Platform Architecture

Battery Cyber Control

The operational cybersecurity layer built exclusively for high-consequence critical-power environments. Operating at the boundary of digital commands and electrical energy, Battery Cyber Control unifies continuous visibility, operational risk prioritization, remote access governance, and safe incident response.

Discuss an environment Deployment Architecture
PILLAR 01

OBSERVE • Continuous Operational Visibility

Passive, non-intrusive discovery across industrial protocols, edge gateways, controller firmware, and cloud dependencies.

Passive OT & Protocol Inspection

Traditional vulnerability scanners send aggressive port probes that can crash sensitive PLCs, lock Modbus slaves, or trip protection relays. Battery Cyber Control operates strictly via passive network taps and SPAN mirrors, decoding Modbus TCP, DNP3, IEC 61850, CAN 2.0B, and SunSpec communications without injecting a single packet into active control loops.

Coverage: BMS Master/Slaves • Inverter Controllers • Station PLCs

Dynamic Communication & Topology Mapping

Automatically maps all site network conversations between SCADA servers, local HMIs, Energy Management Systems (EMS), and external destinations. Detects newly introduced engineering laptops, rogue cellular dongles, unauthorized peer-to-peer controller communications, and unplanned protocol deviations in real time.

Coverage: Inter-VLAN routing • Gateway egress • East-West telemetry

Firmware & Configuration Drift Auditing

Tracks controller firmware versions, logic builds, and operating parameter baselines across heterogeneous hardware fleets. Immediately flags firmware changes, unauthorized setpoint adjustments (e.g., changes to inverter power factor or BMS maximum cell temperature thresholds), and anomalous register writes.

Coverage: Firmware hashes • Register baseline integrity • Logic drift

Supply Chain & Cloud Exposure Discovery

Surfaces hidden outbound connections established by cellular routers, inverter maintenance agents, and OEM cloud telemetry streams. Maintains a verified register of all external endpoints communicating with site control hardware.

Coverage: OEM telemetry • Cellular gateways • Remote API endpoints
PILLAR 02

PRIORITIZE • Operational Impact Scoring

Reject meaningless vulnerability count dashboards. Prioritize engineering intervention around physical safety, dispatch availability, and thermal consequence.

Attack-Path Reachability

Evaluates vulnerabilities in context: is an exposed service on a BMS slave reachable from the corporate WAN or cellular gateway, or is it isolated behind dual-firewalled air-gap architectures? We eliminate false alarms so site engineers focus on genuine breach paths.

Physical Consequence Weighting

Risks are scored based on the physical consequences of manipulation: could an adversary alter cooling system thresholds, override battery discharge rates during peak pricing, or disable thermal runaway protection contactors?

Vendor Dependency Exposure

Quantifies the cumulative risk introduced by third-party maintenance contractors, OEM remote support agreements, and cloud dispatch aggregators, providing actionable vendor risk scores for procurement and operations teams.

PILLAR 03 • CORE DIFFERENTIATOR

GOVERN ACCESS • Remote & OEM Privilege Control

Eliminate permanent VPN tunnels, shared service account credentials, and unmonitored supplier maintenance sessions.

Just-In-Time (JIT) Ephemeral Sessions

OEMs and third-party technicians no longer receive static VPN credentials. When maintenance is required, technicians request an ephemeral, time-bounded session tied to a specific work order, approved by site operations, and automatically revoked upon completion.

• Zero standing access • Automatic credential expiry

Dual Authorization & Policy Enforcement

Privileged commands—such as firmware uploads, safety threshold modifications, or PCS parameter reconfiguration—can require explicit two-person operational approval before transmission to downstream controllers.

• Multi-tier approval • Command restriction

Protocol-Aware Session Recording

Every remote session is recorded at both the visual layer (RDP/SSH terminal recordings) and the protocol layer (decapsulated Modbus/DNP3 commands). Review exactly what register values were changed during maintenance windows.

• Full command audit • Forensic playback

Strict Least-Privilege Segmentation

A battery inverter technician only gains access to the specific PCS units being serviced, never the master EMS, the high-voltage substation switchgear, or neighboring storage blocks.

• Micro-segmented access • Zero lateral movement
PILLAR 04

RESPOND • Graceful Operational Containment

Contain cyber threats without triggering emergency shut-offs, power curtailment, or electrical instability.

Safe Cyber Containment

Isolate compromised gateways or rogue engineering workstations at the network level while keeping autonomous battery protection systems, thermal cooling, and hardwired safety interlocks operational.

Forensic Evidence Preservation

Instantly capture cryptographic snapshots of network traffic (PCAP), controller state tables, and authentication logs to support rigorous root-cause analysis and regulatory reporting.

Golden Baseline Restoration

Rapidly restore verified, digitally signed configuration baselines to PLCs and inverters following an unauthorized parameter shift, ensuring rapid return to safe commercial operation.

Enterprise Integration

Deployment Architecture & Data Boundaries

Battery Cyber Control operates within strict critical-infrastructure constraints. We support hybrid and air-gapped architectures where operational telemetry remains entirely under customer control.

Architecture Element Deployment Model Operational Impact Customer Data Boundary
Site Passive Sensor Hardware 1U / DIN-rail appliance or virtual collector deployed at local switch SPAN/TAP ports Zero packet injection; optically isolated RX-only physical taps ensure 0% risk of bus disruption 100% on-premises; decodes industrial packets locally
Control Plane & Analytics Customer-dedicated Cloudflare Worker / Enterprise Edge or on-premises management cluster Zero impact on real-time sub-second control loops (Modbus/CAN executed locally) Telemetry metadata only; customer retains ownership and cryptographic keys
Outbound Connectivity Unidirectional mTLS over dedicated cellular / satellite or customer-managed DMZ No inbound firewall ports required; zero external listen sockets on site edge All egress traffic encrypted with customer-held certificate authorities
Access Gateway Hardened bastion with hardware MFA and ephemeral session proxying Eliminates direct technician access to controller subnets; transparent to vendor tools Complete session video and protocol logs stored in customer storage bucket

Ready to evaluate Battery Cyber Control on your site?

We conduct architecture reviews and passive pilot deployments on grid-scale BESS and data center facilities.

Discuss an environment