The Ogólnopolski Kongres Energetyczno-Ciepłowniczy — POWERPOL — was organised by Europejskie Centrum Biznesu and held under the honorary patronage of the Ministry of Digital Affairs, the Ministry of Energy, the Ministry of State Assets, the Ministry of Climate and Environment, and the Ministry of Agriculture and Rural Development. Aurora Media Hub covered it, and one of the conversations worth writing up was with Andrzej Cieślak of Dynacon, on cybersecurity in the energy sector with the emphasis firmly on operational technology (OT) — the systems that physically run plant, rather than the systems that hold data about it.
Dynacon is established in protecting onshore Polish critical infrastructure, working across major energy and industrial assets including large-scale power generation and utility environments. What made the conversation interesting was Cieślak’s stated ambition to take that expertise offshore, where the operating environment is far less forgiving and the consequences of an incident are higher.

Why OT security is a different problem offshore
The discussion centred on the systems that actually run an offshore asset, and where OT-focused security applies to them:
- PLCs (programmable logic controllers)
- DCS (distributed control systems) and SCADA (supervisory control and data acquisition)
- Vessel control systems — dynamic positioning, propulsion, power management
- Subsea control systems
- Offshore wind turbine control systems
- Safety-critical systems — emergency shutdown, fire and gas
These are the systems that physically run the asset. A cyber event here does not only affect data. It affects operations, safety and asset integrity.
Local defence in a disconnected world
Cieślak described how Dynacon implements security inside the industrial environment itself, using a local or remote node architecture that can monitor, analyse and counter threats on site rather than depending on a link back to a security operations centre ashore.
That is the part that translates most directly offshore. Continuous external connectivity cannot be assumed on a vessel or an offshore structure, which makes autonomous local defence less of a design preference and more of a requirement.
Continuous connectivity cannot be assumed offshore, which makes autonomous local defence a requirement rather than a preference.
Designed in, not retrofitted
The theme Cieślak returned to was security by design. Dynacon’s preferred model is early involvement during the concept, design and build phases of offshore vessels and infrastructure. Engineered in from day one, security becomes a coherent integrated environment; added later it becomes a collection of retrofitted solutions. Dynacon can implement protection later in an asset’s life, but that typically means bespoke adaptation to OT systems that were never specified with it in mind.

What it looks like from the deck
From an offshore perspective this lands. Across projects, sensitive operational data — vessel systems, positioning data, subsea layouts, procedural knowledge — is routinely spread across multiple platforms with varying levels of protection. VPNs, project servers and poor connectivity are where the practical breakdowns happen, and they happen on the working end of the job rather than in a policy document.
Dynacon’s stated scope covers the full lifecycle: integration and monitoring through to analysis, mitigation and response, with the option of acting as server host to reduce fragmentation across an asset.
Why we asked these questions
Many of the systems in that conversation are ones we have worked around offshore for years. That background is what let the interview go past the pitch and into real operational scenarios — how security behaves on a vessel with a degraded link, not how it looks on a slide. It is the difference between covering a conference and reporting from one.
Thanks to Andrzej Cieślak and the Dynacon team for the time.
Reported from POWERPOL 2026, Warsaw, February 2026. Photography by Aurora Media Hub. Technical descriptions of Dynacon’s architecture and scope are as presented by the company.


