Cybersecurity, engineered for the smart grid.
Secure network validation, from requirements to report.
See how an engagement runs ↓Every assessment runs on our platform — model to evidence, in one loop
Synapse takes the engineering artefacts a project already produces — IEC 61850 SCD files, asset registers, addressing plans — together with the network and asset context that sits alongside them, and builds a vendor-neutral cyber-engineering model of the site. It identifies architecture and control gaps automatically, maps each one to a defined IEC 62443 or IEC 62351 requirement, and returns a traceable pre-FAT cybersecurity evidence pack. Proposed design changes are then tested by simulation, on a cyber range built from the same model, before anything is deployed.
The assessment partner for the teams building the grid's edge
Assessments that end in evidence, not opinion
When you outsource secure network validation to Synapse, you get a standard, repeatable engagement — not a one-off consultant's deck.
A standard, proven process
Requirements, as-found assessment, threat model, baseline, range testing, hardening plan. The same structured engagement every time — scoped in days, not months.
Platform-backed findings
Your network is modelled in our studio and checked against IEC 62443-3-3 and NIST SP 800-82 deterministically. Every finding traces to an asset, zone or conduit — and is re-runnable.
A report you can act on
The engagement returns a full report: zone/conduit diagram, asset inventory, threat model, compliance gaps and a prioritised list of hardening activities.
From diagram to enforced design
The manual pain worth automating
Segmentation work breaks down in the gap between the architecture and its enforcement — where zones, addressing and rule bases are kept in sync by hand. That is exactly the gap Synapse closes.
Zoning & security levels
Hand-deciding which assets sit at which Purdue level, then arguing the target security level zone by zone — undocumented and inconsistent between reviewers.
Place assets on the canvas; zones, conduits and SL-T are first-class and template-seeded, checked against IEC 62443-3-3 the moment you assign them.
IP & VLAN addressing plan
An addressing plan living in a spreadsheet — overlapping subnets, accidental flat networks and wrong-VLAN assignments no one catches until commissioning.
The addressing plan is part of the model. Overlaps, flat segments and mismatched VLANs surface inline, the instant they are introduced.
Conduits → rule base
Translating every conduit — “SCADA ↔ DMZ permits OPC UA / 4840” — into the real firewall rule base, switch ACLs and trunk config by hand, then keeping it in sync as the design moves.
Each conduit is least-privilege by construction: one explicit rule per permitted flow, default-deny everything else — the bridge from zones & conduits to true micro-segmentation.
How an engagement runs
One standard process, requirements to report
Every Synapse assessment follows the same six steps — so you know exactly what you're commissioning, and exactly what comes back.
Requirements
We capture your scope, operational constraints and standards obligations — the security requirements the network actually has to meet.
As-found assessment
We model your network as found — assets, flows, zones and addressing — into a structured, queryable model in the Synapse studio.
Threat modelling
We threat-model the architecture: attack paths, exposed conduits and the consequences that matter for your operation.
Security baseline
We measure the as-found network against IEC 62443-3-3 and NIST SP 800-82, and agree a defensible baseline with your team.
Cyber range testing
We replicate the network in our cyber range and put the design under test — proving which weaknesses are exploitable, not theoretical.
Hardening plan & report
You receive the full report: diagrams, inventory, threat model, gaps and a prioritised programme of hardening activities.
Prevent · detect · respond · recover
An assessment is the baseline of a management system
A report closes an engagement. A cyber security management system is what you are still accountable for in year two. We work at the prevention end — and the model we leave behind is what the other three phases get measured against.
Prevent
Zones, conduits and target security levels designed and checked before the site is built — while a fix still costs a drawing revision.
Detect
Monitoring needs something to call normal. The model hands your team an asset inventory and the exact set of flows the design permits.
Respond
Containment is a segmentation decision taken under time pressure. The conduit map says what can be cut — and what stops when you cut it.
Recover
Rebuilding needs a known-good reference. The as-designed record — addressing, VLANs, zones and conduits — is the state you restore to.
We don't run your SOC, write your incident-response plan or manage a recovery. We make the design all three depend on explicit, checkable and current.
The case for funding it
The same finding costs more every week you don't have it.
Security spend on a plant competes with generation capacity, and it doesn't win that argument on correctness. It wins on cost asymmetry: one segmentation error is worth a completely different amount depending on when someone finds it.
NIS2 removed the other half of the argument. For an essential entity the spend isn't discretionary any more, so the question stopped being whether to fund it and became when — and the cheapest when is design.
Read the cost argument in fullWhat the assessment is really buying
- Rework avoided — segmentation and addressing errors found while they are still edits, not change orders.
- Commissioning protected — the design is proven in the range before it meets a schedule that cannot move.
- Audit prepared — the evidence pack exists as a by-product of the design, instead of being assembled under deadline.
- Obligations answered — NIS2 and IEC 62443 questions answered from the model rather than from memory.
Network engineering. Validated. Secured.
What we engineer
Outsource the work to us or engage us alongside your own engineers — we design resilient utility networks, validate their performance and reduce risk, across the full communication stack of a modern power-system site.
A living model, not a picture
Explorable, structured, and always in sync.
Everything on the canvas is queryable data, not pixels. The same model powers the segmentation checks, the compliance report, and the export — so the “as-designed” record never drifts out of sync at handoff or audit.
- Assets, flows, zones and conduits as first-class entities
- IEC 61850 / 61400-25, DNP3, Modbus TCP and IEEE 2030.5 protocols
- Deterministic checks — re-run any time, identical results
The standards, encoded
Synapse models the requirement structure of the standards that govern secure power-system design — so your architecture is checkable, not just drawable.
Who it's for
One model, the whole 62443 delivery chain
Built around the Cyber Engineering Manager who owns the secure-network design — and the engineering, operations, audit and procurement roles who depend on it.
Cyber Engineering Manager
PrimaryYou own the secure-network design and you're accountable for proving it meets the standards. Synapse gives you speed, consistency, and evidence that holds up at audit — without ever leaving the canvas.
OT / Control Systems Engineer
Builds the model day to day — an intuitive canvas and reusable templates instead of Visio and spreadsheets.
Systems Integrator / EPC
Delivers DER projects against a defensible reference architecture, reused per site instead of rebuilt from scratch.
Asset Owner / Operator
Receives a clear, defensible zone-and-conduit diagram and gap report for sign-off — not the editing environment.
Compliance & Audit
Reads the 62443 coverage and gap analysis, with each control traceable to the asset, zone or conduit that satisfies it.
Procurement & Supply Chain
Acquires and validates security solutions against a clear cybersecurity requirements spec, aligned to the design.
Operations & Maintenance
Inherits an accurate as-designed record — asset inventory, addressing and conduits that don't drift out of sync.
Design together — across roles, sites and time zones
Synapse is a single shared model your whole organisation works from. Engineering, operations, audit and procurement collaborate on one source of truth — so nothing drifts, and everything is accountable.
One source of truth
The model, the checks, the report and the export all read from one structure — distributed teams never work off a stale drawing.
Roles & approvals
Editor, approver and auditor roles with a review-and-approval workflow and a recorded, timestamped sign-off.
Versioned & auditable
Every change is captured with author and timestamp — return to a safe version, compare configurations, and evidence the evolution.
Easy to use. Easy to learn. Easy to adopt across a global organisation.
Ready to validate your network — secure by design?
Tell us about the site and we'll scope the assessment: requirements, as-found review, threat model, baseline, range testing and a prioritised hardening plan — returned as one report.