It's not done when it works. It's done when it's secure.
Dan Kaufman has held the CISSP in good standing since 2014. Every network Triad designs starts from an information security foundation, and every system we work on is assessed for security while we're working on it, not after.
Remote sites are now part of your attack surface
- Every link, camera and access point added to a site is another way in.
- Cameras, cellular routers and vendor remote access are some of the most common entry points into industrial networks.
- On a control network, a compromise is an operations and safety problem, not just an IT one.
- Producers, insurers and auditors are asking harder questions about how field sites are secured.
Most installers make it work. We make it secure.
- Every job led by a CISSP, not a reviewer brought in at the end.
- Thirty years in oil and gas telecom and OT, so security fits how the site actually runs.
- Security checks built into design, configuration and commissioning.
- Written evidence you can hand to a producer, an insurer or an auditor.
Security at every stage, not at the end.
Assess
We look for exposed management interfaces, default passwords, flat networks, open remote access and unpatched devices before we change anything.
Design
Control, camera, business and crew traffic go in separate zones, with only the connections each one needs and secure remote access designed in.
Build
Hardened configurations, named admin accounts, unused services turned off and firmware current. Configs are reviewed before they go to site.
Verify and hand over
We test from each zone to prove the rules hold, then hand over a security summary: what we found, what we fixed and what's left.
What you get
- A security summary for each site, in plain language.
- Findings rated by risk, with what was fixed during the work.
- Network zones, firewall rules and remote access documented.
- Admin credentials handed to you, in your company's name.
- Evidence you can reuse for producer questionnaires and insurance renewals.
Qualified, and current
- CISSP (Certified Information Systems Security Professional), held in good standing since 2014.
- 30 years in telecommunications and networking, most of it in oil and gas.
- Hands-on OT and SCADA network experience on producing sites.
The CISSP requires ongoing education every year to stay in good standing, so the knowledge stays current, not just the certificate.