MINING & METALS
OT Cybersecurity for
Energy Sector
Secure operational technology, industrial control systems, and SCADA environments across energy operations. Red Piranha protects critical energy assets in Australia and worldwide.
CLOCKS ALREADY RUNNING
Energy operators face pressure from every direction. Connected operations, legacy systems, and rising regulation create a difficult risk picture for critical infrastructure security.
WHY MINING OT NEEDS PROTECTION
Mining OT was never built to be defended
A mine is the most operationally consequential technology estate in the country, spread across the most remote ground. Production control now runs on moving vehicles, wireless networks, and satellite links. The same connectivity that made the mine productive is the attack surface.
Autonomous fleets and wireless networks
Autonomous haulage, autonomous drilling, and tele remote loading depend entirely on radio and positioning. Interference, jamming, authentication, and spoofing are safety events, not just IT events.
Remote operations centre risks
One centre can control many sites across several jurisdictions. That is one compromise with the reach of a whole portfolio, plus a permanent high trust link into every site.
Vendor access is the front door
Mills, crushers, drives, analysers and fleet systems are supported through standing vendor tunnels. Shared credentials, no session recording and offshore access are now named regulatory risks.
Legacy plant cannot be patched
Control systems are specified with the mine plan and run for decades. Agents will not install; scanning is unsafe, and a patch window costs more than most security budgets.
Safety controls are reachable
Ventilation on demand, gas monitoring, hoisting, conveyor interlocks, dewatering and tailings instrumentation are all networked. A cyber event that defeats a safety control is a work health and safety failure.
Nobody can see the estate
Brownfield sites and acquisitions arrive with unknown OT. Without an accurate asset inventory you cannot segment, cannot isolate, cannot rebuild and cannot evidence anything to a regulator.
What changed on 10 June 2026, and what it means at site
New obligation | Due | What it means on a mine site |
Cyber framework uplift | 10 Jun 2028 | Move to ISO/IEC 27001:2023, Essential Eight Maturity Level 2, NIST CSF 2.0, C2M2 MIL 2 or AESCSF Security Profile 2. IEC 62443 carries the OT estate as the documented equivalent. |
Network segregation | 10 Jun 2028 | Critical systems must keep running for at least three months while everything else is restored. Site autonomy becomes an architecture requirement. |
Phishing resistant MFA | 10 Jun 2028 | Central logging and monitoring on every path into control systems, including vendor and remote operations centre access. |
Legacy, patching and AI risk | 10 Jun 2027 | Unpatched systems, end-of-life plant and emerging technology must be named and managed as material risks. |
Offshore and remote access | 10 Jun 2027 | Remote access to critical components, and offshore storage of schematics, geospatial data and configuration, are now express material risks. |
Critical worker vetting | 10 Jun 2028 | AusCheck or NV1 for critical workers with five yearly re checks. A real program across a fly in fly out and contractor heavy workforce. |
Supply chain and FOCI | 10 Jun 2028 | Map major suppliers and critical components. Assess foreign ownership, control and influence, sanctions and supplier access to the asset. |
THE RED PIRANHA SOLUTION
Operational Technology and Industrial Control System Security solutions for mining
Red Piranha aligns OT security, ICS security, and SCADA security with the operational reality of a working mine. Crystal Eye delivers controls, telemetry and evidence, from pit to port.
OT and ICS Visibility & Industrial Control System Security
Identify and monitor industrial assets across the fleet, plant, rail, and port.
Red Piranha delivers OT and ICS visibility, network segmentation, and Critical Infrastructure Protection controls that meet SOCI Act and IEC 62443 obligations.
Network Segmentation
Crystal Eye security zones separate IT and OT networks. Conduits reduce lateral movement between autonomous fleet, processing plant control and corporate systems.
Crystal Eye PECA (Passive Encryption Control Application) delivers passive asset management and Zero Trust zoning, aligned to IEC 62443, solving OT device lifecycle challenges without disrupting production.
Threat Detection and Response
Crystal Eye delivers Threat Detection, Investigation and Response (TDIR) across OT and SCADA traffic. Anomalies on the mine network are caught and contained fast.
24/7 Security Operations Centre
A 24/7 security operations centre watches your environment across every site. Sovereign Australian analysts triage, investigate and escalate.
Vulnerability Management
Identify and prioritise vulnerabilities across critical mining systems. Track treatment to reduce exposure over time and produce the evidence your CIRMP annual report needs.
Secure Remote Access
Protect contractors, vendors, and remote operators. Crystal Eye supports controlled VPN access into OT zones, backed by Post-Quantum Cryptography (PQC) ready SD-WAN for secure connectivity to remote sites.
Awareness and Training
Strengthen cyber resilience across operational teams. Reduce human risk in the field, in the control room, and at the remote operations centre.
Managed Detection and Response
MDR for OT combines monitoring, threat intelligence and response. Threats against mining operations are found and contained quickly.
Crystal Eye Platform
Crystal Eye unifies Threat Detection, Investigation and Response (TDIR), segmentation, VPN, and reporting in one platform. It is the control and evidence engine for mining security.
REFERENCE ARCHITECTURE: IEC 62443 FOR MINING OPERATIONS
From pit to port, mapped to zones and conduits
IEC 62443 assumes a fixed plant. A mine does not stand still. Red Piranha models the mobile fleet as its own zone with the wireless network as its conduit, then assigns target security levels from safety and production consequence rather than from network position.
ZONE 01Autonomous fleet | ZONE 02Processing plant | ZONE 03Mine services and | ZONE 04Tailings and | ZONE 05Rail, port and | ZONE 06Remote operations |
Autonomous haulage and drilling Tele remote loading Private LTE, Wi Fi, positioning Collision avoidance | Crushing, milling, flotation DCS, PLC and historian Analysers and weightometers Engineering workstations | Ventilation on demand Gas monitoring and dewatering Hoisting and winding Safety instrumented systems | TSF instrumentation Piezometers and telemetry Pumping and pipelines Borefield and desalination | Heavy haul rail signalling Train control and load out Shiploaders and stackers Generation, solar and storage | Fleet management systems Short interval control Corporate identity and cloud Vendor and OEM support |
The conduit rule. Every link between these zones is a controlled conduit, enforced at both ends. Production telemetry, condition monitoring, and reporting flow outward only. Nothing needs to reach inward to read from a plant. Each site holds local identity, local historian and local time so it can keep producing when the link to the remote operations centre is cut. That is how the three-month isolation requirement is met in practice.
DEFENCE IN DEPTH: OT SECURITY ARCHITECTURE
OT security architecture for mining
Red Piranha secures every layer from the corporate network to the equipment in the pit. Monitoring, detection, segmentation, threat intelligence and incident response wrap each zone.
Every zone and conduit is monitored, segmented and defended.
Crystal Eye maps directly to IEC 62443 zones, conduits and target security levels, from the corporate network to the pit floor.
WHERE IT APPLIES
Built for every part of the mining value chain
CIRMP run as a living assurance program
Compliance is not a paper exercise. Red Piranha operates CIRMP as a continuous program. IEC 62443 shapes the OT architecture. Crystal Eye produces the evidence. The board gets an attestation it can actually stand behind.
WHY RED PIRANHA
A sovereign partner built for high consequence operations
Sovereign by design
Australian owned, Australian developed and Australian hosted, with an Australian SOC. Data sovereignty is a control, not a marketing line, and offshore access is now an express regulatory risk.
We build the full stack
Red Piranha controls the platform end to end, so there is no integration overhead and no bolt on tools. The system generating the events is the system investigating them.
Certified and connected
ISO/IEC 27001 certified, CREST ANZ Member Company, Official Cyber Threat Alliance Member and Team Defence Australia member.
Built for remote sites
Detection continues when the satellite or microwave link drops. Local monitoring does not depend on a central server to keep working.
Evidence that lasts
Log retention of 18 months out of the box, meeting and exceeding ASD guidance, with forensic packet capture on demand for investigations and audits.
Lower total cost
One vendor, one licence model and predictable budget. Achieve more security outcomes with a lower total cost of ownership and no half executed deployment.
Find out where your mine actually stands
Book an OT security assessment. We scope your regulated assets, inventory the OT estate,
map it to IEC 62443 zones and show you exactly what has to be true by 10 June 2027 and 10 June 2028.