Control System Security Services
exida & Byres Research Control System Security Experience
- Background
exida and Byres Research deliver consulting, coaching, tools, and training to support users, manufacturers and engineering contractors in the cost-effective use of new technology for safety-related, cyber security and highly dependable applications.
- Qualifications
The Security Professionals at exida & Byres Research have at a minimum the following qualifications:
- Have at least 15 years of experience in industrial automation and control system safety and security design, implementation and assessment
- Experience in assessing or developing security solutions in the Oil & Gas, Electrical Utility, Chemical, Water & Waste Water and other industries that rely heavily on the use of industrial automation and control systems
- Experience with National Energy Reliability Council (NERC) standards and Federal Energy Regulatory Commission (FERC) rulings on power utility security
- Several personnel have achieved the following certifications:
- Security Certified Network Specialist (SCNS)
- Security+ (CompTIA Certification)
- Certified Functional Safety Expert (CFSE)
The following are brief professional biographies of some of our key control system cyber security experts. Full CV’s are available upon request.
Byres, Eric PE - Canada
Eric Byres is a senior partner in Byres Research, which merged with exida in March 2009, and CTO of Byres Security. One of the world’s leading experts in critical infrastructure security, Eric has been responsible for numerous standards, best practices and innovations for control systems security. Eric’s work spans academic and industry domains. As the founder of the BCIT Critical Infrastructure Security Centre, he shaped it into one of North America’s leading academic facilities in the field of SCADA cyber security. At the same time, Eric has provided guidance to government security agencies and consulted with major energy companies on cyber protection for critical infrastructures. Eric is the chair of the ISA SP99 Security Technologies Working Group and the Canadian representative for IEC TC65/WG13, a standards effort focusing on an international framework for the protection of process facilities from cyber attack.
Cusimano, John CFSE - USA
John Cusimano is director of exida’s security services division. A process automation safety and security expert with more than twenty years of experience, John leads a team devoted to improving the security of control systems for companies worldwide. Prior to joining exida, John led market development for Siemens’ process automation and safety products and held various product marketing positions at Moore Products Co. John started his career at Eastman Kodak Company, where he implemented and managed automation projects. John has a B.S. degree in Electrical & Computer Engineering from Clarkson University and holds a CFSE and CISSP certification.
Grebe, John CFSE - USA
John Grebe has over 26 years of experience in industrial and medical instrumentation. He has a wide breadth of experience encompassing New Product Development (both hardware and software), Manufacturing Engineering, Manufacturing Test, Quality Control, Process Definition, Process Improvement, Field Service and Customer Support and specializes in services and products to assist companies in cost effective development of safety-related products. He was formerly the Senior Director of Product Development for a firm creating decision support software for the Chemical Process Industries. Previous experience also includes over 10 years with a North American firm in the process control industry holding a variety of positions including Director of Systems Engineering, which he founded, and Director of Embedded Products. As an engineer his areas of expertise include functional safety, low-level analog signal acquisition, microprocessors and software architecture. Additional industry experience includes flow meter design for an industry leader. He holds nine U.S. patents on products in the process control industry. Mr. Grebe has taught for the ISA professional courses on safety and reliability. He also teaches topics in Engineering Management as an Adjunct Instructor for Drexel University’s Masters Program in Engineering Management. Mr. Grebe has a BSEE and a MSEE from Drexel University and a MBA from Villanova University.
Medoff, Michael CFSE, CISA - USA
Michael is a Functional Safety & Security expert responsible for incorporating industry best practices for the security development lifecycle and the safety development lifecycle into a common process. He is certified to perform Achilles level 1 certification tests on industrial controllers. He consults with clients on improving their product development process to become compliant with ISO/IEC 51408, IEC 61508 and ISA Secure functional safety and security development lifecycle best practices. He analyzes existing development process and document gaps between current process and security development lifecycle best practices and advises clients on methods to improve process and close gaps. He also prepares safety and security cases providing arguments and evidence that a product or system meets the requirement for a given SIL or SAL level and teaches courses on IEC 61508, IEC 61511, ISO/IEC 51408 and ISO 26262 safety standards.
Michael holds a Masters in Business Administration from Penn State University, a M. S. in Computer Engineering from Villanova University and a B. S. in Electrical Engineering from Cornell University.
Stauffer, Todd - USA
Todd Stauffer is responsible for exida’s alarm management products, services, and training portfolio. He has over 15 years of process control experience with applications in the chemical, pulp & paper, food & beverage, and life sciences industries. He is an editor and voting member of the ISA-18.2 standards committee on alarm management.
Prior to joining exida, he worked for Siemens Energy & Automation and Moore Products in various product management, marketing, consulting, and project engineering roles. He was the company’s subject matter expert on alarm management, HMI design, and control system security – publishing several papers and articles on these topics.

