Who this work is for.
Engineering practices, equipment suppliers, fabricators, contractors and industrial project teams exchanging technical files and working with external vendors.
Trace the project information and its owners.
We review where approved drawings, CAD models, vendor packages and commercial records are stored and shared. Identify authoritative revisions, internal owners, external recipients and the accounts that can change or download a package. The review separates business IT from operational technology and records the responsible team for each environment.
Make external access deliberate.
Scoped implementation can organise project workspaces, narrow sharing permissions, enable the agreed sign-in protections and document vendor onboarding and offboarding. We can help replace shared credentials with accountable access where the chosen platform supports it, and define when a supplier’s access should expire or be reviewed.
Plan changes and recovery around the work.
Review backup ownership, retention, restoration steps and the project records needed to resume work. Agreed business IT configuration or update work follows the owner’s approval, maintenance window, rollback plan and verification steps. Recovery exercises can use selected non-production files so the team can practise without disrupting a live project.
Keep operational technology under its own process.
Any OT-related assessment is limited to an expressly agreed review with the asset owner and responsible engineering or operations team. Start with approved documentation, asset and access inventories, and existing change-control processes. The standard service does not include live OT or PLC scanning, active probing, control-system changes or safety-system intervention.
A possible first engagement.
A supplier workspace for an approved drawing package.
Review a project folder shared with several suppliers. Identify the approved revision, separate internal working files from the issued package, set agreed recipient permissions and access-review dates, and document offboarding and restoration. Any implementation is checked with the file owner before wider use.
Illustrative scope, not a client case study or promised outcome.
What the handoff can include.
- A project information and access map, distinguishing business IT and OT boundaries.
- A prioritised review and roadmap for file sharing, vendor access and agreed business IT controls.
- Scoped workspace or account configuration, with change approval and verification records.
- Staff guidance, vendor access procedures and a recovery plan for the agreed files and systems.
Agree on access, changes and review.
The review can stand alone or lead to an implementation phase. Before access, we agree on the systems and owners, permitted actions, deliverables, price, timing and review steps. Configuration changes need the owner’s approval, a verification plan and a rollback path. The handoff records remaining issues, who maintains the agreed controls and the next review date. Any agreed restore test records the sample, result and unresolved exceptions.
Scope and service boundaries.
We work only within the authorised project scope. Technical design approval and operational safety decisions remain with the responsible professionals and asset owners. Continuous monitoring, emergency incident response, penetration testing and production OT work are not included in the standard service. Specialist engagements must identify the responsible provider, qualifications and operating process before access.
Prepare the first conversation.
Describe the project files, business IT platforms, external participants and access concerns. Share a redacted inventory first, not credentials or confidential drawings. Identify the IT owner and any OT boundary before discussing technical access.
Based in Sherwood Park, Alberta. Meet locally by appointment or discuss the work remotely across Canada. Confirm language needs and an appropriate secure transfer method before sharing confidential material.
Questions about the engagement.
Can you put the agreed controls in place?
Yes. We can configure the agreed business IT or file-sharing controls, document changes and train the team within a written scope. Platform capability, authorisation, maintenance and rollback arrangements are checked first.
Will you scan PLCs or change a live control system?
No. The standard service does not include live OT or PLC scanning or control-system changes. An OT-related assessment must be explicitly scoped with the asset owner and responsible team, using their review and change-control process.
Useful guidance.
These are public reference resources, not certifications or claimed partnerships. The proposal defines the controls and evaluation included in your project.