Articles
Perspectives on secure-by-design OT cybersecurity, the IEC 62443 lifecycle, and bringing design-time rigour to power-systems engineering.
The compliance product is now the regulated product
Secure remote-access appliances are standard equipment on renewable sites, sold on what they do for the asset owner's NIS2 position. The Cyber Resilience Act changed what they are: product boundary, manufacturer status, Class I versus Class II, third-party components, support periods, and the Article 14 reporting duty that is already in force.
Read articleEngineering cybersecurity into the smart grid
Secure-by-design network engineering for substations, solar, wind, BESS and DER: zones and conduits, the digital point of connection, control fan-out, timing budgets a protection engineer will accept, and the chain from requirement to evidence.
Read articleYour security architecture should outlive your security vendor
Why Synapse ships a vendor-neutral interchange layer — a CycloneDX HBOM of your IEC 62443 design — before any single-vendor integration. Design-time versus runtime, as-designed versus as-built, and the case for portability.
Read articleWhat is design-time cyber engineering?
Runtime OT security tools tell you what you already have and what's already wrong. Design-time cyber engineering asks whether the architecture is defensible before it is built: the discipline, what it produces, and why NIS2 makes it unavoidable.
Read articleFrom a messy walkdown to a defensible IEC 62443 design — in two minutes
How we built Synapse's onboarding: paste an OT walkdown spreadsheet and get a checked zone-and-conduit design plus a firewall rule schedule — no signup.
Read articleShifting security left: the economics of secure-by-design OT
Boehm's cost-of-change curve applied to OT — why the cheapest place to fix a network-security flaw is the place it never gets built.
Read article