Security for the systems that move the ore and pour the gold.
A gold operation runs on control systems that were never designed to be connected: PLCs on the mill, dispatch servers in the pit, sensors on the tailings dam, access control in the gold room. We secure that estate as one system - assessing it against IEC 62443 and NIST CSF, separating IT from OT without breaking production, monitoring it around the clock, and rehearsing the day something gets through. Everything we build here is designed to keep the plant running, not to slow it down.

Plant control room
What we build under cyber security.
OT / ICS security assessment
Asset discovery and risk assessment of PLCs, SCADA, historians and fleet systems against IEC 62443 and NIST CSF.
IT/OT segmentation & secure remote access
Zoned networks, industrial DMZs and brokered vendor access so OEMs can support equipment without a path into the plant.
24/7 security monitoring
Passive OT monitoring and IT detection tuned for mine networks, with an on-call analyst who knows what a mill outage costs.
Ransomware resilience & recovery
Immutable backups, tested recovery of dispatch, LIMS and ERP, and a plan that keeps ore moving while systems are restored.
Gold room & custody system hardening
Access control, CCTV, weighing and chain-of-custody systems reviewed and hardened as a single, auditable boundary.
Governance, compliance & awareness
Policies, ISO 27001 alignment, board reporting, phishing simulation and site-specific training for crews and contractors.
What the crew actually sees.
A representative screen from a cyber security deployment. Every interface is built for gloves, glare and a shift that does not stop.
- L4Corporate IT212 assets
- L3.5Industrial DMZ9 assets
- L2Plant control148 assets
- L2Fleet & dispatch63 assets
- L1Gold room17 assets
What a deployment looks like.
Representative engagements, described the way we would scope them with you. Every one starts as a pilot on a single shaft, pit, circuit or process.
Plant control network segmentation
Separate the CIL, milling and reagent control systems from corporate IT and the internet without a single unplanned stop.
Fleet and dispatch hardening
Lock down dispatch servers, telematics and radio-over-IP links so a compromised laptop cannot reach a truck.
Custody system audit
Review who can change a weight, open a door or edit a record, and close the gaps before the next LBMA or insurer audit.
Incident tabletop and recovery drill
Walk the leadership team through a ransomware day, then prove that dispatch, LIMS and ERP come back from backup.
Outcomes we design for.
- A complete, current inventory of every connected system on site
- Vendor and remote access that is brokered, logged and time-limited
- Detection and response measured in minutes, not discovered at shift change
- Evidence ready for insurers, auditors and the board
Technology & integrations.
- IEC 62443 / NIST CSF
- ISO 27001
- Industrial DMZ & firewalls
- Passive OT monitoring
- SIEM / EDR
- Privileged remote access
- Immutable backup
- Identity & MFA
Vendor-neutral by default. We work with what is already on site and recommend new tooling only when it removes a bottleneck.
Before we talk cyber security.

Have a problem cyber security could fix?
A stope that is hard to inspect, a reconciliation that never balances, a report that eats a week every month. We will scope a pilot around it, price it, and tell you honestly whether it is worth doing.