Cybersecurity engineered for critical infrastructure
Fractal EMS protects your assets with a defense-in-depth program built on NIST 800-53 and Zero Trust — owned and operated by our in-house U.S. team, with no reliance on hardware from Foreign Entities of Concern.
ISO/IEC 27001
Certified information-security management system
Zero Trust
Enforced across both IT & OT networks
U.S.-developed software
Built & maintained in-house, never offshored
No FEOC hardware
No components from Foreign Entities of Concern
Your energy storage assets are critical infrastructure, and we treat them that way. Fractal's cybersecurity program is built on the NIST 800-53 control framework and a Zero Trust model that verifies every user, device, and connection across your IT and OT networks. It's designed, run, and continuously improved by our own team — not outsourced — so security stays accountable and onshore.
How we protect your systems
Access & identity
MFA for access, comms & account management
PKI device authentication
Least-privilege under Zero Trust
Network security
Layered security zones (Levels 0–4)
Firewall-enforced boundary & IDS
DDoS protection
IT / OT segmentation
Data protection
TLS 1.3 in transit with certificate auth
Encryption at rest
Controlled customer-data handling
Threat detection & monitoring
Real-time monitoring of OS, config, firmware & CVEs
Malware & ransomware protection
Auditable logging with retention
Vulnerability & risk
Penetration & vulnerability testing
Independent ISO 27001 assessment
Built on NIST 800-53 controls
Incident response
In-house team to detect, contain & recover
Defined customer-notification process
Configuration & change
Change management with controls & escalation
Network asset-inventory control
Supply-chain integrity
No offshore software development
No hardware from Foreign Entities of Concern
Governance & compliance
ISO 27001 & 9001 certified
Documented cybersecurity policies
Awareness training & phishing testing
Resilience & recovery
Encrypted, redundant data backups
Defined data retention & recovery process
Disaster-recovery planning & testing
Layered security zones
We segment the control environment into firewall-separated zones (Levels 0–4), so a compromise in one layer cannot reach the devices that actually run your plant. Traffic between zones is inspected and restricted to only what each layer needs.
| Zone | What lives there |
|---|---|
| Level 0 — Field devices | Sensors, actuators & metering at the equipment |
| Level 1 — Basic control | Unit-level controllers and the Power Plant Controller |
| Level 2 — Supervisory control | EMS server & HMI supervising site operations |
| Level 3 — Site operations | Historian, logging & site networking infrastructure |
| Level 4 — Enterprise / remote | Firewalled external connectivity & remote access |
Secure by supply chain
Security starts before a single line of code runs. Fractal's software is developed and maintained entirely in-house in the United States — never offshored — and our deployments do not rely on hardware from Foreign Entities of Concern. That gives you a controls platform you can trust end to end, from source code to silicon.
Fractal EMS maintains ISO/IEC 27001:2022 (information security) and ISO 9001:2015 (quality) certifications, independently audited and current.
View our certifications →

NERC CIP Medium–compliant
Learn about our 24/7 Remote Operations Center
Your assets are monitored around the clock from our in-house ROC in Austin, Texas — staffed to detect, escalate, and respond to events in real time.
Explore our operations →
Want to review our security posture for your project?
Request a proposal
