Assessors in PPE, where the risk lives
Our assessments happen on rig decks, vessel bridges, and plant floors — walking zones and conduits physically, verifying what drawings claim, and talking to the operators who live with the systems every shift.
Independent OT security assurance for energy and maritime operators across the Middle East and Asia — built on IEC 62443, delivered by people who have worked control rooms, platforms, and vessels for over two decades.
AI-powered OT security assessment platform. Zero-footprint collection from your OT estate, structured evidence review, consistent IEC 62443 scoring, and audit-ready reports — weeks of assessment work compressed into days.
OT-localised LLMs and agentic automation deployed on your infrastructure — on-premise or air-gapped, human-approved, fully auditable. Automates evidence review, compliance mapping, and reporting.
How it works →Risk assessments, gap assessments, and architecture reviews for rigs, plants, vessels, FPSOs, and renewables — IEC 62443 zone & conduit method, P×C scored, evidence-backed.
Scope & method →Plant-safe adversarial testing: passive analysis on live systems, active exploitation only in FAT, staging, and offline replicas. Real attack-path validation without risking a running process.
Discuss scope →IACS UR E26/E27 readiness for newbuilds and fleets: vessel asset mapping, control implementation, test & acceptance design, and class-notation evidence packs — aligned to IMO MSC.428(98).
Maritime track record →Fifteen expert-led programs across five tracks — OT, Maritime, Corporate, Family, and Intelligence — from ICS/OT fundamentals and CyberHAZOP to UR E26/E27 resilience. Delivered worldwide, in-person or virtual.
View training catalogue (PDF)Our track record was built inside national oil companies, petrochemical complexes, ports, and classed vessels — not conference rooms. We don't name clients. Our references speak privately, which is how critical infrastructure prefers it.
Two decades across upstream, refining, and petrochemicals in the GCC and Asia — from wellhead RTUs to plant-wide DCS estates.
Vessel and port OT security delivered under class-society and IMO expectations — where connectivity risk sails with the ship.
Assurance you can trust is done in PPE, and AI you can trust is built beside the people who run the process. Both are how we work.
Our assessments happen on rig decks, vessel bridges, and plant floors — walking zones and conduits physically, verifying what drawings claim, and talking to the operators who live with the systems every shift.
Our engineers embed inside your operation — sitting with planners, operators, and engineers to map real workflows first, then building AI agents around them: localised, human-gated, and shaped to how your plant actually runs.
Independent assurance is our core service: telling you, with evidence, whether your OT environment is as secure as your paperwork says it is.
Structured, standards-based assurance of your OT environment — zone-and-conduit risk assessment, control validation, compliance audit, and evidence-backed findings scored by probability × consequence across safety, environment, financial, and reputational impact. Independent, vendor-neutral, and written for both the boardroom and the control room.
Purdue-model segmentation, DMZ design, remote access, and industrial network transport reviewed against how attacks actually move — not how diagrams look.
IEC 62443-aligned policies, procedures, and security programs mapped to regional regulation — written to be operated by your teams, not filed away.
OT-specific response plans, playbooks, and tabletop exercises that respect a running plant: you cannot simply pull the plug on a live process.
Security engineered into capital projects from FEED and detail design through cyber FAT at vendor factories, cyber SAT during commissioning, pre-startup review, and secure as-built handover.
Independent, capability-scored evaluation of OT security vendors and packages — and prioritised remediation roadmaps sequenced around turnarounds, legacy constraints, and operational risk.
OT cybersecurity training for engineers, operators, and leadership — grounded in the standards and incidents that shape your sector.
We don't sell AI. We engineer it to work safely where it matters: localised language models deployed on your infrastructure, inside your security perimeter — air-gapped where required — so nothing about your plant ever leaves your plant.
Local LLMs on your hardware, in your data centre or at the edge. No cloud dependency, no external API calls, no data egress. Suitable for air-gapped and sovereign environments.
Nothing generated by a model reaches an OT system without explicit human authorisation. Approval gates are enforced in the architecture — not promised in a policy.
Every input, output, and approval is logged and traceable. If a regulator or operator asks "why", the evidence trail already exists.
On the ground in the UAE, serving oil & gas, petrochemical, and utility operators across the GCC — aligned to UAE NESA/IAS and regional regulatory expectations.
WhatsApp +971 50 358 6277 →MeruEPC Pte. Ltd. — our registered base and Asia hub, serving maritime, ports, and energy clients across Southeast Asia and the wider APAC region.
WhatsApp +65 9642 7273 →VyomEPC Private Limited — our India entity, delivering SCADA and engineering support, instrumentation & automation cybersecurity, and OT expert services to pipeline and energy operators across India.
contact@meruepc.com →A single assessment, a full assurance program, or a question about running AI safely inside your OT environment — reach us directly. We respond fast.