Independent OT cybersecurity assurance · Energy & Maritime

We build where the asset is

MeruEPC engineers deploy to the site, work the problem in front of them, and build the thing that fixes it. Our assurance products are what remains afterwards — method earned in control rooms, on platforms, and aboard vessels over two decades, not assembled in a conference room.

Industries we serve
Maritime Offshore Onshore EPC
INGEST ASSESS REPORT AI AGENT SWARM · ENERGY WORKFLOWS HUMAN GATE EVIDENCE · MAPPING · COMPLIANCE · REPORTING — AUTOMATED
Offshore oil platform silhouetted against a sunset
OT Assessments · Rig · Vessel · FPSO · FLNG
Offshore & onshore — where we assess
How we work

Field-derived engineering

We do not write the report and leave. We do not ship the box and hope. Our engineers deploy to the asset, work the problem that is actually in front of them, and what remains afterwards becomes a product. The product is the residue of the deployment — never the other way round.

THE OPERATING LOOP 01 DEPLOY 02 OBSERVE 03 CODIFY 04 PRODUCTISE 05 REDEPLOY EACH CYCLE FEEDS THE PLATFORM SECOND SOLVE COSTS A FRACTION OF THE FIRST
01
Deploy Engineers go to the asset — deck, bridge, plant floor — in PPE, inside the operating constraints that actually apply.
02
Observe Map the real problem, not the tendered one. What the drawings claim and what the systems permit are rarely the same thing.
03
Codify Turn the solution into method: repeatable steps, defined evidence, and judgement written down rather than carried in someone's head.
04
Productise The method becomes tooling and enters one of our three lines, where it is maintained, versioned, and improved.
05
Redeploy The next engagement starts further ahead than the last one. The engineer arrives with the accumulated method already in hand.

If an engagement ends and nothing has entered the platform, we treat it as a failure — however well it was delivered.

That standard is why our products look the way they do. Every one of them started as a problem someone handed us on a site, under real constraints, with a running process that could not be stopped.

Critical sectors

One assurance layer, five operating worlds

Energy and maritime infrastructure does not sit in a data centre. It sits offshore, at sea, on a plant floor, at a berth, and in a substation — each with its own access constraint, its own safety case, and its own reason the assessor cannot simply walk up to it.

ONE EVIDENCE LANGUAGE 01 OFFSHORE 02 MARITIME 03 PROCESS 04 PORT 05 POWER
01
Offshore Rigs, FPSOs and platforms. Access is a scheduled window governed by weather, permits and POB.
02
Maritime Bridge, machinery and cargo control. The boundary moves with every charter and port call.
03
Process DCS, SIS and packaged vendor systems that have accumulated across decades of turnarounds.
04
Port & terminal Cranes, gate automation and berth control, where OT and commercial IT quietly converged.
05
Power Substation automation, wind, solar and storage. Distributed by design, unmanned by default.
Three lines

One architecture, not a catalogue

Everything we build resolves into three lines. Each one exists because a deployment forced it into existence — and each one is where the next deployment's learning goes.

Line 01 Deployed

Assessment

Evidence about the state of an OT environment, produced to a consistent method so that findings from different assets can be compared and defended.

  • ElantisMaritime & offshore OT assurance
  • MeruGuardOffline configuration assurance
  • Assessment servicesRisk, gap & architecture reviews
See the Assessment line →
Line 02 In build

Edge

Assurance work that has to happen where the assessor cannot easily go — at the gateway, at the boundary, on assets that are remote, unmanned, or only reachable in scheduled windows.

  • Remote assessment at the gatewayIn active development
  • Boundary evidence collectionDesigned for constrained access
  • Field-deployable toolingBuilt around real site conditions
See the Edge line →
Line 03 Under NDA

Continuity

Operating knowledge sits with a small number of experienced people, and it walks out of the door with them. This line addresses continuity of engineering judgement across the asset lifecycle.

  • Delivered through field deploymentNot as a shelf product
  • Scoped per asset and per operator
  • Further detail available under NDA
See the Continuity line →

Services, training, and AI capability sit across all three lines rather than beside them — they are how a line reaches an operator, not separate offerings. The full index of what we deliver is below.

Full index

Everything the three lines deliver

The complete list of products and services, grouped as an operator would buy them.

Elantis — Maritime & Offshore OT Assurance, a MeruEPC product
Maritime & Offshore OT Assurance
A MeruEPC product
Product · A MeruEPC product

Elantis

Assurance that reaches every asset.

Elantis helps maritime and offshore operators build a consistent, evidence-led view of OT assurance across remote and safety-critical assets.

  • Comparable assurance evidence across vessels, rigs, and FPSOs
  • Designed for the operating context shaped by IMO guidance, IACS cyber-resilience expectations, and IEC 62443
  • AI assists comparison and insight; qualified people retain context and accountability
Discuss your operating context How Elantis works →
MeruAI
AI services

MeruAI for OT

OT-localised LLMs and agentic automation deployed on your infrastructure — on-premise or air-gapped, human-approved, fully auditable. Automates evidence review, compliance mapping, and reporting.

How it works →
MeruGuard
Product · A MeruEPC product

MeruGuard

Offline IT/OT configuration assurance. Turns exported network-device configurations into prioritised security findings and defensible assessment evidence — no credentials, no connection to the device.

What it analyses →
Assessment services

OT security assessments

Risk assessments, gap assessments, and architecture reviews for rigs, plants, vessels, FPSOs, and renewables — IEC 62443 zone & conduit method, P×C scored, evidence-backed.

Scope & method →
Offensive services

OT penetration testing

Plant-safe adversarial testing: passive analysis on live systems, active exploitation only in FAT, staging, and offline replicas. Real attack-path validation without risking a running process.

Discuss scope →
Maritime compliance

UR E26 / E27 cyber services

IACS UR E26/E27 readiness for newbuilds and fleets: vessel asset mapping, control implementation, test & acceptance design, and class-notation evidence packs — aligned to IMO MSC.428(98).

Maritime track record →
Training · MeruShield

Cybersecurity training

Fifteen expert-led programs across five tracks — OT, Maritime, Corporate, Family, and Intelligence — from ICS/OT fundamentals and CyberHAZOP to UR E26/E27 resilience. Delivered worldwide, in-person or virtual.

View training catalogue (PDF)
Elantis
A MeruEPC product

Assurance that reaches every asset

Elantis helps maritime and offshore operators build a consistent, evidence-led view of OT assurance across remote and safety-critical assets.

When asset access is difficult, assurance evidence cannot be optional.

One fleet. Different exposure. One evidence language. Vessels, chartered assets, drilling rigs, and offshore installations each carry a different combination of systems, people, rules, and risk — and charters, port calls, maintenance windows, and vendor changes move the boundary continuously. A fleet-level assurance decision still needs evidence that compares across all of it.

Elantis makes the evidence method travel to the asset, rather than asking the asset to wait for an assessor.

Elantis overview · 35 seconds
Safer

Designed to leave operations unchanged

An assurance approach built for safety-critical environments: no configuration changes to OT systems, no cloud dependency, and no requirement to treat control, power, bridge, or cargo systems like ordinary IT endpoints.

Faster

Assurance without the travel window

Evidence can be gathered without routing a specialist assessor to every hull and rig. Assurance stops being constrained by access, sailing schedules, and mobilisation logistics.

Smarter

Comparable evidence, over time

Consistent evidence across assets and repeat cycles builds a defensible baseline, clear exceptions, and traceable proof of remediation — not a one-time observation.

Access is limited. Assurance must travel lightly.
Evidence must compare. Different assets still need one language.
People stay accountable. Technology supports the decision.
The operating guardrail

AI assists the evidence. People own the decision.

AI is used where it adds speed and consistency — comparing patterns and surfacing insight inside an assessor-led process. It never executes on the asset, changes an OT configuration, or authorises a risk decision.

Qualified people retain context, technical judgement, and accountability at every stage.

Designed for the operating context shaped by
IMO & ISM IACS UR E26 & E27 Class society requirements IEC 62443
Discuss your operating context
MeruGuard
MeruGuard
OT Configuration Assurance
A MeruEPC product

Know what your network configuration is exposing

MeruGuard is an offline IT/OT configuration-assurance platform that transforms exported network-device configurations into prioritised security findings and defensible assessment evidence.

MeruGuard analyses exported IT and OT device configurations to uncover risky firewall rules, weak management services, segmentation gaps, legacy security settings, and industrial-protocol exposure. It works locally, requires no device credentials, and produces prioritised, audit-ready evidence.

EXPORTED CONFIGURATIONS · ANALYSED OFFLINE ENTERPRISE FIREWALL CONTROL ! PERMISSIVE RULE — FLAGGED FOR REVIEW PRIORITISED FINDINGS RULE EXPOSURE · MGMT SERVICES · SEGMENTATION · LEGACY SETTINGS · PROTOCOL REACH
Configurations read offline and compared against intended zone boundaries
Engineer reviewing exported device configuration output on screen
Configuration review · IT & OT estate
Evidence gathered from systems already in service, without touching a live device
What it analyses
  • Risky firewall rules and permissive access paths
  • Weak or exposed management services
  • Segmentation gaps against intended zone boundaries
  • Legacy and deprecated security settings
  • Industrial-protocol exposure across the estate
How it works
  • Offline by design — analysis runs locally, on your infrastructure
  • No device credentials and no connection to live equipment
  • Reads configurations you have already exported
  • Findings ranked by priority, not dumped as a flat list
  • Output structured as audit-ready evidence
Scope, stated plainly

What MeruGuard is — and is not

MeruGuard is a configuration-assurance and evidence-generation platform. It supports security assessments, remediation planning, and compliance activity by making the current state of your network configuration visible, comparable, and defensible.

  • It is not an IEC 62443-certified product.
  • It is not a vulnerability scanner.
  • It is not proof that a network is secure.

A configuration review tells you what your devices are currently permitting. Judging whether that is acceptable remains the work of qualified assessors — which is exactly where MeruGuard hands off.

Line 02 · Edge

Where the assessor cannot easily go

Some assets cannot be visited on demand. Access is scheduled, weather-dependent, or governed by an operating window that closes long before the assessment is finished.

The Edge line exists because the same problem kept appearing across different sectors: the assurance method was sound, but the asset was unreachable often enough that the evidence was always out of date by the time a decision needed it.

Our approach is to move the evidence method to the boundary — collecting what can be collected at the gateway, under the constraints the site actually imposes, so that assurance does not stall while it waits for travel, a window, or a shutdown.

This line is in active development. We would rather describe it accurately now than overstate it and correct it later.

What shapes it
  • Assets reachable only in scheduled windows
  • Remote, unmanned, and low-bandwidth sites
  • Environments where assessor travel is the binding constraint
  • Operating contexts shaped by IEC 62443 zone-and-conduit thinking
Line 03 · Continuity

When the expertise leaves, what stays?

Operating knowledge sits with a small number of experienced people, and it walks out of the door with them.

Across every sector we work in, the same risk surfaces late: the engineer who understands why a system is configured the way it is, what was tried before, and which constraints are real rather than habitual — retires, transfers, or moves to another operator. What is left behind is documentation that records decisions but not judgement.

The Continuity line addresses continuity of engineering judgement across the asset lifecycle. It is delivered through field deployment rather than sold as a shelf product, because the work only makes sense in the context of a specific asset and a specific operating history.

Further detail is available under NDA.

Request an NDA discussion Client-confidential by design
Why it matters
  • Senior OT expertise is concentrated and ageing
  • Handover documents record decisions, not reasoning
  • Replacement hiring does not restore site-specific judgement
  • The cost surfaces during turnarounds and incidents, not before
Capability matrix

Everything we build, in one view

Products, engineering capabilities and delivered services across the three lines. Filter by line to see what each one actually contains.

Line 01 · ProductDeployed

Elantis

Maritime and offshore OT assurance. One evidence language across dissimilar assets, collected inside the access window the asset actually allows.

#maritime#offshore#evidence#UR-E26
Line 01 · ProductDeployed

MeruGuard

Offline configuration assurance. Reviews exported firewall, router and switch configurations without credentials and without connecting to a live device.

#offline#segmentation#no-touch
Line 01 · ServiceDeployed

OT risk & gap assessment

Zone-and-conduit modelling, scored findings and a remediation roadmap sequenced around turnaround windows rather than calendar quarters.

#IEC62443#zones#roadmap
Line 01 · ServiceDeployed

Cyber FAT & SAT

Factory and site acceptance testing for vendor packages, so that what was written into FEED is verified before handover rather than assumed.

#EPC#newbuild#handover
Line 01 · ServiceDeployed

Class & flag readiness

Asset mapping, control implementation and test design for the operating context shaped by IACS UR E26/E27 and IMO MSC.428(98).

#class#IMO#fleet
Line 01 · ServiceDeployed

Plant-safe adversarial testing

Testing designed around a running process — passive where it must be, active only where the safety case and the operator explicitly permit it.

#pentest#safety-case#passive
Line 02 · ProductIn build

Remote assessment at the gateway

Assurance evidence collected at the boundary, so the position does not go stale waiting on travel, a weather window or a shutdown.

#gateway#remote#boundary
Line 02 · CapabilityIn build

Field-deployable evidence kit

A controlled, tamper-evident collection kit built around real site conditions — write-blocked, sanitised between assets, and manifested on return.

#chain-of-custody#write-block#manifest
Line 02 · CapabilityIn build

Constrained-access assurance

Method designed for unmanned, low-bandwidth and scheduled-window assets, where assessor travel is the binding constraint on assurance.

#unmanned#low-bandwidth#windows
Line 03 · ProgrammeUnder NDA

Continuity of engineering judgement

Addresses the risk that operating knowledge concentrated in a few experienced people leaves with them. Delivered through field deployment, scoped per asset.

#continuity#lifecycle#NDA
AI · DeliveredDeployed

Agentic workflows for OT GRC

Multi-agent automation of evidence review, control mapping and reporting. Every action passes a human approval gate before it reaches an operational system.

#agentic#GRC#human-gate
AI · DeliveredDeployed

OT-localised language models

Local deployment inside the security perimeter — on-premise or air-gapped — so plant documentation and findings never leave the operator's environment.

#on-prem#air-gapped#sovereign
AI · DeliveredDeployed

Forward-deployed AI engineering

Engineers embedded with planners and process engineers to map the real workflow before a single agent is built. The plant comes first, the automation second.

#embedded#workflow#field-first
AI · CapabilityIn build

AI risk assessment for OT

Evaluating AI and agentic systems proposed for operational environments: what the model can influence, where the gates sit, and what evidence exists if a regulator asks.

#AI-risk#assurance#regulator
Across lines · TrainingDeployed

MeruShield training

Fifteen programmes across five tracks, written for people who run plant and sail ships rather than for people who run security operations centres.

#training#crew#operators
Across lines · ServiceDeployed

Governance & compliance programmes

Policy, standards mapping and audit support built for the operating context shaped by IEC 62443 — not lifted from an enterprise IT framework.

#governance#audit#IEC62443
20+
Years in OT / ICS security
3
Hubs — Abu Dhabi · Singapore · Chennai
60+
Assessments, audits & programs delivered
7
Standards & regulatory frameworks applied
Domain reputation

Trusted where energy meets water

Our track record was built inside national oil companies, petrochemical complexes, ports, and classed vessels — not conference rooms. We don't name clients. Our references speak privately, which is how critical infrastructure prefers it.

Energy

Two decades across upstream, refining, and petrochemicals in the GCC and Asia — from wellhead RTUs to plant-wide DCS estates.

  • OT assurance programs for national-scale oil & gas operators
  • DCS, SIS, and packaged-system security assessments on live plants
  • Secure MPLS / industrial transport architecture assurance
  • IEC 62443 & UAE regulatory alignment, end to end

Maritime

Vessel and port OT security delivered under class-society and IMO expectations — where connectivity risk sails with the ship.

  • IEC 62443-based vessel OT assessments for tankers and carriers
  • IACS UR E26/E27 and IMO MSC.428(98) compliance frameworks
  • VSAT / satcom vendor and connectivity risk assessments
  • Port & terminal OT governance from prior operator-side roles
Who we serve

The operators who call us

We do not name clients — critical infrastructure prefers it that way, and so do we. What we can describe is the kind of operator we sit across from, and the question they arrive with.

Operator type 01

National & regional energy operators

"We have plenty of evidence. We cannot compare any of it."

Upstream, refining, and petrochemical estates where DCS, SIS, and packaged vendor systems have accumulated over decades, each assessed by whoever was available at the time.

Assessment · Edge
Operator type 02

Fleet owners & maritime operators

"Half the fleet isn't ours. Class still wants one answer."

Owned and chartered assets under IMO and class expectations, where the boundary moves with every charter, port call, and vendor change.

Assessment · Edge
Operator type 03

EPC contractors & capital projects

"Security was in the spec. Nobody tested whether it arrived."

Newbuilds and greenfield plants where cybersecurity was written into FEED but never verified at factory acceptance, site acceptance, or handover.

Assessment
Operator type 04

Ports, terminals & logistics OT

"Our OT and our IT stopped being separate years ago."

Terminal operating systems, cranes, gate automation, and berth control where operational continuity and commercial systems have quietly converged.

Assessment · Continuity
Operator type 05

Renewables & power

"The assets are remote and nobody is standing next to them."

Wind farms, solar PV, battery storage, and substation automation — distributed by design, unmanned by default, and reachable only through the gateway.

Edge · Assessment
Operator type 06

Operators facing a knowledge cliff

"The person who understood this system retires next year."

Any of the above, at the point where engineering judgement is concentrated in a handful of people and no handover document captures why the decisions were made.

Continuity
Delivery record

What we have actually delivered

Engagements described by shape rather than by name. Every one of these fed something back into a line.

Sector
Engagement
Scale
What was delivered
Oil & Gas · Onshore
Plant-wide OT risk & gap assessment
Multi-unit site
Zone-and-conduit model, P×C scored findings, prioritised remediation roadmap sequenced around turnaround windows.
Offshore
OT assurance across drilling & production assets
Multi-asset
Comparable evidence baseline across dissimilar assets, delivered inside restricted access windows.
Maritime
Vessel OT assessment & class readiness
Fleet programme
Asset mapping, control implementation and test design against IACS UR E26/E27 and IMO MSC.428(98) expectations.
EPC · Capital project
Cyber FAT & SAT through to handover
Greenfield
Vendor package security reviews, factory and site acceptance testing, secure as-built baseline at handover.
Energy · Network
Industrial transport & segmentation assurance
Estate-wide
Offline configuration review of network devices, verifying what was permitted against what the architecture claimed.
Energy · AI
Agentic AI workflows for OT governance
Operator programme
Evidence review, compliance mapping and reporting automated behind human approval gates, deployed on operator infrastructure.
Client names, asset names and locations are withheld under confidentiality in every engagement
What the field produced

Problems that became method

We do not name clients. What we can describe is the pattern: the operating constraint we met, and what it forced us to build. Each of these entered one of the three lines.

Pattern 01 · Offshore

Assessment windows shorter than the assessment

Access to the asset was limited to scheduled windows governed by weather and operations. A conventional assessment could not complete inside one, and restarting it lost continuity each time.

Entered → AssessmentA repeatable evidence workflow that survives interruption, now part of how Elantis is delivered.
Pattern 02 · Mixed fleet

Same fleet, incomparable evidence

Owned and chartered assets carried different systems, vendors, and reporting habits. Every asset had evidence; none of it could be compared, so no fleet-level decision could be defended.

Entered → AssessmentOne evidence language across dissimilar assets — the core premise Elantis is built on.
Pattern 03 · Onshore process

Segmentation that existed only on the drawing

Architecture documents described zones and conduits confidently. The device configurations permitting traffic told a different story, and connecting to live devices to check was not acceptable.

Entered → AssessmentOffline configuration review from exported files, with no credentials and no device connection — now MeruGuard.
Pattern 04 · Remote assets

Evidence older than the decision it supported

By the time an assessor could reach the asset and report, the environment had changed. The assurance position was always describing a state that no longer existed.

Entered → EdgeMoving the evidence method to the boundary rather than moving the assessor to the asset.
Deployment engineering

The people who close the loop

Field-derived engineering only works if the engineers are actually in the field. These are the two roles the whole method depends on — assessors who verify physically, and engineers who build beside the people running the process.

Offshore crew in orange coveralls and PPE on site

Assessors in PPE, where the risk lives

Our assessments happen on rig decks, vessel bridges, and plant floors — walking zones and conduits physically, verifying what drawings claim, and talking to the operators who live with the systems every shift.

Engineer building software and workflows on screen

Forward-deployed AI engineers

Our engineers embed inside your operation — sitting with planners, operators, and engineers to map real workflows first, then building AI agents around them: localised, human-gated, and shaped to how your plant actually runs.

Services

Assurance first. Everything else follows.

Independent assurance is our core service: telling you, with evidence, whether your OT environment is as secure as your paperwork says it is.

Core service

OT security assurance & audit

Structured, standards-based assurance of your OT environment — zone-and-conduit risk assessment, control validation, compliance audit, and evidence-backed findings scored by probability × consequence across safety, environment, financial, and reputational impact. Independent, vendor-neutral, and written for both the boardroom and the control room.

02

Architecture assurance

Purdue-model segmentation, DMZ design, remote access, and industrial network transport reviewed against how attacks actually move — not how diagrams look.

03

Governance & compliance

IEC 62443-aligned policies, procedures, and security programs mapped to regional regulation — written to be operated by your teams, not filed away.

04

Incident response readiness

OT-specific response plans, playbooks, and tabletop exercises that respect a running plant: you cannot simply pull the plug on a live process.

05

EPC lifecycle cybersecurity

Security engineered into capital projects from FEED and detail design through cyber FAT at vendor factories, cyber SAT during commissioning, pre-startup review, and secure as-built handover.

06

Vendor evaluation & remediation

Independent, capability-scored evaluation of OT security vendors and packages — and prioritised remediation roadmaps sequenced around turnarounds, legacy constraints, and operational risk.

07

Training & capability

OT cybersecurity training for engineers, operators, and leadership — grounded in the standards and incidents that shape your sector.

MeruAI — Secure. Smart. Human
OT-localised AI

AI that stays inside the fence

We don't sell AI. We engineer it to work safely where it matters: localised language models deployed on your infrastructure, inside your security perimeter — air-gapped where required — so nothing about your plant ever leaves your plant.

OT and AI — stronger together: an OT worker and an AI agent joining hands on a rising curve
Sovereignty

On-premise by design

Local LLMs on your hardware, in your data centre or at the edge. No cloud dependency, no external API calls, no data egress. Suitable for air-gapped and sovereign environments.

Safety

Human-approved actions

Nothing generated by a model reaches an OT system without explicit human authorisation. Approval gates are enforced in the architecture — not promised in a policy.

Accountability

Auditable end to end

Every input, output, and approval is logged and traceable. If a regulator or operator asks "why", the evidence trail already exists.

AI we have put into operations

Not demonstrations. Work delivered into live energy and maritime environments, under the same constraints as everything else we build — on operator infrastructure, behind human approval, and auditable after the fact.

AI engagement 01Delivered

Agentic workflows for OT governance, risk & compliance

Multi-agent automation of evidence review, control mapping, and reporting — the repetitive analytical work that consumes assessor time. Every action passes a human approval gate before it reaches an operational system.

AI engagement 02Delivered

OT-localised language models on operator infrastructure

Local model deployment inside the security perimeter — on-premise or air-gapped — so that plant documentation, configurations, and findings are never processed outside the operator's own environment.

AI engagement 03Delivered

Forward-deployed AI engineering

Engineers embedded with planners, operators, and process engineers to map the real workflow before a single agent is built. The workflow comes first; the automation is shaped around how the plant actually runs.

AI engagement 04In build

AI risk assessment — assessing AI before it reaches the plant

Structured evaluation of AI and agentic systems proposed for operational environments: what the model can influence, what it cannot, where the approval gates sit, and what evidence exists if a regulator asks why.

Applied in our tooling: I-CAIRA · compliance intelligence Elantis · maritime & offshore OT assurance CyberEquipe · governance workflows
Presence

Three hubs. One standard of work.

🇦🇪

Abu Dhabi

Middle East operations

On the ground in the UAE, serving oil & gas, petrochemical, and utility operators across the GCC — aligned to UAE NESA/IAS and regional regulatory expectations.

contact@meruepc.com →
🇸🇬

Singapore

Asia headquarters

MeruEPC Pte. Ltd. — our registered base and Asia hub, serving maritime, ports, and energy clients across Southeast Asia and the wider APAC region.

contact@meruepc.com →
🇮🇳

Chennai

India operations · VyomEPC
VyomEPC — Your Cyber Armor

VyomEPC Private Limited — our India entity, delivering SCADA and engineering support, instrumentation & automation cybersecurity, and OT expert services to pipeline and energy operators across India.

contact@meruepc.com →
Contact

Start with a conversation

A single assessment, a full assurance program, or a question about running AI safely inside your OT environment — reach us directly by email and we will route you to the right specialist.