Aurora Media Hub
All insights

Conference & Interviews

Cybersecurity by Design for Offshore Energy

At POWERPOL 2026 in Warsaw we sat down with Andrzej Cieślak of Dynacon to talk about operational technology security — and what changes when the asset you are defending spends weeks at a time without a reliable link to shore.

Daniel “Rusty” Russell4 min read
Andrzej Cieślak of Dynacon speaking at the POWERPOL 2026 congress in Warsaw
Andrzej Cieślak of Dynacon speaking at the POWERPOL 2026 congress in Warsaw. Photo: Aurora Media Hub.

The Ogólnopolski Kongres Energetyczno-Ciepłowniczy — POWERPOL — was organised by Europejskie Centrum Biznesu and held under the honorary patronage of the Ministry of Digital Affairs, the Ministry of Energy, the Ministry of State Assets, the Ministry of Climate and Environment, and the Ministry of Agriculture and Rural Development. Aurora Media Hub covered it, and one of the conversations worth writing up was with Andrzej Cieślak of Dynacon, on cybersecurity in the energy sector with the emphasis firmly on operational technology (OT) — the systems that physically run plant, rather than the systems that hold data about it.

Dynacon is established in protecting onshore Polish critical infrastructure, working across major energy and industrial assets including large-scale power generation and utility environments. What made the conversation interesting was Cieślak’s stated ambition to take that expertise offshore, where the operating environment is far less forgiving and the consequences of an incident are higher.

Andrzej Cieślak beside the Dynacon stand at the POWERPOL 2026 congress
Andrzej Cieślak at POWERPOL 2026, Warsaw. Photo: Aurora Media Hub.

Why OT security is a different problem offshore

The discussion centred on the systems that actually run an offshore asset, and where OT-focused security applies to them:

  • PLCs (programmable logic controllers)
  • DCS (distributed control systems) and SCADA (supervisory control and data acquisition)
  • Vessel control systems — dynamic positioning, propulsion, power management
  • Subsea control systems
  • Offshore wind turbine control systems
  • Safety-critical systems — emergency shutdown, fire and gas

These are the systems that physically run the asset. A cyber event here does not only affect data. It affects operations, safety and asset integrity.

Local defence in a disconnected world

Cieślak described how Dynacon implements security inside the industrial environment itself, using a local or remote node architecture that can monitor, analyse and counter threats on site rather than depending on a link back to a security operations centre ashore.

That is the part that translates most directly offshore. Continuous external connectivity cannot be assumed on a vessel or an offshore structure, which makes autonomous local defence less of a design preference and more of a requirement.

Continuous connectivity cannot be assumed offshore, which makes autonomous local defence a requirement rather than a preference.

Designed in, not retrofitted

The theme Cieślak returned to was security by design. Dynacon’s preferred model is early involvement during the concept, design and build phases of offshore vessels and infrastructure. Engineered in from day one, security becomes a coherent integrated environment; added later it becomes a collection of retrofitted solutions. Dynacon can implement protection later in an asset’s life, but that typically means bespoke adaptation to OT systems that were never specified with it in mind.

Andrzej Cieślak mid-answer during a panel session at POWERPOL 2026
POWERPOL 2026, Warsaw. Photo: Aurora Media Hub.

What it looks like from the deck

From an offshore perspective this lands. Across projects, sensitive operational data — vessel systems, positioning data, subsea layouts, procedural knowledge — is routinely spread across multiple platforms with varying levels of protection. VPNs, project servers and poor connectivity are where the practical breakdowns happen, and they happen on the working end of the job rather than in a policy document.

Dynacon’s stated scope covers the full lifecycle: integration and monitoring through to analysis, mitigation and response, with the option of acting as server host to reduce fragmentation across an asset.

Why we asked these questions

Many of the systems in that conversation are ones we have worked around offshore for years. That background is what let the interview go past the pitch and into real operational scenarios — how security behaves on a vessel with a degraded link, not how it looks on a slide. It is the difference between covering a conference and reporting from one.

Thanks to Andrzej Cieślak and the Dynacon team for the time.


Reported from POWERPOL 2026, Warsaw, February 2026. Photography by Aurora Media Hub. Technical descriptions of Dynacon’s architecture and scope are as presented by the company.


About Aurora Media Hub

Aurora Media Hub is a Poland-registered media team built by offshore people. We produce documentary-grade coverage inside fabrication yards, on the water and offshore, where conventional crews cannot operate. No stock footage, no staged framing, just the work as it actually is.

Filming a campaign like this?