ZENTARA

Industries · Energy & Critical Infrastructure

A test that trips the plant is not a test. It is the incident.

Every OT engineer has watched an IT team run a routine scan and stop a process. That memory is why security proposals stall here, and it is a rational objection rather than resistance to change. Zentara starts passive, works to your shutdown window rather than ours, and treats availability and safety as the controls that outrank everything else — because on a plant network they are.

Perpres 82/2022
Vital information infrastructure protection
Its definition of IIV names operational technology explicitly
ESDM
A designated strategic sector
Energy and mineral resources, under the ministry's responsibility
3 tiers
CSIRT structure required
National at BSSN, sectoral at the ministry, organisational at the operator
SL 0–4
IEC 62443 security levels
Set by the adversary you must withstand, not the budget you have

What we are defending

Where a security decision becomes a safety decision.

01

DCS and SCADA

The control layer. Active scanning here has knocked over controllers that were never designed to answer unexpected traffic, which is why the first pass should not touch them at all.

02

Safety instrumented systems

A different category from everything else on this list. SIS exists to put the process in a safe state, and work near it is scoped with the process safety engineer or it is not scoped.

03

The IT/OT boundary

Historian, data diode, jump host — wherever business reporting reaches into the plant. Most incidents we are asked about crossed here, not through the perimeter.

04

Vendor remote access

Siemens, ABB, Emerson, Honeywell, Yokogawa. Support demands a path in; the question is whether it is brokered, recorded and time-bound, or standing and forgotten.

05

Remote and unmanned sites

Substations, wellheads, telemetry huts. A cabinet in a field is a physical access problem before it is a network one, and nobody is watching it.

06

Legacy engineering estate

Workstations running what the OEM certified, on hardware kept alive because requalifying the replacement costs more than the plant will approve.

Instrument · Obligation · Operational outcome

Designated as vital, and expected to prove it.

Perpres 82/2022 makes ESDM a designated strategic sector and names operational technology in its own definition of vital infrastructure. That is an obligation with a coordinator, a reporting structure and a required team — not an aspiration.

Perpres 82/2022

Pelindungan IIV

Requires

Protection of vital information infrastructure — electronic systems using information and/or operational technology in strategic sectors, where disruption would seriously affect public interest, public services, defence or the national economy. BSSN coordinates; operators must stand up an organisational cyber incident response team beneath the sectoral and national tiers.

We do

Organisational CSIRT stand-up that functions on a plant schedule, and the assessment that establishes what within your estate is actually in scope.

What the operator ends up with

Operating CSIRT, scoped asset register

Perpres 47/2023

Presiden RI

Requires

National Cyber Security Strategy across eight pillars, with protection of vital information infrastructure and operational resilience among them.

We do

Resilience treated as something exercised rather than documented, with the plant's own people in the exercise.

What the operator ends up with

Tested playbooks, trained responders

IEC 62443

International

Requires

Security for industrial automation and control systems: zone and conduit architecture, and a target Security Level from SL 1 to SL 4 set by the capability of the adversary you must withstand.

We do

Zone and conduit design, target SL agreed per zone, and assessment that does not require putting traffic on a control network to reach a conclusion.

What the operator ends up with

Zone model, per-zone target SL, gap register

NIST SP 800-82

Guidance

Requires

Operational technology security guidance — the reference for method where IEC 62443 sets the architecture.

We do

Method aligned to it, with the safety and availability constraints written into the test plan rather than discovered during it.

What the operator ends up with

Documented method, agreed constraints

UU PDP

Republik Indonesia

Requires

Personal data obligations, including notification within 72 hours. Utilities hold customer records at national scale alongside the plant estate.

We do

Governance across both estates, because the customer database and the control network are almost never the same team and the clock does not care.

What the operator ends up with

DPIA records, cross-team runbook

ISO 27001

Certifiable

Requires

Information security management system covering the organisation, increasingly demanded by lenders, offtakers and joint-venture partners.

We do

Assessment and implementation scoped so the OT estate is addressed honestly rather than excluded to make certification easier.

What the operator ends up with

Certifiable ISMS with OT in scope

Security Levels · Set by the adversary

The right level is not the highest one.

IEC 62443 does something unusual among security standards: it defines its levels by who you are defending against rather than by how much control you have implemented. SL 2 protects against an intentional attack using simple means and generic skills. SL 3 assumes sophisticated means and skills specific to industrial control systems. SL 4 assumes extended resources and high motivation — a state programme. Most plant zones do not need SL 4 and pursuing it everywhere wastes budget that a genuinely exposed zone needed. The work is agreeing a target per zone and then closing to it, which is a much shorter conversation than an undifferentiated uplift.

IEC 62443 target security level

  1. 0

    SL 0 — none

    No specific security requirement stated for the zone.

  2. 1

    SL 1 — casual

    Protection against accidental or coincidental violation. A mis-keyed command, not an adversary.

  3. 2

    SL 2 — simple means

    Intentional attack using simple means, low resources, generic skills, low motivation.

  4. 3

    SL 3 — ICS-specific

    Sophisticated means, moderate resources, skills specific to control systems, moderate motivation.

  5. 4

    SL 4 — state capable

    Sophisticated means, extended resources, ICS-specific skills, high motivation.

Highlighted: SL 2 and above — where any zone carrying real process consequence has to sit.

Security Levels as defined in the IEC 62443 series

Sector threat model

  • Ransomware crossing from the business network into an estate that cannot be rebooted to recover
  • Vendor remote access, standing and unmonitored, provisioned during commissioning years ago
  • Engineering workstations on an operating system the OEM certified and nobody may patch
  • Flat plant networks where a compromise at one site reaches every other
  • Unmanned remote assets — substations, wellheads, pumping stations — with physical access and no witness
  • IT security tooling deployed into OT and causing the outage it was bought to prevent

What this sector answers to

The regulatory landscape for energy & critical infrastructure. Our own accreditations are listed on certifications.

Perpres 82/2022 — IIVPerpres 47/2023IEC 62443NIST SP 800-82 — guidanceUU PDPISO 27001

Track record

ISO 27001 assessment for listed power-generation companies; cyber-risk briefings for national energy directorates.

For mining and downstream processing

Smelters were built fast. Security was not in the commissioning scope.

Indonesia's downstream processing estate went from plan to production at remarkable speed, and OT security was rarely part of the EPC package. What exists now is a modern plant with a flat network, vendor access provisioned during commissioning and never revoked, and no asset inventory anyone trusts. That is a solvable position — but only if the assessment respects that the furnace does not stop.

  • Passive asset discovery across processing lines, delivered without a production interruption.
  • Zone and conduit design retrofitted to a plant that was not built with segmentation in mind, sequenced so each step is independently valuable.
  • Vendor and contractor access brokered, recorded and time-bound — usually the largest single risk reduction available and among the cheapest.
  • Findings written for a plant manager and an operations director, not only for a corporate CISO who has never been on the floor.

Before you have to justify us internally

Bringing in a security vendor is itself a risk you have to evidence.

So here is the answer to the questions your risk committee will ask, before they ask them.

We start passive, and often stay there

A control network can be characterised from a span port without a single packet being sent to a PLC. Most first engagements produce a full asset inventory and zone model without ever transmitting on the process network.

Nothing active without a safety case and an abort

Any test that touches production is scoped with your process safety engineer, has a named abort authority on the call, and stops the moment they say so. No exceptions for schedule.

Your shutdown window, not our calendar

Work that requires the plant down is planned around turnaround, because the alternative is asking operations to create a window that costs more than the engagement.

We will not void your OEM support

Where a change touches vendor-certified configuration we bring the OEM into the conversation rather than working around them. A finding that invalidates your support contract is not a finding you can act on.

Availability and safety outrank confidentiality

The IT priority order is inverted here and we design to the inverted one. A recommendation that improves confidentiality at the cost of availability is wrong on a plant network, whatever it scores on a framework.

The capability stays with your engineers

Plant staff know the process and we do not. The durable outcome is your control engineers able to reason about their own zones, not a report that ages until the next audit.

VAPT & Offensive Security

Penetration testing for Energy & Critical Infrastructure

28 services in the catalog apply to Energy & Critical Infrastructure — from point-in-time pentests to red team and continuous validation.

Explore all 28
Penetration Test

External Network Penetration Test

Black-box test of internet-facing assets, perimeter exposure, and exploitable services.

Penetration Test

Internal Network Penetration Test

Assumed-breach lateral movement, AD abuse, sensitive data discovery from inside.

Penetration Test

Active Directory / Entra ID Security Assessment

Kerberoasting, AS-REP, ACL abuse, BloodHound paths, hybrid identity review.

Assessment

Firewall, Router & Switch Configuration Review

Rule base hygiene, ACL drift, hardening against CIS Benchmarks.

Penetration Test

VPN Security Assessment

IKE/IPsec, SSL VPN, split tunneling, ZTNA migration readiness.

Assessment

Email & DNS Security Review

SPF/DKIM/DMARC, MTA-STS, DNSSEC, BIMI, phishing surface.

Penetration Test

Web Application Penetration Test

OWASP Top 10, business logic, authenticated/unauthenticated flows.

Assessment

Secure Code Review (Manual + SAST)

Manual review of critical flows + SAST tooling for OWASP/CWE coverage.

Securing energy & critical infrastructure?

Start with a scored maturity baseline or go straight to a specialist conversation.