MicroSec's OT/IoT cybersecurity platform

OVERVIEW

MicroSec (founded 2016, Singapore) builds cybersecurity for Operational Technology and Industrial IoT — the sensors, PLCs, controllers and networks that run ships, factories, power grids and smart buildings. Its core technology is patented across five jurisdictions, and the company was featured as a top vendor in Forrester's Operational Technology Security Solutions Landscape, Q1 2024.

Unlike IT security, this world has physics working against it: the devices being protected have 250,000× smaller memory, 100× lower computing power, and 2,000× lower bandwidth than the servers mainstream security tools were designed for. Many run bare metal or FreeRTOS and speak industrial protocols like Modbus, BACnet, DNP3 or LoRaWAN.

MicroIDS — Monitoring Suite

AI intrusion detection: asset discovery, real-time threat detection with ML anomaly models, automated mitigation and remediation.

CyberAssessor

AI-driven compliance automation against IEC 62443, IACS UR E26/E27, NIST, Essential Eight, AESCSF — audit-ready reports in minutes.

LCMS — Protection Suite

Device identity & lifecycle: lightweight PKI, quantum-safe certificates, MicroAgent hardening, signed firmware updates.

YEAR

2024

Role

Product Designer —

end-to-end

Focus

Research · IA · Design system · Data-viz

Three user problems, three design constraints

The interface is itself a security control:
if the operator misreads the screen, the design has failed exactly when it mattered most.

"I can't see what I own"

OT networks accrete devices over decades. Operators can't protect assets they can't enumerate — and active scanning can crash fragile field devices, so discovery itself is risky.

"I can't act fast enough"

When an anomaly fires at 3 a.m. on a vessel or plant floor, the responder is an OT engineer, not a SOC analyst. Alert walls without prioritized, safe next-steps get ignored.

"Compliance eats my year"

Frameworks like IEC 62443 span hundreds of controls. Assessments are manual, spreadsheet-driven, error-prone, and stale the moment they're finished.

Control-room conditions

Dark environments, wall-mounted displays, long monitoring sessions. Legible at distance, easy on the eyes for hours — hence the near-black canvas and high-chroma signal colors.

Severity is sacred

Red, orange, green may only ever mean threat, warning, safe. No decorative use of semantic colors anywhere — a mismatched red is a safety hazard, not a style bug.

One language, three products

MicroIDS, CyberAssessor and LCMS must feel like one console — shared shell, shared components, shared data-viz grammar.

Who actually sits in front of this UI

The OT Engineer — "Ravi"


  • Owns uptime first, security second

  • Fears any tool that touches live devices

  • Needs: passive visibility, plain-language alerts, one-click safe mitigations

The Compliance Officer — "Mei"


  • Lives in IEC 62443 / class-society checklists

  • Drowning in evidence-gathering spreadsheets

  • Needs: auto-mapped controls, gap lists, audit-ready exports

The CISO — "Daniel"


  • Accountable for OT + IT posture across sites

  • Buys platforms, not point tools

  • Needs: fleet-level posture score, trends, defensible board reporting


Key insights

Discovery must be passive-first

Asset discovery defaults to passive listening; active probing is opt-in and clearly labeled — the map builds itself without endangering devices.

Alerts without actions are noise

Every detection carries a severity, an explanation, and an automated mitigation option with status tracking and false-positive feedback.

Compliance is continuous, not annual

Posture is a live dashboard mapped to framework controls, not a yearly PDF — "audit-ready" becomes a permanent state.

Brownfield beats greenfield

Onboarding assumes heterogeneous, legacy, protocol-diverse networks — never a clean slate.

Air-gapped is a real constraint

The same UI ships as SaaS (Cloud) and on-prem (Core); nothing in the interface can depend on external calls.

The token layer

Why cyan? Every other high-visibility hue carries a semantic meaning. Blue-cyan is the only color on a dark canvas with no alarm connotation — so it can safely mean "interactive" everywhere, while inheriting the brand mark's shield-blue.

The network map

Network Map + Threat List. The canonical MicroIDS screen: force-directed topology on the left, triage panel on the right.

Breadcrumb depth as context. "MicroSec › Maritime › Network Map › Force Directed" — the trail doubles as scope indicator (org → site → view → layout mode), critical when one CISO monitors many sites.



Red glow = pre-attentive threat detection. Compromised nodes get a soft red halo scaled to look "radioactive" against the dark canvas — visible from across a control room before reading a single word.

Map and list stay side by side. The same incident visible spatially and textually at once; selecting either highlights the other — no context switch to triage.

Toolbar shows layout modes, not tools. Force-directed is the default because brownfield OT networks rarely match their official diagrams.

Counts as reassurance. The "39" badge next to filters answers "am I seeing everything?" — a trust device, not decoration.

The dashboard

Dashboard — Threat tab, with the threat-detail slide-over open on the left.

The gauge answers first. "Overall Threat Score 7/10 · Medium" in orange — one glance, one number, one word. Everything else is elaboration.

Numbers wear their severity. 25 High set in red, 20 Medium in orange — the numeral itself is the status indicator, no icon needed.

Tabs split audiences, not features. Device / Threat / Compliance mirror the three roles who open this page.

Timeline proves the trend. "Is it getting worse?" is every stakeholder's second question, so it's the second thing on the page.

Threat detail

Threat detail. Score card → impacted devices → MITRE-mapped explanation → insights timeline.

Plain-language first, MITRE second. The description reads like a colleague explaining it; the T0856 chip is one click deeper for the specialist. Progressive disclosure keyed to persona.

The OPEN chip is a red outline, not a fill. Status must be visible but can't out-shout severity; outline chips sit one visual level below filled semantic color.

Tabs carry counts. "Devices (1) · Threats (10)" — the tab bar is itself a summary of blast radius.

Segmented insights. Timeline / Frequency / Top Impacted Devices — three analytical lenses without leaving the incident.

CyberAssessor

Compliance results. 58% posture score, IEC 62443 foundational-requirement list, distribution donut, criticality scatter.

Design System

Design

Information Architecture

User Flow & wireframe

Evaluative research

Phase 1

Phase 2

Map: Before implementation, officers relied on pdf maps or had to visit specific car parks to determine where CCTVs and gantries were located

Lots allocation

There are many types of parking lots, and officers reported that there was no overview of what kinds of lots specific car parks have

Data visualization

To improve consistency and efficiency of the design system,
I was responsible for creating new components that were used by other designers and engineers

Retrospective

What I would do differently: I would advocate for implementing sprint-based work during the discovery stage to better manage workload and deadlines. Instead, we only adopted sprints once engineering investigation and implementation began.

Lessons: This was my first project with a government client, and I discovered that government operations differ fundamentally from those of tech companies. While private sector projects are driven by business impact and scale, government projects prioritize public officers' and residents' satisfaction. Instead of focusing purely on business metrics, the emphasis is on creating smooth operations and positive experiences for both civil servants and residents.

Tradeoff: One of the calculated risks I helped the team decide on was using an open-source design system instead of building our own. I partnered with an engineering lead to choose the most flexible and usable option for our project. This approach allowed us to focus on solving real officers' problems rather than reinventing standard components. The team's velocity improved significantly, though we occasionally had to work around the design system's limitations to meet specific requirements.

MicroSec's OT/IoT cybersecurity platform

OVERVIEW

MicroSec (founded 2016, Singapore) builds cybersecurity for Operational Technology and Industrial IoT — the sensors, PLCs, controllers and networks that run ships, factories, power grids and smart buildings. Its core technology is patented across five jurisdictions, and the company was featured as a top vendor in Forrester's Operational Technology Security Solutions Landscape, Q1 2024.

Unlike IT security, this world has physics working against it: the devices being protected have 250,000× smaller memory, 100× lower computing power, and 2,000× lower bandwidth than the servers mainstream security tools were designed for. Many run bare metal or FreeRTOS and speak industrial protocols like Modbus, BACnet, DNP3 or LoRaWAN.

MicroIDS — Monitoring Suite

AI intrusion detection: asset discovery, real-time threat detection with ML anomaly models, automated mitigation and remediation.

CyberAssessor

AI-driven compliance automation against IEC 62443, IACS UR E26/E27, NIST, Essential Eight, AESCSF — audit-ready reports in minutes.

LCMS — Protection Suite

Device identity & lifecycle: lightweight PKI, quantum-safe certificates, MicroAgent hardening, signed firmware updates.

YEAR

2024

Role

Product Designer —

end-to-end

Focus

Research · IA · Design system · Data-viz

Three user problems, three design constraints

The interface is itself a security control:
if the operator misreads the screen, the design has failed exactly when it mattered most.

"I can't see what I own"

OT networks accrete devices over decades. Operators can't protect assets they can't enumerate — and active scanning can crash fragile field devices, so discovery itself is risky.

"I can't act fast enough"

When an anomaly fires at 3 a.m. on a vessel or plant floor, the responder is an OT engineer, not a SOC analyst. Alert walls without prioritized, safe next-steps get ignored.

"Compliance eats my year"

Frameworks like IEC 62443 span hundreds of controls. Assessments are manual, spreadsheet-driven, error-prone, and stale the moment they're finished.

Control-room conditions

Dark environments, wall-mounted displays, long monitoring sessions. Legible at distance, easy on the eyes for hours — hence the near-black canvas and high-chroma signal colors.

Severity is sacred

Red, orange, green may only ever mean threat, warning, safe. No decorative use of semantic colors anywhere — a mismatched red is a safety hazard, not a style bug.

One language, three products

MicroIDS, CyberAssessor and LCMS must feel like one console — shared shell, shared components, shared data-viz grammar.

Who actually sits in front of this UI

The OT Engineer — "Ravi"


  • Owns uptime first, security second

  • Fears any tool that touches live devices

  • Needs: passive visibility, plain-language alerts, one-click safe mitigations

The Compliance Officer — "Mei"


  • Lives in IEC 62443 / class-society checklists

  • Drowning in evidence-gathering spreadsheets

  • Needs: auto-mapped controls, gap lists, audit-ready exports

The CISO — "Daniel"


  • Accountable for OT + IT posture across sites

  • Buys platforms, not point tools

  • Needs: fleet-level posture score, trends, defensible board reporting


Key insights

Discovery must be passive-first

Asset discovery defaults to passive listening; active probing is opt-in and clearly labeled — the map builds itself without endangering devices.

Alerts without actions are noise

Every detection carries a severity, an explanation, and an automated mitigation option with status tracking and false-positive feedback.

Compliance is continuous, not annual

Posture is a live dashboard mapped to framework controls, not a yearly PDF — "audit-ready" becomes a permanent state.

Brownfield beats greenfield

Onboarding assumes heterogeneous, legacy, protocol-diverse networks — never a clean slate.

Air-gapped is a real constraint

The same UI ships as SaaS (Cloud) and on-prem (Core); nothing in the interface can depend on external calls.

The token layer

Why cyan? Every other high-visibility hue carries a semantic meaning. Blue-cyan is the only color on a dark canvas with no alarm connotation — so it can safely mean "interactive" everywhere, while inheriting the brand mark's shield-blue.

The network map

Network Map + Threat List. The canonical MicroIDS screen: force-directed topology on the left, triage panel on the right.

Breadcrumb depth as context. "MicroSec › Maritime › Network Map › Force Directed" — the trail doubles as scope indicator (org → site → view → layout mode), critical when one CISO monitors many sites.



Red glow = pre-attentive threat detection. Compromised nodes get a soft red halo scaled to look "radioactive" against the dark canvas — visible from across a control room before reading a single word.

Map and list stay side by side. The same incident visible spatially and textually at once; selecting either highlights the other — no context switch to triage.

Toolbar shows layout modes, not tools. Force-directed is the default because brownfield OT networks rarely match their official diagrams.

Counts as reassurance. The "39" badge next to filters answers "am I seeing everything?" — a trust device, not decoration.

The dashboard

Dashboard — Threat tab, with the threat-detail slide-over open on the left.

The gauge answers first. "Overall Threat Score 7/10 · Medium" in orange — one glance, one number, one word. Everything else is elaboration.

Numbers wear their severity. 25 High set in red, 20 Medium in orange — the numeral itself is the status indicator, no icon needed.

Tabs split audiences, not features. Device / Threat / Compliance mirror the three roles who open this page.

Timeline proves the trend. "Is it getting worse?" is every stakeholder's second question, so it's the second thing on the page.

Threat detail

Threat detail. Score card → impacted devices → MITRE-mapped explanation → insights timeline.

Plain-language first, MITRE second. The description reads like a colleague explaining it; the T0856 chip is one click deeper for the specialist. Progressive disclosure keyed to persona.

The OPEN chip is a red outline, not a fill. Status must be visible but can't out-shout severity; outline chips sit one visual level below filled semantic color.

Tabs carry counts. "Devices (1) · Threats (10)" — the tab bar is itself a summary of blast radius.

Segmented insights. Timeline / Frequency / Top Impacted Devices — three analytical lenses without leaving the incident.

CyberAssessor

Compliance results. 58% posture score, IEC 62443 foundational-requirement list, distribution donut, criticality scatter.

Design System

Design

Information Architecture

User Flow & wireframe

Evaluative research

Phase 1

Phase 2

Map: Before implementation, officers relied on pdf maps or had to visit specific car parks to determine where CCTVs and gantries were located

Lots allocation

There are many types of parking lots, and officers reported that there was no overview of what kinds of lots specific car parks have

Data visualization

To improve consistency and efficiency of the design system,
I was responsible for creating new components that were used by other designers and engineers

Retrospective

What I would do differently: I would advocate for implementing sprint-based work during the discovery stage to better manage workload and deadlines. Instead, we only adopted sprints once engineering investigation and implementation began.

Lessons: This was my first project with a government client, and I discovered that government operations differ fundamentally from those of tech companies. While private sector projects are driven by business impact and scale, government projects prioritize public officers' and residents' satisfaction. Instead of focusing purely on business metrics, the emphasis is on creating smooth operations and positive experiences for both civil servants and residents.

Tradeoff: One of the calculated risks I helped the team decide on was using an open-source design system instead of building our own. I partnered with an engineering lead to choose the most flexible and usable option for our project. This approach allowed us to focus on solving real officers' problems rather than reinventing standard components. The team's velocity improved significantly, though we occasionally had to work around the design system's limitations to meet specific requirements.

MicroSec's OT/IoT cybersecurity platform

OVERVIEW

MicroSec (founded 2016, Singapore) builds cybersecurity for Operational Technology and Industrial IoT — the sensors, PLCs, controllers and networks that run ships, factories, power grids and smart buildings. Its core technology is patented across five jurisdictions, and the company was featured as a top vendor in Forrester's Operational Technology Security Solutions Landscape, Q1 2024.

Unlike IT security, this world has physics working against it: the devices being protected have 250,000× smaller memory, 100× lower computing power, and 2,000× lower bandwidth than the servers mainstream security tools were designed for. Many run bare metal or FreeRTOS and speak industrial protocols like Modbus, BACnet, DNP3 or LoRaWAN.

MicroIDS — Monitoring Suite

AI intrusion detection: asset discovery, real-time threat detection with ML anomaly models, automated mitigation and remediation.

CyberAssessor

AI-driven compliance automation against IEC 62443, IACS UR E26/E27, NIST, Essential Eight, AESCSF — audit-ready reports in minutes.

LCMS — Protection Suite

Device identity & lifecycle: lightweight PKI, quantum-safe certificates, MicroAgent hardening, signed firmware updates.

YEAR

2024

Role

Product Designer —

end-to-end

Focus

Research · IA · Design system · Data-viz

Three user problems, three design constraints

The interface is itself a security control:
if the operator misreads the screen, the design has failed exactly when it mattered most.

"I can't see what I own"

OT networks accrete devices over decades. Operators can't protect assets they can't enumerate — and active scanning can crash fragile field devices, so discovery itself is risky.

"I can't act fast enough"

When an anomaly fires at 3 a.m. on a vessel or plant floor, the responder is an OT engineer, not a SOC analyst. Alert walls without prioritized, safe next-steps get ignored.

"Compliance eats my year"

Frameworks like IEC 62443 span hundreds of controls. Assessments are manual, spreadsheet-driven, error-prone, and stale the moment they're finished.

Control-room conditions

Dark environments, wall-mounted displays, long monitoring sessions. Legible at distance, easy on the eyes for hours — hence the near-black canvas and high-chroma signal colors.

Severity is sacred

Red, orange, green may only ever mean threat, warning, safe. No decorative use of semantic colors anywhere — a mismatched red is a safety hazard, not a style bug.

One language, three products

MicroIDS, CyberAssessor and LCMS must feel like one console — shared shell, shared components, shared data-viz grammar.

Who actually sits in front of this UI

The OT Engineer — "Ravi"


  • Owns uptime first, security second

  • Fears any tool that touches live devices

  • Needs: passive visibility, plain-language alerts, one-click safe mitigations

The Compliance Officer — "Mei"


  • Lives in IEC 62443 / class-society checklists

  • Drowning in evidence-gathering spreadsheets

  • Needs: auto-mapped controls, gap lists, audit-ready exports

The CISO — "Daniel"


  • Accountable for OT + IT posture across sites

  • Buys platforms, not point tools

  • Needs: fleet-level posture score, trends, defensible board reporting


Key insights

Discovery must be passive-first

Asset discovery defaults to passive listening; active probing is opt-in and clearly labeled — the map builds itself without endangering devices.

Alerts without actions are noise

Every detection carries a severity, an explanation, and an automated mitigation option with status tracking and false-positive feedback.

Compliance is continuous, not annual

Posture is a live dashboard mapped to framework controls, not a yearly PDF — "audit-ready" becomes a permanent state.

Brownfield beats greenfield

Onboarding assumes heterogeneous, legacy, protocol-diverse networks — never a clean slate.

Air-gapped is a real constraint

The same UI ships as SaaS (Cloud) and on-prem (Core); nothing in the interface can depend on external calls.

The token layer

Why cyan? Every other high-visibility hue carries a semantic meaning. Blue-cyan is the only color on a dark canvas with no alarm connotation — so it can safely mean "interactive" everywhere, while inheriting the brand mark's shield-blue.

The network map

Network Map + Threat List. The canonical MicroIDS screen: force-directed topology on the left, triage panel on the right.

Breadcrumb depth as context. "MicroSec › Maritime › Network Map › Force Directed" — the trail doubles as scope indicator (org → site → view → layout mode), critical when one CISO monitors many sites.



Red glow = pre-attentive threat detection. Compromised nodes get a soft red halo scaled to look "radioactive" against the dark canvas — visible from across a control room before reading a single word.

Map and list stay side by side. The same incident visible spatially and textually at once; selecting either highlights the other — no context switch to triage.

Toolbar shows layout modes, not tools. Force-directed is the default because brownfield OT networks rarely match their official diagrams.

Counts as reassurance. The "39" badge next to filters answers "am I seeing everything?" — a trust device, not decoration.

The dashboard

Dashboard — Threat tab, with the threat-detail slide-over open on the left.

The gauge answers first. "Overall Threat Score 7/10 · Medium" in orange — one glance, one number, one word. Everything else is elaboration.

Numbers wear their severity. 25 High set in red, 20 Medium in orange — the numeral itself is the status indicator, no icon needed.

Tabs split audiences, not features. Device / Threat / Compliance mirror the three roles who open this page.

Timeline proves the trend. "Is it getting worse?" is every stakeholder's second question, so it's the second thing on the page.

Threat detail

Threat detail. Score card → impacted devices → MITRE-mapped explanation → insights timeline.

Plain-language first, MITRE second. The description reads like a colleague explaining it; the T0856 chip is one click deeper for the specialist. Progressive disclosure keyed to persona.

The OPEN chip is a red outline, not a fill. Status must be visible but can't out-shout severity; outline chips sit one visual level below filled semantic color.

Tabs carry counts. "Devices (1) · Threats (10)" — the tab bar is itself a summary of blast radius.

Segmented insights. Timeline / Frequency / Top Impacted Devices — three analytical lenses without leaving the incident.

CyberAssessor

Compliance results. 58% posture score, IEC 62443 foundational-requirement list, distribution donut, criticality scatter.

Design System

Design

Information Architecture

User Flow & wireframe

Evaluative research

Phase 1

Phase 2

Map: Before implementation, officers relied on pdf maps or had to visit specific car parks to determine where CCTVs and gantries were located

Lots allocation

There are many types of parking lots, and officers reported that there was no overview of what kinds of lots specific car parks have

Data visualization

To improve consistency and efficiency of the design system,
I was responsible for creating new components that were used by other designers and engineers

Retrospective

What I would do differently: I would advocate for implementing sprint-based work during the discovery stage to better manage workload and deadlines. Instead, we only adopted sprints once engineering investigation and implementation began.

Lessons: This was my first project with a government client, and I discovered that government operations differ fundamentally from those of tech companies. While private sector projects are driven by business impact and scale, government projects prioritize public officers' and residents' satisfaction. Instead of focusing purely on business metrics, the emphasis is on creating smooth operations and positive experiences for both civil servants and residents.

Tradeoff: One of the calculated risks I helped the team decide on was using an open-source design system instead of building our own. I partnered with an engineering lead to choose the most flexible and usable option for our project. This approach allowed us to focus on solving real officers' problems rather than reinventing standard components. The team's velocity improved significantly, though we occasionally had to work around the design system's limitations to meet specific requirements.

Create a free website with Framer, the website builder loved by startups, designers and agencies.