About
A narrow specialism, on purpose.
BatterySec exists because battery energy storage sits in a gap. Enterprise security teams know networks and identity but not protection coordination. Electrical engineers know the plant but were never asked to treat a control channel as hostile. The risks that matter most live exactly where those two bodies of knowledge stop.
Perspective
What we think is being missed.
The consequence is physical, so the assessment has to be too. A finding that stops at "an attacker could reach the EMS" is only half an answer. The other half is what the EMS can then instruct, what refuses an unsafe instruction, and whether that refusal survives the same compromise.
Remote access is the real perimeter. Storage assets are operated and maintained remotely because that is the only economic way to run a distributed fleet. The maintenance channel is therefore not an edge case — it is the primary architecture, and it deserves to be assessed as such.
Independence is the property that matters. Layers of defence only count as layers if compromising one does not compromise the next. A great deal of apparent depth collapses under that question.
Findings must survive contact with operations. A recommendation that would trip a site, void a warranty or breach a grid code will not be implemented, and an assessment full of them is a document rather than an improvement.
How we work
Practical commitments.
ON THIS PAGE
You will notice this page names no people, no founding date, no office and no client list. That is deliberate: we would rather publish nothing than publish something we cannot stand behind. If you need to know who you would be working with, ask — that conversation happens directly, not through a website.