Can this system reach that asset?
A network path being available does not by itself establish authorization for a particular engineering activity.
ENGINEERING AUTHORIZATION FOR INDUSTRIAL ENVIRONMENTS
EWSP is an authorization and evidence layer for privileged industrial engineering activity. It evaluates the engineering context surrounding activity against industrial assets, makes an authorization decision, can enforce that decision locally, and preserves evidence of what was evaluated and what occurred.
Policy-based authorization Local enforcement Explainable evidence
THE PROBLEM
Industrial organizations already protect networks, endpoints, identities and remote access. Segmentation, firewalls, EDR, application allowlisting, PAM, remote access controls and OT network monitoring each answer an important question. Privileged engineering work raises another one: what is trusted engineering software actually authorized to do to an industrial asset?
A network path being available does not by itself establish authorization for a particular engineering activity.
A trusted workstation or application does not by itself establish authorization for every industrial engineering action.
THE MISSING SECURITY BOUNDARY
EWSP addresses this authorization boundary.
WHAT EWSP DOES
EWSP evaluates the context, decides, enforces locally and keeps the evidence, so engineering authorization no longer depends on assumption.
EWSP evaluates the context surrounding privileged engineering activity, including the relevant workstation, application, project or artifact, target asset, requested activity and authorization evidence where available.
EWSP applies explicit policy to engineering context and produces an explainable authorization decision, and can incorporate scoped authorization evidence into that decision.
EWSP can incorporate explicit evidence about the requested engineering operation into authorization decisions, while distinguishing reported operation evidence from evidence considered sufficient for authorization. EWSP does not assume every requested engineering operation can currently be identified from every industrial engineering tool.
EWSP can enforce the resulting decision at the engineering workstation before protected communication reaches the target asset.
EWSP is experimentally validating a persistent local protection boundary for protected engineering communications. In controlled lab testing, the boundary remained active during an unexpected authorization agent interruption, preventing new protected engineering connections until normal authorization operation was restored. The mechanism also includes a standalone recovery path designed to prevent persistent protection from becoming an unrecoverable workstation lockout.
EWSP preserves an explainable record of the context, the authorization decision, the enforcement result and available operational evidence.
EWSP can detect relevant changes in governed engineering state and require reevaluation where supported. Where supported evidence is available, it can compare intended or approved engineering state with observed deployed state.
EWSP preserves engineering activity context to support investigation, reconciliation and recovery workflows.
HOW EWSP WORKS · HIGH LEVEL
A conceptual view of where EWSP sits. It is not a description of the software’s internal components.
SEE EWSP DECIDE
Recorded from the actual product: EWSP evaluates the engineering context, denies a session that does not satisfy the required authorization condition, then permits one that does.
HOW EWSP FITS WITH EXISTING OT SECURITY
It is designed to sit alongside the controls an industrial organization already relies on, not to replace them.
Endpoint trust can contribute to engineering authorization. It does not replace engineering authorization.
BROWNFIELD BY DESIGN
EWSP is built around brownfield plants, where existing engineering tools, networks and controllers stay in place.
No. It complements them.
Yes. Observation and review come before selective enforcement, where supported by the current product.
Compatibility with particular engineering tools and controllers is established during validation, not assumed. EWSP does not claim universal compatibility.
EVIDENCE AND GOVERNANCE
EWSP is designed to preserve a protected local record so an engineering decision can be understood and reviewed afterward.
Recorded
Read-only integration interfaces can expose governed engineering evidence to approved enterprise workflows.
EWSP may generate evidence that is useful to governance and compliance workflows. It does not provide certification, and it does not by itself establish compliance with IEC 62443, NERC CIP, or any other framework.
CURRENT PRODUCT STATUS
An honest view of maturity, so a reader knows exactly what exists today.
A native Windows engineering authorization and local enforcement platform.
Authorization, enforcement, evidence and selected governance capabilities demonstrated in controlled test environments.
Industrial design partner and pilot validation using real engineering workflows and industrial assets.
This capability remains experimental and opt-in. Validation currently applies to the tested IPv4, new-connection scenario; reboot behavior, broader lifecycle paths including uninstall, interoperability across engineering tools, and validation in production deployments remain future milestones.
EWSP has not yet been validated in production plants, across the range of vendor engineering tools, or at PLC scale.
LOW-RISK ADOPTION
You are not expected to install EWSP and immediately start blocking engineers. Observation and review come first; enforcement is added only where you choose.
VALIDATION AND PROOF
Controlled technical validation is not production deployment. Detailed validation results are shared privately during technical diligence and pilot discussions.
DESIGN PARTNERS AND PILOTS
EWSP is seeking industrial operators, OT cybersecurity teams, automation organizations and experienced design partners to validate the engineering authorization boundary in real engineering workflows.