SPC / SPC-02
IoT and building-system security
Identify and secure connected equipment often managed outside IT: cameras, access control, sensors or building-management systems. The service connects ownership, networking, updates and data protection.

WHEN IT HELPS
A focused response
to a defined need.
Equipment installed by multiple suppliers, shared passwords, internet-exposed devices, dependence on vendor cloud or no maintenance owner.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Inventory
- ownership
- interfaces
- accounts
- updates
- networks
- supplier access
- cloud services
- data storage
- end of life
- removal procedure
Deliverables
- Asset map
- security assessment
- segmentation plan
- priority configurations
- supplier requirements
- maintenance register
- non-destructive tests
- replacement plan
Acceptance evidence
Owners are identified; management interfaces are restricted; access is tested; data is protected; end of support is documented; incompatible devices are isolated or scheduled for replacement.
DELIVERY
How the work is structured.
Approach
Verify expertise and authorisation; scope constraints; collect without unapproved risk; assess and propose; validate with competent owners.
Prerequisites & responsibilities
Customer: decision authority, operators, control engineers or transaction leads as applicable. Provider: validated expertise; specialist partners where needed and approved.
Scope factors
Sites, systems, safety, evidence access, independence and qualification requirements. Bespoke engagement; effort and subcontracting confirmed before proposal.
Questions to clarify
Who owns and maintains each device? What data does it collect? Can it operate if the vendor or its cloud becomes unavailable?
IMPORTANT BOUNDARIES
Equipment may affect safety, privacy and building operations. Tests and changes must be coordinated with relevant owners and suppliers.
Delivery is conditional on the specialist resources, authorisations and framework requirements established during scoping. Formal qualifications and clearance are confirmed where required.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
Headquarters has cameras on its office network. Project: review accounts, remote access and segmentation. Target outcome: restricted administration and verified separation, with specific handling of footage and retention.
Scenario 02
A company relies on a supplier for connected heating. Project: inventory cloud access and prepare continuity. Target outcome: clear responsibilities and recovery; unresolved supplier dependence is explicitly accepted or addressed.
Technology and reference context
References: OT and personal-data security; device- and version-specific guidance, without assuming a standard agent can be installed.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
