Platform Architecture
Battery Cyber Control
The operational cybersecurity layer built exclusively for high-consequence critical-power environments. Operating at the boundary of digital commands and electrical energy, Battery Cyber Control unifies continuous visibility, operational risk prioritization, remote access governance, and safe incident response.
OBSERVE • Continuous Operational Visibility
Passive, non-intrusive discovery across industrial protocols, edge gateways, controller firmware, and cloud dependencies.
Passive OT & Protocol Inspection
Traditional vulnerability scanners send aggressive port probes that can crash sensitive PLCs, lock Modbus slaves, or trip protection relays. Battery Cyber Control operates strictly via passive network taps and SPAN mirrors, decoding Modbus TCP, DNP3, IEC 61850, CAN 2.0B, and SunSpec communications without injecting a single packet into active control loops.
Coverage: BMS Master/Slaves • Inverter Controllers • Station PLCsDynamic Communication & Topology Mapping
Automatically maps all site network conversations between SCADA servers, local HMIs, Energy Management Systems (EMS), and external destinations. Detects newly introduced engineering laptops, rogue cellular dongles, unauthorized peer-to-peer controller communications, and unplanned protocol deviations in real time.
Coverage: Inter-VLAN routing • Gateway egress • East-West telemetryFirmware & Configuration Drift Auditing
Tracks controller firmware versions, logic builds, and operating parameter baselines across heterogeneous hardware fleets. Immediately flags firmware changes, unauthorized setpoint adjustments (e.g., changes to inverter power factor or BMS maximum cell temperature thresholds), and anomalous register writes.
Coverage: Firmware hashes • Register baseline integrity • Logic driftSupply Chain & Cloud Exposure Discovery
Surfaces hidden outbound connections established by cellular routers, inverter maintenance agents, and OEM cloud telemetry streams. Maintains a verified register of all external endpoints communicating with site control hardware.
Coverage: OEM telemetry • Cellular gateways • Remote API endpointsPRIORITIZE • Operational Impact Scoring
Reject meaningless vulnerability count dashboards. Prioritize engineering intervention around physical safety, dispatch availability, and thermal consequence.
Attack-Path Reachability
Evaluates vulnerabilities in context: is an exposed service on a BMS slave reachable from the corporate WAN or cellular gateway, or is it isolated behind dual-firewalled air-gap architectures? We eliminate false alarms so site engineers focus on genuine breach paths.
Physical Consequence Weighting
Risks are scored based on the physical consequences of manipulation: could an adversary alter cooling system thresholds, override battery discharge rates during peak pricing, or disable thermal runaway protection contactors?
Vendor Dependency Exposure
Quantifies the cumulative risk introduced by third-party maintenance contractors, OEM remote support agreements, and cloud dispatch aggregators, providing actionable vendor risk scores for procurement and operations teams.
GOVERN ACCESS • Remote & OEM Privilege Control
Eliminate permanent VPN tunnels, shared service account credentials, and unmonitored supplier maintenance sessions.
Just-In-Time (JIT) Ephemeral Sessions
OEMs and third-party technicians no longer receive static VPN credentials. When maintenance is required, technicians request an ephemeral, time-bounded session tied to a specific work order, approved by site operations, and automatically revoked upon completion.
• Zero standing access • Automatic credential expiryDual Authorization & Policy Enforcement
Privileged commands—such as firmware uploads, safety threshold modifications, or PCS parameter reconfiguration—can require explicit two-person operational approval before transmission to downstream controllers.
• Multi-tier approval • Command restrictionProtocol-Aware Session Recording
Every remote session is recorded at both the visual layer (RDP/SSH terminal recordings) and the protocol layer (decapsulated Modbus/DNP3 commands). Review exactly what register values were changed during maintenance windows.
• Full command audit • Forensic playbackStrict Least-Privilege Segmentation
A battery inverter technician only gains access to the specific PCS units being serviced, never the master EMS, the high-voltage substation switchgear, or neighboring storage blocks.
• Micro-segmented access • Zero lateral movementRESPOND • Graceful Operational Containment
Contain cyber threats without triggering emergency shut-offs, power curtailment, or electrical instability.
Safe Cyber Containment
Isolate compromised gateways or rogue engineering workstations at the network level while keeping autonomous battery protection systems, thermal cooling, and hardwired safety interlocks operational.
Forensic Evidence Preservation
Instantly capture cryptographic snapshots of network traffic (PCAP), controller state tables, and authentication logs to support rigorous root-cause analysis and regulatory reporting.
Golden Baseline Restoration
Rapidly restore verified, digitally signed configuration baselines to PLCs and inverters following an unauthorized parameter shift, ensuring rapid return to safe commercial operation.
Enterprise Integration
Deployment Architecture & Data Boundaries
Battery Cyber Control operates within strict critical-infrastructure constraints. We support hybrid and air-gapped architectures where operational telemetry remains entirely under customer control.
| Architecture Element | Deployment Model | Operational Impact | Customer Data Boundary |
|---|---|---|---|
| Site Passive Sensor | Hardware 1U / DIN-rail appliance or virtual collector deployed at local switch SPAN/TAP ports | Zero packet injection; optically isolated RX-only physical taps ensure 0% risk of bus disruption | 100% on-premises; decodes industrial packets locally |
| Control Plane & Analytics | Customer-dedicated Cloudflare Worker / Enterprise Edge or on-premises management cluster | Zero impact on real-time sub-second control loops (Modbus/CAN executed locally) | Telemetry metadata only; customer retains ownership and cryptographic keys |
| Outbound Connectivity | Unidirectional mTLS over dedicated cellular / satellite or customer-managed DMZ | No inbound firewall ports required; zero external listen sockets on site edge | All egress traffic encrypted with customer-held certificate authorities |
| Access Gateway | Hardened bastion with hardware MFA and ephemeral session proxying | Eliminates direct technician access to controller subnets; transparent to vendor tools | Complete session video and protocol logs stored in customer storage bucket |
Ready to evaluate Battery Cyber Control on your site?
We conduct architecture reviews and passive pilot deployments on grid-scale BESS and data center facilities.
Discuss an environment