443 zone and conduit models extended to AI/ML integration points, with edge inference and selective cloud telemetry to preserve latency and sovereignty.
- Adversarial ML threat modelling for OT (training-data poisoning, inference-time evasion, model extraction), countered with ensemble detection, physics-informed constraints and cryptographic data provenance.
- AI governance for operational technology aligned to AAISM, alongside model endpoint, pipeline and vector store security for enterprise AI systems.
Regulated operations
Critical infrastructure & safety-adjacent systems
- Architectural controls shaped by safety constraints and operational volatility across energy, utilities, and defence sectors.
- Segmentation patterns supporting containment, assured degradation, and OT/IT boundary enforcement.
- Assurance of telemetry, incident response pathways, and governance enforcement under SOCI Act and critical infrastructure obligations.
- Risk framing suitable for executive and regulator-facing contexts: NIST CSF, ASD Essential 8, IRAP, and IEC 62443 aligned.
- Post-quantum cryptography migration planning for critical infrastructure: NIST FIPS 203/204/205 aligned architecture.
Enterprise scale
Cloud governance & landing zones
- Enforceable guardrails across multi-account and multi-subscription estates: Azure and AWS at sovereign and regulated scale.
- Identity-first controls for network segmentation, encryption, and logging-by-default across hybrid and multi-cloud environments.
- Cloud Adoption Framework delivery: platform autonomy and regulatory assurance trade-offs.
- Standard patterns for onboarding regulated workloads and maintaining audit survivability under IRAP, ASD Essential 8, and SOCI Act obligations.
Control-plane design
Identity-first and zero trust security architecture
- Trust boundary definition, policy hierarchy, and least-privilege operating model across enterprise and OT environments.
- Authentication and authorisation strategy aligned to privileged access workflows in safety-adjacent and regulated contexts.
- Zero trust architecture patterns per NIST 800-207, applied across cloud, on-premises, and OT/IT convergence boundaries.
- Assurance mechanisms for critical national infrastructure under NIST CSF, ISM, and NESA IAS frameworks.
Systemic risk
Resilience, availability & failure-domain design
- Failure-mode analysis and bounded-failure architecture across critical services and national-scale infrastructure.
- Design for recoverability: backup integrity, restore time, dependency discipline, and operational continuity under uncertainty.
- Architectural patterns supporting continuity for safety-adjacent operations where availability is a public safety obligation.
- Trade-offs across cost, complexity, and operational survivability in regulated and critical infrastructure contexts.
These domains are evidenced in the programme record.