Security-by-design
Controlling every energy installation securely
An EMS controls batteries, inverters and charging points remotely. That calls for a solid foundation. The Voltmasters EMS is developed to the principles of IEC 62443 and security-by-design, so that security is built in from the design stage rather than bolted on afterwards.
The approach
IEC 62443 and security-by-design
IEC 62443 is the international standard for the cybersecurity of industrial automation and control systems. That is exactly the domain an EMS operates in: it controls physical energy installations. We follow the principles of that standard and apply security-by-design: security is a starting point when designing the architecture, the controller and the platform, not an option you add later.
In practice that means layered protection, from the device in the cabinet to the platform in the cloud. Below we set out the key measures we apply to control your installations, and those of your customers, securely.
The measures
Security on every layer
From encrypted communication to fail-safe behaviour: nine measures that together determine how securely an installation is controlled and monitored remotely.
Encrypted communication
Traffic between the controller, the platform and the app is encrypted. Data in transit stays unreadable to third parties.
Strong authentication
Access to the platform requires strong authentication. Only verified users and devices reach an installation.
Role-based access control
Permissions follow the role: you manage as the installer, your customer follows along with read access. Everyone only sees and does what fits their role.
Audit logging
Important actions are logged. That makes it possible to trace afterwards who changed what and when, which helps with verification and troubleshooting.
Secure remote access
Remote configuration and monitoring run over secure channels, so you can manage an installation safely without going on site.
Secure updates
Software and firmware updates run in a controlled way, so the controller stays up to date and only runs trusted software.
Network segmentation
Systems are shielded from one another, so a problem in one part does not simply spill over into another.
Vulnerability management
We track vulnerabilities and address them in a targeted way, so that security stays up to standard after the installation too.
Fail-safe behaviour
If a connection drops or something goes wrong, the installation falls back to a safe state. The controller keeps working locally, even without internet.
Fail-safe & offline
Keep working safely, even when something fails
The Voltmaster Controller runs the control logic locally in the cabinet. If the internet or the platform drops out for a moment, the installation keeps working safely based on the last known, safe settings. Security goes hand in hand with reliability.
- Local control that continues during an internet outage.
- Fall-back to a safe state within the configured limits and safety margins.
- Automatic recovery and synchronisation as soon as the connection is back.
Frequently asked questions
Security, in short
What does IEC 62443 mean for the Voltmasters EMS?
IEC 62443 is the international standard for the cybersecurity of industrial automation and control systems. Because an EMS controls physical energy installations, we develop to the principles of that standard: layered security from the device in the cabinet to the platform in the cloud.
What does security-by-design mean?
That security is a starting point in the design, not something you add afterwards. The architecture, the controller and the platform are built from the start around secure communication, strong authentication and role-based access.
Does my installation stay safe during an internet outage?
Yes. The Voltmaster Controller runs the control logic locally in the cabinet. If the internet drops out, the installation keeps working safely within the configured limits and safety margins, and everything synchronises automatically once the connection is back.
Who has access to an installation?
Access runs through strong authentication and role-based access control. You manage as the installer, your customer follows along with read access. Everyone only sees and does what fits their role, and important actions are logged.
How is remote management kept secure?
Remote configuration and monitoring happen over encrypted, secure channels. That way you manage an installation safely without going on site, while communication stays unreadable to third parties.
Ready to make your first project pay off?
Tell us about your next installation. We will show you the platform, help you build the business case and guide you from first quote to certification.