Systems
The connected environment, component by component.
This page is a reference, not a sales page. If you are new to the OT side of storage, it explains what each element does and how it can be reached. If you already know, it shows which questions we ask about each one.
Reachability map
Components
What each part does, and what we ask about it.
Cells, modules, racksThe stored energy itself. Not directly network-reachable, but every risk above eventually expresses itself here as temperature, current or state of charge. We ask: what physical conditions are unacceptable, and which of them can be induced by a command?
BMSMonitors cell state and enforces operating limits — voltage, current, temperature windows — and decides when to disconnect. The most safety-relevant controller in the system. We ask: can its limits be changed remotely, is protection independent of the compromised path, and can reported state be falsified?
PCS / inverterThe bidirectional converter between the DC battery and the AC network, moving power in both directions according to setpoints it is given. We ask: who can write a setpoint, what bounds them, and what happens at the limits?
EMSDecides dispatch — when to charge, discharge or hold — against market signals, site load or grid instruction. We ask: where does its instruction come from, and is that source authenticated in a way that would survive a compromised upstream?
SCADA and PLCsSupervisory monitoring and control, plus deterministic logic for site equipment. We ask: would an operator action and an intruder action be distinguishable in the record?
Gateways and protocol convertersTranslate between industrial protocols and IP networks. Often the least-maintained device on site and frequently the actual segmentation boundary. We ask: what does it translate, what does it authenticate, and who patches it?
Industrial protocolsModbus, DNP3, IEC 61850 and others. Several were designed for trusted serial links and carry little or no authentication by default. We ask: which control-carrying protocols are unauthenticated, and what compensates?
Remote support accessVendor and O&M access for diagnostics and maintenance. Operationally necessary; also a standing inbound path. We ask: is it brokered, time-bounded, individually attributed, and revocable the day a contract ends?
Cloud and fleet platformsMulti-site monitoring, analytics and often dispatch. A compromise here is a fleet-wide event rather than a site-level one. We ask: what can it command, and is the blast radius one site or all of them?
APIs and integrationsMachine-to-machine interfaces to traders, aggregators, VPP operators and asset-management systems. We ask: which of these can influence dispatch, and how is that authorisation scoped?
Firmware and embedded softwarePresent in every controller and designed to be updated remotely, which is precisely what makes the update channel worth attention. We ask: is it signed, is signing verified on the device, and who can trigger an update?
Electrical dependenciesProtection coordination, earthing, isolation and the auxiliary supplies that keep controls alive. We ask: what happens to protection when control power or communications are lost?
Which of these do you actually have?
Most sites differ from the reference picture in ways that matter. The first stage of any engagement is finding out how.