FreedomGRESS
Operators, ports, shipping companies, insurers

Project 528

Security risk reasoning for offshore and maritime infrastructure. The product is the margin between the moment a threat becomes detectable and the moment it becomes damage.

Start a conversation
The base of an offshore turbine in fog; further turbines are barely visible

The problem

Offshore wind farms are cyber-physical systems in a hostile environment, and the threats they face range from weather and equipment failure to deliberate interference with cables, vessels and control systems.

Security assessments for these assets are still largely static: a report is written, a risk register is filled in, and the picture ages from the day it is signed. The environment, meanwhile, changes hourly.

The question an operator actually needs answered is not whether a risk exists. It is how much time remains before it becomes damage, and what changes that number.

What the system does

  • Assesses risk continuously from live and heterogeneous data rather than from a periodic report
  • Adapts the assessment as conditions change — weather, traffic, asset state, sensor availability
  • Flags where detection is weak: the blind spots matter more than the confirmed threats
  • Produces reasoning that can be inspected, not a score without provenance

What it is built on

  • Discrete-time dynamic Bayesian networks for reasoning under uncertainty with explicit probabilities
  • Functional Resonance Analysis (FRAM) to map how normal variability in operations combines into failure
  • Morphological and cross-impact analysis for systematic construction of threat scenarios
  • Machine learning for detection, sitting on top of the quantitative layer rather than replacing it

Who it is for

  • Wind farm operators and owners responsible for uptime and safety
  • Ports and shipping companies whose routes and assets share the same waters
  • Insurers pricing risk for offshore assets, who need assessments they can defend
  • Coastal and maritime security services planning across multiple sites

Why this method

Detectability is the central question

A threat you cannot see early enough is, operationally, a threat you cannot manage. We treat the detection margin as the quantity to be improved, not risk in the abstract.

Uncertainty is stated, not hidden

Bayesian reasoning forces the model to say how confident it is and on what evidence. A number without a stated uncertainty is not a risk assessment.

Normal work, not just accidents

FRAM starts from how operations actually vary under pressure. Most incidents are not caused by one broken part but by ordinary variability resonating across functions.

Questions we are usually asked

Is this an AI product?

Machine learning is used for detection, but the reasoning core is quantitative and explicit. No recommendation is produced that cannot be traced back to evidence and stated probabilities.

Does it replace our existing risk process?

No. It replaces the part of that process that ages between reviews — the live picture. Your risk register, your procedures and your regulator's requirements stay where they are.

What data does it need?

It is built to work with what a site already has: operational and sensor data, traffic and weather feeds, maintenance records. Where a data source is missing, the model says what that costs in detection rather than quietly assuming it away.

Talk to us about your site

The useful first conversation is about a specific asset and a specific decision — not a product demo. Tell us what you are responsible for and what you cannot currently see.

Start a conversation