Connectivity for plants and remote sites, and the boundary between the process network and the office one.
A plant network is not a small office network. It inverts the usual priorities: availability first, because a stopped line costs money every minute; equipment that has been in service for a decade and will stay for another; and protocols that were designed when the network was assumed to be physically private, so they authenticate nothing.
You cannot re-architect that away. The engineering is in the boundary you put around it.
The link between the plant and the office is segmented, authenticated and logged. Segmented so a compromise on one side does not become a compromise on the other. Authenticated so the tunnel knows who is at each end. Logged so that afterwards there is an answer to what happened, rather than a theory.
None of that is exotic. What makes it engineering rather than configuration is deciding what may cross the boundary at all, and being able to justify each exception to somebody who will ask.
NIS2 and the Cyber Resilience Act changed what the sector has to be able to demonstrate, not just what it has to do. Most of the cost is not new equipment: it is evidence, and evidence is only cheap if the system was built to produce it.
Alongside that I am taking the organisation itself to ISO 27001, writing the policies, procedures and evidence single-handedly. The hard part is not the document set. It is writing something the business will actually follow, because a control nobody performs is worse than no control: it is a control you believe you have.
No topology, no vendor list, no site count, no addressing, no exception list. That is not modesty, it is the point: a description precise enough to be useful to an attacker is a description I should not have written.
Work carried out under NDA. This page describes the engineering, not the employer. No employer names, internal architectures, client details or proprietary systems appear anywhere on this site, and none will be added.