CISO

OT Cybersecurity for 
Energy Sector

Secure operational technology, industrial control systems, and SCADA environments across energy operations. Red Piranha protects critical energy assets in Australia and worldwide.


Australian Sovereign SOC

IEC 62443-aligned governance

CIRMP & AESCSF SP2 uplift

Trusted by energy, utilities & renewable operators

OT-ALIGNED CISO

Why OT Operators Need an OT-Aligned CISO

Operational Technology environments face cyber physical risks that traditional IT governance cannot address. As energy and critical infrastructure operators move toward digitalisation and renewable integration, the need for specialised OT cybersecurity leadership becomes critical.

Red Piranha’s methodology starts with scoping; defining system boundaries, critical assets, and trust zones. We collect business and risk context, build asset inventories, map network segmentation, and assess protocol traffic. This structured approach ensures CIRMP uplift and AESCSF SP2 compliance are grounded in real operational risk, not just technical alerts.

Our OT‑aligned CISO (vCISO or eCISO™) leads this scoping process by:

  •  Translating business risk - Guiding you to prioritise high‑consequence processes (breaker control, turbine management, chemical dosing) over low‑impact noise.
  •  Driving governance alignment - Showing how scoping outputs map directly into CIRMP, AESCSF SP2, and IEC 62443 frameworks.
  •  Overseeing asset & protocol inventories - Helping you validate completeness and address insecure traffic (Modbus, DNP3, MQTT, Profinet, EtherNet/IP).
  •  Managing vendor & third‑party pathways - Guiding secure remote access governance with MFA, jump servers, and session recording.
  •  Ensuring incident response readiness - Embedding playbooks, SOC monitoring, and isolation authority into your maturity baseline.


By guiding you through scoping within the CISO governance model, Red Piranha ensures operators gain a defensible, audit‑ready foundation for compliance uplift and resilience.

Our OT‑focused CISO services provide:


Governance aligned to CIRMP, AESCSF SP2, and IEC 62443

Support for solar, wind, battery, and inverter‑based renewable systems

Evidence‑based compliance uplift

Unified oversight across IT, OT, SCADA, and field systems

OT risk management and segmentation assurance
looks_one

Autonomous fleets and wireless networks

Autonomous haulage, autonomous drilling, and tele remote loading depend entirely on radio and positioning. Interference, jamming, authentication, and spoofing are safety events, not just IT events.

looks_two

Remote operations centre risks

One centre can control many sites across several jurisdictions. That is one compromise with the reach of a whole portfolio, plus a permanent high trust link into every site.

looks_3

Vendor access is the front door

Mills, crushers, drives, analysers and fleet systems are supported through standing vendor tunnels. Shared credentials, no session recording and offshore access are now named regulatory risks.

looks_4

Legacy plant cannot be patched

Control systems are specified with the mine plan and run for decades. Agents will not install; scanning is unsafe, and a patch window costs more than most security budgets.

looks_5

Safety controls are reachable

Ventilation on demand, gas monitoring, hoisting, conveyor interlocks, dewatering and tailings instrumentation are all networked. A cyber event that defeats a safety control is a work health and safety failure.

looks_6

Nobody can see the estate

Brownfield sites and acquisitions arrive with unknown OT. Without an accurate asset inventory you cannot segment, cannot isolate, cannot rebuild and cannot evidence anything to a regulator.

COMPLIANCE AND RESILIENCE IN MINING CYBERSECURITY

The rules that apply to your mining operations

Mining is not one of the eleven critical infrastructure sectors named in the SOCI Act. Most large miners are regulated anyway; through the assets they own. Scope the assets, not the industry code, and the obligations become clear.

AUSTRALIA
SOCI Act and the asset test

Critical ports, critical freight infrastructure such as private heavy haul rail, critical freight services, critical electricity, gas and liquid fuel assets, and critical water assets. Own one and you are a responsible entity.

AUSTRALIA
Enhanced CIRMP Rules 2026

In force from 10 June 2026 across nine high risk asset classes. Six of them are commonly held by miners. Deadlines fall on 10 June 2027 and 10 June 2028.

AUSTRALIA
Cyber Security Act 2024

Ransomware and extortion payments must be reported to the Australian Signals Directorate within 72 hours. Critical infrastructure entities are in scope regardless of turnover.

AUSTRALIA
ASD OT principles and CI Fortify

Six principles for OT cybersecurity, plus the expectation that vital OT can be isolated for three months and rebuilt quickly. Both shape architecture, not paperwork.

GLOBAL OT
IEC 62443

Zones, conduits and target security levels across 62443-2-1, 3-2, 3-3, 4-1, and 4-2. The engineering standard underneath every regime on this page is important.

WORK SAFETY
Mine safety law

Principal hazard management plans and mechanical and electrical engineering control plans require safeguard reliability. A defeated control system is a safety failure in NSW, WA and Queensland.

What changed on 10 June 2026, and what it means at site

New obligation
Due
What it means on a mine site
Cyber framework uplift
10 Jun 2028
Move to ISO/IEC 27001:2023, Essential Eight Maturity Level 2, NIST CSF 2.0, C2M2 MIL 2 or AESCSF Security Profile 2. IEC 62443 carries the OT estate as the documented equivalent.
Network segregation
10 Jun 2028
Critical systems must keep running for at least three months while everything else is restored. Site autonomy becomes an architecture requirement.
Phishing resistant MFA
10 Jun 2028
Central logging and monitoring on every path into control systems, including vendor and remote operations centre access.
Legacy, patching and AI risk
10 Jun 2027
Unpatched systems, end-of-life plant and emerging technology must be named and managed as material risks.
Offshore and remote access
10 Jun 2027
Remote access to critical components, and offshore storage of schematics, geospatial data and configuration, are now express material risks.
Critical worker vetting
10 Jun 2028
AusCheck or NV1 for critical workers with five yearly re checks. A real program across a fly in fly out and contractor heavy workforce.
Supply chain and FOCI
10 Jun 2028
Map major suppliers and critical components. Assess foreign ownership, control and influence, sanctions and supplier access to the asset.

THE RED PIRANHA SOLUTION

Operational Technology and Industrial Control System Security solutions for mining

Red Piranha aligns OT security, ICS security, and SCADA security with the operational reality of a working mine. Crystal Eye delivers controls, telemetry and evidence, from pit to port.

OT and ICS Visibility & Industrial Control System Security

Identify and monitor industrial assets across the fleet, plant, rail, and port.

Red Piranha delivers OT and ICS visibility, network segmentation, and Critical Infrastructure Protection controls that meet SOCI Act and IEC 62443 obligations.

Network Segmentation

Crystal Eye security zones separate IT and OT networks. Conduits reduce lateral movement between autonomous fleet, processing plant control and corporate systems.

Crystal Eye PECA (Passive Encryption Control Application) delivers passive asset management and Zero Trust zoning, aligned to IEC 62443, solving OT device lifecycle challenges without disrupting production.

Threat Detection and Response

Crystal Eye delivers Threat Detection, Investigation and Response (TDIR) across OT and SCADA traffic. Anomalies on the mine network are caught and contained fast.

24/7 Security Operations Centre

A 24/7 security operations centre watches your environment across every site. Sovereign Australian analysts triage, investigate and escalate.

Vulnerability Management

Identify and prioritise vulnerabilities across critical mining systems. Track treatment to reduce exposure over time and produce the evidence your CIRMP annual report needs.

Secure Remote Access

Protect contractors, vendors, and remote operators. Crystal Eye supports controlled VPN access into OT zones, backed by Post-Quantum Cryptography (PQC) ready SD-WAN for secure connectivity to remote sites.

Awareness and Training

Strengthen cyber resilience across operational teams. Reduce human risk in the field, in the control room, and at the remote operations centre.

Managed Detection and Response

MDR for OT combines monitoring, threat intelligence and response. Threats against mining operations are found and contained quickly.

Crystal Eye Platform

Crystal Eye unifies Threat Detection, Investigation and Response (TDIR), segmentation, VPN, and reporting in one platform. It is the control and evidence engine for mining security.

REFERENCE ARCHITECTURE: IEC 62443 FOR MINING OPERATIONS

From pit to port, mapped to zones and conduits

IEC 62443 assumes a fixed plant. A mine does not stand still. Red Piranha models the mobile fleet as its own zone with the wireless network as its conduit, then assigns target security levels from safety and production consequence rather than from network position.

ZONE 01
Autonomous fleet
and wireless
ZONE 02
Processing plant
control
ZONE 03
Mine services and
safety
ZONE 04
Tailings and
water
ZONE 05
Rail, port and
power
ZONE 06
Remote operations
centre and IT
Autonomous haulage and drilling

Tele remote loading

Private LTE, Wi Fi, positioning

Collision avoidance
Crushing, milling, flotation

DCS, PLC and historian

Analysers and weightometers

Engineering workstations
Ventilation on demand

Gas monitoring and dewatering

Hoisting and winding

Safety instrumented systems
TSF instrumentation

Piezometers and telemetry

Pumping and pipelines

Borefield and desalination
Heavy haul rail signalling

Train control and load out

Shiploaders and stackers

Generation, solar and storage
Fleet management systems

Short interval control

Corporate identity and cloud

Vendor and OEM support

The conduit rule. Every link between these zones is a controlled conduit, enforced at both ends. Production telemetry, condition monitoring, and reporting flow outward only. Nothing needs to reach inward to read from a plant. Each site holds local identity, local historian and local time so it can keep producing when the link to the remote operations centre is cut. That is how the three-month isolation requirement is met in practice.

DEFENCE IN DEPTH: OT SECURITY ARCHITECTURE

OT security architecture for mining

Red Piranha secures every layer from the corporate network to the equipment in the pit. Monitoring, detection, segmentation, threat intelligence and incident response wrap each zone.


Applied at every layer
Monitoring
Detection
Segmentation
Threat intelligence
Incident response
Crystal Eye


Every zone and conduit is monitored, segmented and defended.
Crystal Eye maps directly to IEC 62443 zones, conduits and target security levels, from the corporate network to the pit floor.

WHERE IT APPLIES

Built for every part of the mining value chain

The Red Piranha Difference

CIRMP run as a living assurance program

Compliance is not a paper exercise. Red Piranha operates CIRMP as a continuous program. IEC 62443 shapes the OT architecture. Crystal Eye produces the evidence. The board gets an attestation it can actually stand behind.

1DefineLegal scoping per asset and per jurisdiction. Identify critical components and critical workers.
2AssessHazard workshops across cyber, personnel, supply chain and physical risk. Maturity review against the chosen framework.
3DesignZone and conduit model, target security levels, isolation points and a graduated isolation plan.
4DeployCrystal Eye at boundaries, PECA on legacy plant, DAS for access, CEASR on endpoints. Observe, simulate, enforce.
5Operate24/7 SOC cadence, detection tuning, threat hunting, exercises against the 12- and 72-hour reporting clocks.
6AssureAnnual report evidence, independent assurance readiness and a board pack that survives a regulator audit.

WHY RED PIRANHA

A sovereign partner built for high consequence operations

Sovereign by design

Australian owned, Australian developed and Australian hosted, with an Australian SOC. Data sovereignty is a control, not a marketing line, and offshore access is now an express regulatory risk.

We build the full stack

Red Piranha controls the platform end to end, so there is no integration overhead and no bolt on tools. The system generating the events is the system investigating them.

Certified and connected

ISO/IEC 27001 certified, CREST ANZ Member Company, Official Cyber Threat Alliance Member and Team Defence Australia member.

brightness_5

Built for remote sites

Detection continues when the satellite or microwave link drops. Local monitoring does not depend on a central server to keep working.

Evidence that lasts

Log retention of 18 months out of the box, meeting and exceeding ASD guidance, with forensic packet capture on demand for investigations and audits.

Lower total cost

One vendor, one licence model and predictable budget. Achieve more security outcomes with a lower total cost of ownership and no half executed deployment.

Find out where your mine actually stands

Book an OT security assessment. We scope your regulated assets, inventory the OT estate,
map it to IEC 62443 zones and show you exactly what has to be true by 10 June 2027 and 10 June 2028.