OT cybersecurity assurance for the plants that can't stop

Independent OT security assurance for energy and maritime operators across the Middle East and Asia — built on IEC 62443, delivered by people who have worked control rooms, platforms, and vessels for over two decades.

Industries we serve
Maritime Offshore Onshore EPC
INGEST ASSESS REPORT AI AGENT SWARM · ENERGY WORKFLOWS HUMAN GATE EVIDENCE · MAPPING · COMPLIANCE · REPORTING — AUTOMATED
Offshore oil platform silhouetted against a sunset
OT Assessments · Rig · Vessel · FPSO · FLNG
Offshore & onshore — where we assess
Products & services

Where we assist

CyberCommando — AI-powered OT security assessment platform
Platform

CyberCommando

AI-powered OT security assessment platform. Zero-footprint collection from your OT estate, structured evidence review, consistent IEC 62443 scoring, and audit-ready reports — weeks of assessment work compressed into days.

  • Zero-footprint collector — no agents left behind
  • Evidence-linked findings, human-reviewed
  • Assessment-to-report automation
Request a demo
MeruAI
AI services

MeruAI for OT

OT-localised LLMs and agentic automation deployed on your infrastructure — on-premise or air-gapped, human-approved, fully auditable. Automates evidence review, compliance mapping, and reporting.

How it works →
Assessment services

OT security assessments

Risk assessments, gap assessments, and architecture reviews for rigs, plants, vessels, FPSOs, and renewables — IEC 62443 zone & conduit method, P×C scored, evidence-backed.

Scope & method →
Offensive services

OT penetration testing

Plant-safe adversarial testing: passive analysis on live systems, active exploitation only in FAT, staging, and offline replicas. Real attack-path validation without risking a running process.

Discuss scope →
Maritime compliance

UR E26 / E27 cyber services

IACS UR E26/E27 readiness for newbuilds and fleets: vessel asset mapping, control implementation, test & acceptance design, and class-notation evidence packs — aligned to IMO MSC.428(98).

Maritime track record →
Training · MeruShield

Cybersecurity training

Fifteen expert-led programs across five tracks — OT, Maritime, Corporate, Family, and Intelligence — from ICS/OT fundamentals and CyberHAZOP to UR E26/E27 resilience. Delivered worldwide, in-person or virtual.

View training catalogue (PDF)
20+
Years in OT / ICS security
3
Hubs — Abu Dhabi · Singapore · Chennai
60+
Assessments, audits & programs delivered
7
Standards & regulatory frameworks applied
Domain reputation

Trusted where energy meets water

Our track record was built inside national oil companies, petrochemical complexes, ports, and classed vessels — not conference rooms. We don't name clients. Our references speak privately, which is how critical infrastructure prefers it.

Energy

Two decades across upstream, refining, and petrochemicals in the GCC and Asia — from wellhead RTUs to plant-wide DCS estates.

  • OT assurance programs for national-scale oil & gas operators
  • DCS, SIS, and packaged-system security assessments on live plants
  • Secure MPLS / industrial transport architecture assurance
  • IEC 62443 & UAE regulatory alignment, end to end

Maritime

Vessel and port OT security delivered under class-society and IMO expectations — where connectivity risk sails with the ship.

  • IEC 62443-based vessel OT assessments for tankers and carriers
  • IACS UR E26/E27 and IMO MSC.428(98) compliance frameworks
  • VSAT / satcom vendor and connectivity risk assessments
  • Port & terminal OT governance from prior operator-side roles
In the field

On the deck, in the plant — not just on paper

Assurance you can trust is done in PPE, and AI you can trust is built beside the people who run the process. Both are how we work.

Offshore crew in orange coveralls and PPE on site

Assessors in PPE, where the risk lives

Our assessments happen on rig decks, vessel bridges, and plant floors — walking zones and conduits physically, verifying what drawings claim, and talking to the operators who live with the systems every shift.

Engineer building software and workflows on screen

Forward-deployed AI engineers

Our engineers embed inside your operation — sitting with planners, operators, and engineers to map real workflows first, then building AI agents around them: localised, human-gated, and shaped to how your plant actually runs.

Services

Assurance first. Everything else follows.

Independent assurance is our core service: telling you, with evidence, whether your OT environment is as secure as your paperwork says it is.

Core service

OT security assurance & audit

Structured, standards-based assurance of your OT environment — zone-and-conduit risk assessment, control validation, compliance audit, and evidence-backed findings scored by probability × consequence across safety, environment, financial, and reputational impact. Independent, vendor-neutral, and written for both the boardroom and the control room.

02

Architecture assurance

Purdue-model segmentation, DMZ design, remote access, and industrial network transport reviewed against how attacks actually move — not how diagrams look.

03

Governance & compliance

IEC 62443-aligned policies, procedures, and security programs mapped to regional regulation — written to be operated by your teams, not filed away.

04

Incident response readiness

OT-specific response plans, playbooks, and tabletop exercises that respect a running plant: you cannot simply pull the plug on a live process.

05

EPC lifecycle cybersecurity

Security engineered into capital projects from FEED and detail design through cyber FAT at vendor factories, cyber SAT during commissioning, pre-startup review, and secure as-built handover.

06

Vendor evaluation & remediation

Independent, capability-scored evaluation of OT security vendors and packages — and prioritised remediation roadmaps sequenced around turnarounds, legacy constraints, and operational risk.

07

Training & capability

OT cybersecurity training for engineers, operators, and leadership — grounded in the standards and incidents that shape your sector.

MeruAI — Secure. Smart. Human
OT-localised AI

AI that stays inside the fence

We don't sell AI. We engineer it to work safely where it matters: localised language models deployed on your infrastructure, inside your security perimeter — air-gapped where required — so nothing about your plant ever leaves your plant.

OT and AI — stronger together: an OT worker and an AI agent joining hands on a rising curve
Sovereignty

On-premise by design

Local LLMs on your hardware, in your data centre or at the edge. No cloud dependency, no external API calls, no data egress. Suitable for air-gapped and sovereign environments.

Safety

Human-approved actions

Nothing generated by a model reaches an OT system without explicit human authorisation. Approval gates are enforced in the architecture — not promised in a policy.

Accountability

Auditable end to end

Every input, output, and approval is logged and traceable. If a regulator or operator asks "why", the evidence trail already exists.

Applied in our tooling: I-CAIRA · compliance intelligence CyberCommando · assessment automation CyberEquipe · governance workflows
Presence

Three hubs. One standard of work.

🇦🇪

Abu Dhabi

Middle East operations

On the ground in the UAE, serving oil & gas, petrochemical, and utility operators across the GCC — aligned to UAE NESA/IAS and regional regulatory expectations.

WhatsApp +971 50 358 6277 →
🇸🇬

Singapore

Asia headquarters

MeruEPC Pte. Ltd. — our registered base and Asia hub, serving maritime, ports, and energy clients across Southeast Asia and the wider APAC region.

WhatsApp +65 9642 7273 →
🇮🇳

Chennai

India operations · VyomEPC
VyomEPC — Your Cyber Armor

VyomEPC Private Limited — our India entity, delivering SCADA and engineering support, instrumentation & automation cybersecurity, and OT expert services to pipeline and energy operators across India.

contact@meruepc.com →
Contact

Start with a conversation

A single assessment, a full assurance program, or a question about running AI safely inside your OT environment — reach us directly. We respond fast.