MICKAI®SectorsCritical Infrastructure, Maritime and Energy
Team
Sector · Off-grid intelligence for the systems a nation cannot afford to lose.

Critical Infrastructure, Maritime and Energy

Grid operators, port and maritime authorities, generators and pipeline operators want to run modern AI over their SCADA logs, OT telemetry and network schematics, yet NIS 2 and NERC CIP treat that data as too sensitive to place on commercial cloud, and IEC 62443 expects operational technology to stay isolated from internet-facing systems. The cloud route is effectively barred, so the analysis either does not happen or happens on spreadsheets and tribal knowledge. Mickai brings the full AI stack inside the isolated control room, on hardware the operator owns and under keys the operator holds. Predictive maintenance, vulnerability analysis and threat simulation run against live OT data while that data never leaves the building.

The problem and our solution
The buyer

Critical-infrastructure, maritime and energy operators running OT, SCADA and bulk-grid systems under national resilience mandates.

The problem

NIS 2, NERC CIP and IEC 62443 forbid OT schematics and grid data on commercial cloud, stranding these operators without a compliant path to modern AI.

Our sovereign solution

Mickai installs the entire AI stack inside the isolated control room, on owned hardware under the operator's own keys, running independent of the internet and cloud vendors.

The value

Predictive maintenance, vulnerability analysis and threat simulation run against live OT data on-site, which removes the third-party cloud-exposure vector for that data while the operator keeps its own physical, insider and regulatory controls.

The sovereign advantages

These architectural choices support control over the workflows in your deployment. Their benefits depend on configuration, integrations and operating practices. Review external connections, physical security, access and compliance responsibilities together.

Control the processing boundary

Scope inference, extraction, retrieval and storage on infrastructure you control. Document and test any external connector, support channel or transfer before describing a workflow as zero-egress.

Plan for disconnected work

Workflows with local models, data and supporting services can continue offline. Live external email, calendars and other services need an approved connection or controlled import, with clear unavailable and pending states.

Make data location inspectable

Map prompts, documents, indexes, logs and backups to their processing and storage locations. Local hosting supports control of location; access, retention and any transfers still need review.

Use approved company knowledge

Prepare and classify source records, preserve permissions and evaluate answers against the originals. Retrieval and model training are separate choices; agree data use and licences for each.

Budget for the whole service

Compare hardware and licences alongside integration, power, administration, support, updates, evaluation and recovery. Measure cost at the required workload and quality before claiming savings.

Verify access and authority

Define who holds keys, who can administer the system and which actions need approval. Test denied requests, revoked access and audit records. Physical security, insider risk and incident response remain operational responsibilities.

Control change and exit

Agree version selection, signed update procedures, rollback, data export and licence rights. Reassess requirements as software and obligations change; owning hardware does not remove maintenance or compliance work.

Requirements to assess

Review the requirements relevant to your organisation, jurisdiction and intended use with your responsible teams. Cloud services can be appropriate subject to applicable safeguards; on-premise deployment alone does not establish compliance or remove supplier responsibilities.

NIS 2 Directive (EU network and information systems security for essential entities)
NERC CIP (North American bulk electric system critical infrastructure protection)
IEC 62443 (industrial automation and control systems cyber security)
National critical national infrastructure (CNI) and operator-of-essential-services regimes
Sector regulators for energy, ports and water and their resilience reporting duties
Organisations of this profile

The kind of organisation this serves, named illustratively from public information to characterise the market. These are target profiles, not customers: Mickai has no relationship, engagement, trial, or endorsement with any of them.

National GridEDF EnergyMaerskport and harbour authorities
The lead studios

The enterprise studios that lead in this sector, drawn from the eighteen that sit on the one sovereign substrate. Scope their local processing, operator-held keys and Open Audit Record coverage for the proposed deployment. Confirm availability and any external integrations before relying on a workflow.

Department studio

Predictive Maintenance and OT

Runs predictive maintenance and failure analysis over SCADA and OT telemetry inside the air-gapped control room, so plant and grid data is modelled where it sits rather than shipped to a vendor cloud.

Department studio

Fraud and Anomaly Detection

Performs off-grid anomaly detection and threat simulation across control-system logs, flagging abnormal command and sensor patterns without exposing the topology of the network to any external system.

Department studio

Compliance and Regulator Mode

Maps activity to NIS 2, NERC CIP and IEC 62443 obligations and produces regulator-ready evidence on-site, removing the cross-border-transfer and third-party-processing friction while the operator keeps its own duties.

Department studio

Audit

Holds an immutable on-premise audit trail of every model query and access event, so incident investigators and auditors can reconstruct what happened without that record ever touching the public internet.

Department studio

Executive BI

Gives control-room leadership and the board a sovereign view of asset health, threat posture and resilience metrics, drawn from OT data that stays entirely within the facility.

See all eighteen on the sovereign services catalogue.

The opportunity

Critical-infrastructure operators are under simultaneous pressure to modernise ageing OT estates with AI and to keep that same data off commercial cloud, a tension that mainstream hyperscaler offerings cannot resolve. That leaves a large, regulation-protected segment of energy, maritime and utility operators with strong budgets and few compliant routes to advanced analytics.

The outcome

Measure value, cost and risk on hardware you control.

Operators gain predictive maintenance and threat simulation that were previously off-limits, displacing the recurring cloud-analytics spend they could never safely commit to and reducing unplanned-outage and forced-maintenance exposure. The third-party cloud-exposure vector for OT schematics and grid data is removed; physical and insider controls remain the operator's own, and the regulatory obligations stay with the operator.

Lawful B2B engagement

Map the sovereign stack to your critical infrastructure, maritime and energy estate.

Briefings are for organisations weighing a sovereign, on-premises deployment. Tell us about your estate and we will walk the pack, the regulatory crosswalk, and the deployment that fits your estate.

Other sectors
Retail with customer-data depth
Retail
Law firms and legal-ops
Legal
Banking, insurance, and financial services
Finance
NHS Trusts and private healthcare
Healthcare
Defence and government
Public Sector
Generational discretion and an uncompromised deal edge, on hardware you own.
VCs and Family Offices
Multi-generational wealth, processed entirely inside your own walls.
Private Banking and Wealth
The ledger never leaves the firm.
Accounting, Tax and Audit
Price the risk without surrendering the risk profile.
Insurance and Actuarial
Sovereign discovery infrastructure for assets too valuable to leave the building.
Pharma, Biotech and Pre-patent IP
Quality auditing of device and calibration data that never leaves the building.
Medical Devices
Bunker-grade AI for work that can never touch the public cloud.
Defence, Aerospace and Dual-Use
Your process is your moat. Keep it inside the factory walls.
Heavy Industry, Manufacturing and Semiconductors
Network intelligence that never leaves the core
Telecommunications
Sovereign research intelligence that keeps the IP, and the dual-use risk, on campus.
Academic and University Research
Sift the whole talent pool without the raw records ever leaving your building.
Executive Search and HR
Athlete telemetry and tactics that never leave the training ground.
Elite Sport and Performance
The client black book that never leaves the room.
Luxury, Private Aviation and VIP Concierge
Clienteling and collections held in the house, not the cloud.
Luxury Fashion
Tag every frame on premises, so no pixel ever leaves the studio.
Commercial Photography and Media Houses
Sovereign deal intelligence for the agencies that hold the industry's secrets.
Talent and Literary Agencies
Your catalogue, indexed and searchable, with no master ever leaving the building.
Music Studios and Labels
Source protection that never leaves the newsroom.
Press and Investigative Journalism
The IP lifecycle stays under lock and key, from script to final pixel.
Film, TV and VFX
Safeguarding intelligence that never leaves the trust.
Multi-Academy Trusts (Primary and Secondary)
Where the question paper never leaves the vault until test day.
Examination and Testing Boards
Special-needs records that never leave the setting
SEN and Alternative Provision
Ship native AI for schools without inheriting the data-processing-agreement fight.
EdTech and LMS Vendors