Port254 is the principal-led advisory of Tony Kirui (ISA/IEC 62443 Expert, CISSP, OSCP, OSEP), built on two decades securing networks and industrial environments, most recently at principal level in Australian critical infrastructure. We advise African critical-infrastructure operators on OT/ICS security, IEC 62443 alignment, and the AI systems now entering that same environment.
The compliance deadlines have passed. The bigger risk isn't the paperwork. It's SCADA, energy-management and industrial-control environments that were never designed to be internet-adjacent, now converging with IT faster than most operators' security programmes have kept up. We work on the operational-technology layer that IT security firms don't cover.
Asset identification, zone and conduit modelling, and target security level assessment for SCADA, DCS, and industrial control environments: the foundation every other engagement builds on.
Learn More →IEC 62443 is the only international standard purpose-built for industrial control systems. We hold all four ISA/IEC 62443 Expert certificates and turn the standard into a resourced remediation programme.
Learn More →Pre-audit assessment against Form CMCA 6, the prescribed NC4 audit template, plus risk register, CISO designation support, and compliance report drafting.
Learn More →IT/OT boundary design, zone-and-conduit network architecture, and remote and vendor access review: the networking depth most cybersecurity-only advisors don't have.
Learn More →OSCP- and OSEP-certified, operations-safe penetration testing of SCADA, ICS, and IT/OT boundary systems, without disrupting a live process.
Learn More →OSAI-certified adversarial testing and hardening guidance for AI models and agents entering operational and critical-infrastructure environments.
Learn More →Port254 is one credentialed principal who has held the operational and engineering role, not just the audit role, and who is available directly, not delegated to a graduate team.
CCNP-grounded networking depth and IEC 62443 standards expertise, not a checklist stretched over an unfamiliar environment.
OSCP and OSEP certified: the same person who designs the architecture can test it, rather than handing that off to a separate team.
Principal-level experience in Australian critical infrastructure, applied directly to Africa's energy, water, transport and financial-sector operators.
The conversation worth having is about the operational-technology layer, not just the compliance file.