ENGINEERING AUTHORIZATION FOR INDUSTRIAL ENVIRONMENTS

Govern the engineering session, not only the workstation.

EWSP is an authorization and evidence layer for privileged industrial engineering activity. It evaluates the engineering context surrounding activity against industrial assets, makes an authorization decision, can enforce that decision locally, and preserves evidence of what was evaluated and what occurred.

Policy-based authorization Local enforcement Explainable evidence

THE PROBLEM

A network path is not an engineering authorization.

Industrial organizations already protect networks, endpoints, identities and remote access. Segmentation, firewalls, EDR, application allowlisting, PAM, remote access controls and OT network monitoring each answer an important question. Privileged engineering work raises another one: what is trusted engineering software actually authorized to do to an industrial asset?

CONNECTIVITY

Can this system reach that asset?

A network path being available does not by itself establish authorization for a particular engineering activity.

ENGINEERING AUTHORIZATION

Is this activity permitted for this asset, in this context?

A trusted workstation or application does not by itself establish authorization for every industrial engineering action.

THE MISSING SECURITY BOUNDARY

The layer between a trusted workstation and an industrial asset.

NetworksWhat can communicate
EndpointsWhat is trusted
Identities and remote accessWho can obtain privileged access
Engineering authorization EWSPWhat privileged engineering activity is authorized for this asset, in this engineering context

EWSP addresses this authorization boundary.

WHAT EWSP DOES

One authorization boundary for privileged engineering activity.

EWSP evaluates the context, decides, enforces locally and keeps the evidence, so engineering authorization no longer depends on assumption.

ENGINEERING CONTEXT

Understands the activity around the connection

EWSP evaluates the context surrounding privileged engineering activity, including the relevant workstation, application, project or artifact, target asset, requested activity and authorization evidence where available.

AUTHORIZATION

Policy-based, explainable decisions

EWSP applies explicit policy to engineering context and produces an explainable authorization decision, and can incorporate scoped authorization evidence into that decision.

ENGINEERING OPERATION CONTEXT

Operation evidence, without overstating it

EWSP can incorporate explicit evidence about the requested engineering operation into authorization decisions, while distinguishing reported operation evidence from evidence considered sufficient for authorization. EWSP does not assume every requested engineering operation can currently be identified from every industrial engineering tool.

LOCAL ENFORCEMENT

Decisions that take effect

EWSP can enforce the resulting decision at the engineering workstation before protected communication reaches the target asset.

PERSISTENT PROTECTION BOUNDARY

A protection boundary designed to survive an interruption

EWSP is experimentally validating a persistent local protection boundary for protected engineering communications. In controlled lab testing, the boundary remained active during an unexpected authorization agent interruption, preventing new protected engineering connections until normal authorization operation was restored. The mechanism also includes a standalone recovery path designed to prevent persistent protection from becoming an unrecoverable workstation lockout.

EVIDENCE

A record that explains itself

EWSP preserves an explainable record of the context, the authorization decision, the enforcement result and available operational evidence.

INTEGRITY

Change is not silently absorbed

EWSP can detect relevant changes in governed engineering state and require reevaluation where supported. Where supported evidence is available, it can compare intended or approved engineering state with observed deployed state.

RECOVERY AND INVESTIGATION

Context that survives the event

EWSP preserves engineering activity context to support investigation, reconciliation and recovery workflows.

HOW EWSP WORKS · HIGH LEVEL

Context, decision, enforcement, evidence.

A conceptual view of where EWSP sits. It is not a description of the software’s internal components.

Engineer or engineering team
Engineering workstationApplication · Project · Engineering context
EWSPEngineering Authorization
ContextPolicyDecision
PERMIT
Industrial asset
DENY / WITHHOLD
Protected communication does not proceed
Engineering evidenceContext, decision, enforcement result and observed outcome
Failure behavior. EWSP separates authorization failures, evidence uncertainty and enforcement failures so unavailable evidence is not silently treated as authorization. Current protection behavior is designed to avoid silently permitting protected activity when EWSP cannot establish the required authorization or enforcement state. EWSP tests failure and recovery behavior rather than assuming it. See Current Product Status for what has been measured to date.

SEE EWSP DECIDE

A real engineering session, evaluated, denied, then permitted.

Recorded from the actual product: EWSP evaluates the engineering context, denies a session that does not satisfy the required authorization condition, then permits one that does.

HOW EWSP FITS WITH EXISTING OT SECURITY

EWSP complements existing OT security.

It is designed to sit alongside the controls an industrial organization already relies on, not to replace them.

OT network securityhelps determine what can communicate.
Endpoint securityhelps determine whether a workstation or application is trusted.
PAM and remote access controlshelp govern who can obtain privileged access.
EWSPfocuses on the engineering authorization context surrounding privileged activity against industrial assets.

Endpoint trust can contribute to engineering authorization. It does not replace engineering authorization.

BROWNFIELD BY DESIGN

Designed for the industrial environments that already exist.

EWSP is built around brownfield plants, where existing engineering tools, networks and controllers stay in place.

  • Local Windows deployment on the engineering workstation.
  • Designed so the current enforcement model does not require redesigning the controls network.
  • No PLC logic modification is required for current workstation-side enforcement.
  • Existing engineering tools remain the engineering tools.
  • EWSP is not inserted into the process-control loop.
  • Adoption can begin without immediately enforcing blocks.
Does it replace my firewall, EDR or PAM?

No. It complements them.

Can we begin without blocking engineers?

Yes. Observation and review come before selective enforcement, where supported by the current product.

Compatibility with particular engineering tools and controllers is established during validation, not assumed. EWSP does not claim universal compatibility.

EVIDENCE AND GOVERNANCE

An explainable record of what was evaluated and what happened.

EWSP is designed to preserve a protected local record so an engineering decision can be understood and reviewed afterward.

Recorded

  • Engineering context
  • Authorization decision
  • Policy result
  • Enforcement outcome
  • Project or artifact evidence, where available
  • Industrial asset evidence, where available
  • Operational outcome, where observed
  • Recovery and reconciliation evidence, where available

Read-only integration interfaces can expose governed engineering evidence to approved enterprise workflows.

EWSP may generate evidence that is useful to governance and compliance workflows. It does not provide certification, and it does not by itself establish compliance with IEC 62443, NERC CIP, or any other framework.

CURRENT PRODUCT STATUS

Working software. Controlled validation. Pilot next.

An honest view of maturity, so a reader knows exactly what exists today.

WORKING SOFTWARE

Built

A native Windows engineering authorization and local enforcement platform.

CONTROLLED VALIDATION

Lab validated

Authorization, enforcement, evidence and selected governance capabilities demonstrated in controlled test environments.

NEXT MILESTONE

Pilot validation

Industrial design partner and pilot validation using real engineering workflows and industrial assets.

  1. Built
  2. Lab validated
  3. Pilot validated next
  4. Production validated not yet
Protection continuity. EWSP has completed controlled lab validation of an experimental, opt-in persistent protection boundary. In the measured test, the boundary remained active throughout an approximately 62 second service recovery interval following an unexpected authorization agent interruption, and no successful new protected connection was observed during that interval, across 12 attempts. In the same kind of interval without this experimental capability, new connections have been observed succeeding immediately. Standalone emergency removal and clean protection reconstruction afterward were also validated.

This capability remains experimental and opt-in. Validation currently applies to the tested IPv4, new-connection scenario; reboot behavior, broader lifecycle paths including uninstall, interoperability across engineering tools, and validation in production deployments remain future milestones.

EWSP has not yet been validated in production plants, across the range of vendor engineering tools, or at PLC scale.

LOW-RISK ADOPTION

Begin with evidence. Add enforcement deliberately.

OBSERVE
REVIEW
SELECTIVELY ENFORCE
VALIDATE

You are not expected to install EWSP and immediately start blocking engineers. Observation and review come first; enforcement is added only where you choose.

VALIDATION AND PROOF

Demonstrated in controlled environments.

  • Contextual authorization demonstrated
  • Authorized and unauthorized communication demonstrated
  • Local enforcement demonstrated
  • Engineering project integrity monitoring demonstrated
  • Explainable evidence and audit records demonstrated
  • Controlled backup and recovery behavior demonstrated
  • Persistent protection boundary continuity during an unexpected agent interruption demonstrated (experimental)

Controlled technical validation is not production deployment. Detailed validation results are shared privately during technical diligence and pilot discussions.

DESIGN PARTNERS AND PILOTS

Validate the engineering authorization boundary in a real workflow.

EWSP is seeking industrial operators, OT cybersecurity teams, automation organizations and experienced design partners to validate the engineering authorization boundary in real engineering workflows.

contact@ewsp.org