Risk Mitigation Framework — Trust, PLC Safety & UNS Resilience
What this is. The deployment risk model for DigiTPME pilots in Moroccan factories. It exists because every conversation we open with a plant — YNNA Steel, Sonasid, OCP Group, Managem Tizert, Lesieur Cristal, Tanger Med — eventually arrives at the same four questions from their automation lead: “Can we trust you near our PLCs? What happens if your broker dies? What does the CNDP say about the data leaving the plant? And what if you’re wrong?”
This document is the standing answer. It binds onto Morocco UNS Standard v0.1 §6 (architecture) and v0.2 §11 (security), and onto the DigiTPME MVP — Product Specification v1 runbook. Read-only first, edge gateway always, UNS never on the control path.
1. Why this is a Moroccan-specific problem, not a generic Industry 4.0 problem
The standard Industry 4.0 risk playbook (cf. Walker Reynolds of 4.0 Solutions, Arlen Nipper on Sparkplug B) assumes a buyer who already trusts the principle and is choosing between vendors. That is not the Moroccan starting position. Three local factors reshape the risk conversation:
- Enterprise distrust of student-led or new-entity work. A founder coming from ENSA Berrechid / UM6P without a track record is not granted the benefit of the doubt by a 30-year-old plant. The first conversation must be defensible to a skeptical automation engineer whose job is on the line if a PLC misbehaves. No amount of architecture diagrams replaces a read-only, supervised pilot in the first phase.
- Regulatory pressure shifts the buyer’s risk appetite. CBAM enters full implementation in 2026; YNNA Steel and Sonasid need exportable carbon data before their next EU shipment cycle, regardless of how comfortable they are with the technology. This compresses the trust-building window — we get less time to prove ourselves but the buyer is more willing to accept a constrained, read-only deployment because it solves a regulatory problem they already have. Use this asymmetry.
- Data sovereignty matters in a way it does not in EU pilots. The CNDP (Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel, Law 09-08) and the DGSSI cybersecurity directive frame what data can be processed where. A foreign-cloud-hosted broker is a non-starter for OCP-tier accounts. Our Made-in-Morocco posture (local hosting, MAD pricing, Arabic+French documentation, see v0.2 §13) is not branding — it is risk reduction for the buyer’s compliance officer.
The four risks below are framed against this Moroccan context, not the generic playbook.
2. Risk 1 — Enterprise trust deficit
2.1 What the buyer is actually afraid of
| Surface fear (what they say) | Real fear (what they mean) |
|---|---|
| “We don’t have time for a pilot" | "If you break our line we lose 200k MAD/hour and I lose my job" |
| "We already have AVEVA / Rockwell Automation / Siemens Energy" | "I do not want to defend an unknown vendor to my CIO when the incumbent already covers us" |
| "Show us a reference" | "Has anyone else in Morocco let students near their PLCs and lived?" |
| "Send us a proposal" | "Give me a paper trail I can put in front of legal and quality” |
2.2 Mitigations — the trust ladder
We climb deliberately. Each rung delivers the buyer a defensible artifact.
| Rung | What we deploy | What the buyer signs | Duration | Pilots that match |
|---|---|---|---|---|
| R0 — Simulation | Factory I/O / CODESYS / Siemens PLCSIM digital twin replicating the target line | NDA + scope letter | 2–3 weeks | Pre-sales for any account |
| R1 — Isolated bench | Real PLC of the target family, on an isolated VLAN in our lab or a corner of theirs, no production data | Pilot kickoff letter, risk register | 2 weeks | YNNA Steel CBAM build phase |
| R2 — Read-only shadow | Edge gateway tapped onto the live network, publish-only on the UNS, no writes to PLC, supervised by a plant engineer | Pilot SOW + cybersecurity attestation aligned with DGSSI guidance | 4–6 weeks | Overlay — Managem Tizert Sparkplug B (their existing Sparkplug B is the lighthouse), Overlay — Sonasid CBAM Pilot |
| R3 — Limited write, non-critical | Same edge gateway, write access only to a non-safety, non-control target (e.g. a setpoint on an auxiliary energy meter, never a process loop) | Change-control sign-off from plant manager + automation lead | 4 weeks | Overlay — Lesieur Cristal energy/Scope 1-2 measurement |
| R4 — Production integration | Full architecture, with v0.2 §11 security envelope and 24/7 runbook | Production acceptance test, formal handover | 12+ weeks | Overlay — OCP Safi Pilot, Overlay — Tanger Med |
Hard rule. No account jumps rungs. The CBAM urgency at YNNA Steel tempts us to skip R0–R1 and go straight to R2; we still build the simulation in week 1 because the SOW depends on it being signed off.
2.3 Specific Moroccan trust accelerators
- Local engineer in the loop, by name. Every pilot SOW names the plant’s automation lead as the supervising engineer with a veto. They co-sign the read-only attestation. This is non-negotiable — the buyer’s organisation needs an internal champion whose career is enhanced by our success, not threatened.
- Reference architecture from Managem Tizert. The first Moroccan plant running Sparkplug B in production gives us a domestic precedent. Until our own pilots are live, this is the answer to “has anyone in Morocco done this?”
- IEIA as the standards body, not us. Conversations frame the Morocco UNS standard as an industry effort (CC-BY-4.0 planned for v1.0) we author and maintain, not a proprietary vendor lock-in. This shifts the buyer from “vetting a vendor” to “adopting a national standard” — a much easier internal sale.
- Documentation in French and Arabic. v0.2 §13 mandates the Arabic transliteration table for UNS paths. Pilot deliverables (runbook, risk register, attestation) ship in French primary + Arabic where the audience is operations-floor.
- MAD pricing, fixed-fee, milestone-billed. Buyers are wary of dollar-denominated SaaS commitments that drift with FX. Every overlay is priced in MAD with milestone invoices (cf. the 600k–800k MAD / 6-week structure on YNNA Steel).
3. Risk 2 — PLC criticality (the system is one bad write away from a stoppage)
3.1 Architectural rule
The UNS is a data bus, not a control bus. PLCs are reachable from the UNS only through an edge gateway, and only with the access mode the rung allows (R0–R2: read-only; R3: limited write to non-critical; R4: governed write under change control).
This is non-negotiable and it tracks the Walker Reynolds 2-step Digital Transformation framework: data first, then twin/AI/control — not the other way around.
3.2 Reference architecture (binds to v0.1 §6)
┌──────────┐ OPC UA / Modbus TCP / S7 / FINS / Sparkplug B
│ PLC │────────────────────┐
│ (S7-1500,│ │ read-only by default
│ CL, │ ▼
│ Omron) │ ┌───────────────────┐
└──────────┘ │ Edge Gateway │
│ (industrial PC, │
│ ruggedised, │
│ on plant VLAN) │
│ │
│ - protocol │
│ adapters │
│ - local buffer │
│ (24h–7d) │
│ - edge identity │
│ (mTLS cert) │
└─────────┬─────────┘
│ MQTT/TLS 1.3 + Sparkplug B
│ signed CBAM envelope (v0.2 §11.6)
▼
┌───────────────────┐
│ UNS Broker │ ┌──────────────────┐
│ cluster │◀───▶│ Replica broker │
│ (HiveMQ / │ │ (failover, DR) │
│ EMQX / Mosq.) │ └──────────────────┘
└─────────┬─────────┘
│ topic-prefix ACL by enterprise
▼
┌─────────────────┴─────────────────┐
▼ ▼
┌────────────┐ ┌────────────┐
│ Analytics │ │ ERP / MES │
│ + CBAM XML │ │ bridge │
│ generator │ │ (MES) │
└────────────┘ └────────────┘
3.3 PLC-side rules
- No firmware change to the PLC during R0–R3. If a tag we need does not exist, we add it as a new read-mapped tag in a separate program block, after change-control sign-off, and only on R3+.
- Network segmentation. Edge gateway lives on the plant VLAN (cell/area zone in ISA-95 / IEC 62443 terms). Broker lives in the site DMZ. Analytics consumers live in the IT zone. Cross-zone traffic only via documented flows.
- Protocol selection by family.
- Siemens S7-1200 / S7-1500: OPC UA (preferred) or S7 over isolated VLAN via Intellic Integration-style connector.
- Allen-Bradley CompactLogix / ControlLogix: OPC UA on the controller’s own server, never EtherNet/IP traffic on the same wire as the UNS.
- Schneider M340 / M580: Modbus TCP read-only, OPC UA where M580 supports it.
- Omron NJ/NX: FINS via the MaestroHub-equivalent open-source stack (fins/Omron reference) — see IIoT Platform Build Intelligence — Open Source Stack 2026.
- Watchdog + dead-man’s switch. If the edge gateway loses heartbeat to the broker for >N seconds, it stops publishing (not the PLC). The PLC keeps running its program regardless of broker state. This is the single most important architectural property.
3.4 Why this is safer than what’s already on the plant floor
Most Moroccan plants we’ve audited already have a half-broken, vendor-specific historian or SCADA-to-cloud pipe wired into the PLC, often with write privileges and weak auth. Our R2 read-only shadow is, on day one, a strict reduction in PLC attack surface compared to what is already there. Frame this in the cybersecurity attestation.
4. Risk 3 — UNS as a single point of failure
4.1 The asymmetry to communicate to the buyer
“If our broker dies, you lose visibility for a few minutes. If our broker were on the control path and died, you would lose the line. This is why we will never put it on the control path.”
The UNS being down is a data outage, not a production outage — provided §3.2 is respected. Every conversation about UNS reliability must restate this asymmetry; otherwise the buyer over-indexes on broker uptime and we end up over-engineering the wrong layer.
4.2 Resilience model
| Layer | Failure mode | Mitigation |
|---|---|---|
| Edge gateway | Hardware fault | Cold-spare unit on-site, swap in <30 min; configuration in version control, restored from git |
| Edge gateway | Lost connection to broker | Local persistent buffer (24h minimum, 7d default), Sparkplug B store-and-forward, replay on reconnect with monotonic timestamps preserved (v0.2 §11.4) |
| Broker | Single-node crash | Cluster mode (3 nodes minimum for production accounts) on HiveMQ / EMQX / Mosquitto + bridge |
| Broker | Site-wide power / network loss | Cross-site replica broker, DR runbook tested quarterly |
| Backend (analytics, CBAM XML, ERP bridge) | Service crash | Stateless services, restart-on-failure under systemd / Kubernetes, idempotent consumers |
| Storage | Database loss | Daily off-site backup + WAL streaming; CBAM signed envelopes are independently re-derivable from buffered raw payloads |
| Identity / PKI | Cert expiry | Automated renewal 30 days before expiry, broker logs alert on cert age >80% lifetime |
| Operator visibility | Outage goes unnoticed | Health dashboard on edge gateway itself (locally hosted, reachable on plant LAN even when WAN is down); SMS alert to on-call |
4.3 What we explicitly do not do
- No “broker on the control path” patterns. No closed-loop control over MQTT for the MVP. v0.3 may revisit this for specific use cases under a separate safety case; v0.2 forbids it.
- No single-broker production deployments. Even on R3 pilots the broker is at least 2-node clustered. Single-broker is acceptable only on R0–R1 lab benches.
- No reliance on internet for plant-side operation. Edge → broker traffic must work on the plant LAN even with the WAN cut. CBAM XML generation can lag; production data collection cannot.
4.4 Edge buffering — why it matters more in Morocco than in EU pilots
Plant connectivity quality in Khouribga, Safi, Jorf Lasfar, Tizert, Tit Mellil, and the southern OCP/Managem sites is variable. Multi-hour WAN outages happen. The edge buffer is not a luxury — without it, a CBAM quarterly report will have gaps, and one gap voids the EU verifier’s sign-off (cf. Carbon Compliance verification rules). The 24h–7d buffer requirement is dictated by the worst observed connectivity at the target site, not by a global default.
5. Risk 4 — Cybersecurity, data sovereignty, and regulatory exposure
5.1 Three regulatory frames simultaneously
| Frame | What it constrains | Where we comply |
|---|---|---|
| CNDP / Law 09-08 | Personal data processing, data transfers outside Morocco | Operator dashboards process named-user data only; production telemetry is non-personal; no data leaves Morocco without an explicit transfer agreement (CBAM XML to EU verifier is the documented exception, scope-limited to emissions metadata) |
| DGSSI cybersecurity directive | Critical infrastructure operators (OCIV) — applies to OCP, ONEE, Tanger Med, large banks | Our security posture in v0.2 §11 (TLS 1.3, mTLS, ACL, signed envelopes) is designed to satisfy DGSSI on OCIV accounts; pilot security attestations explicitly map to DGSSI requirements |
| EU CBAM verification | Data integrity and traceability for the quarterly XML | Producer-side Ed25519 signing of CBAM-relevant payloads (v0.2 §11.6); raw payloads buffered and replayable by the EU verifier on demand |
5.2 Hard cybersecurity rules (from v0.2 §11, restated for the risk register)
- TLS 1.3 mandatory on every connection. Plain MQTT 1883 refused at the broker.
- mTLS for every edge node. Self-signed certs forbidden in any environment touching production data, including pilots.
- Topic-prefix ACL derived from the mTLS CN. A producer cannot publish outside its declared scope.
- Signed envelope for any CBAM-relevant metric (Ed25519, key rotation policy in v0.2 §11.6).
- Audit log of every publish, subscribe, ACL denial, cert event. Retained 12 months minimum.
- No production deployment without a penetration test on the broker + edge stack. Budget line item, not a stretch goal.
5.3 Data sovereignty posture
- Default hosting: in-Morocco, on operator-controlled infrastructure (the plant’s own data centre, or a Moroccan IaaS — Inwi Cloud, Maroc Telecom Cloud, OVHcloud Casablanca). EU/US cloud hosting is not the default.
- CBAM XML is the only data egress. Emissions metadata leaves Morocco only as the EU-format quarterly XML, only to the customer’s nominated verifier, only over TLS, only with audit logging. No telemetry, no operator data, no plant intelligence egresses.
- Made-in-Morocco bill of materials. Documentation, support, onboarding, training are in Morocco, in MAD, by Morocco-based engineers. This is what closes OCP Group-tier procurement reviews.
6. Phased deployment — the standing playbook
The trust ladder (§2.2) maps onto a deployment timeline that every overlay reuses. Specific milestones below are taken from the YNNA Steel CBAM-urgent overlay; other overlays adjust durations but not order.
| Phase | Weeks | Environment | Access | Buyer artifact | Internal artifact |
|---|---|---|---|---|---|
| 0 — Simulation | W1–W3 | Factory I/O / PLCSIM digital twin of target line | None to real PLC | NDA, scope letter | UNS topic plan, signal inventory |
| 1 — Isolated bench | W4–W5 | Real PLC family, isolated VLAN | Read-only on bench | Risk register, cybersecurity attestation draft | End-to-end test of edge → broker → CBAM XML |
| 2 — Read-only shadow | W6–W11 | Live plant network | Read-only on production tags | Pilot acceptance test, CNDP/DGSSI compliance pack | Reliability data, edge buffer behaviour under real WAN |
| 3 — Limited write (if scope demands) | W12+ | Live plant, non-critical target | Write to one auxiliary, change-controlled | Change-control sign-off | Updated runbook |
| 4 — Production handover | W12+ on YNNA, W20+ on OCP | Live plant, full architecture | As scoped | 30-day unattended uptime evidence, signed handover | 24/7 on-call rotation, quarterly DR drill |
The MVP gate (cf. DigiTPME MVP — Product Specification v1 §1) requires a 30-day unattended run in Phase 4 before a pilot is declared shipped. Phase 0–3 are not “the MVP” — Phase 4 with a paid invoice is.
7. Risk × Mitigation matrix (one-page summary)
| Risk | Mitigation | Where it’s enforced | Pilot exemplar |
|---|---|---|---|
| Enterprise distrust of new entrants | Trust ladder R0→R4, supervised by named plant engineer, framed via IEIA standard not vendor pitch | §2.2, every SOW | Managem Tizert (R2), YNNA Steel (R0–R4) |
| PLC unintended write | Read-only by default; edge gateway between PLC and UNS; no broker on control path; watchdog stops publish, not PLC | §3.2–3.3, Morocco UNS Standard v0.1 §6 | All overlays |
| Cybersecurity / unauthenticated traffic | TLS 1.3 + mTLS + path-prefix ACL + signed CBAM envelope | Morocco UNS Standard v0.2 — Security & i18n §11 | OCP Safi Pilot, Tanger Med |
| UNS single point of failure | Broker cluster + cross-site replica + edge buffer 24h–7d + stateless backend + DR runbook | §4.2 | All R3+ overlays |
| Data loss during WAN outage | Persistent edge buffer with Sparkplug B store-and-forward; replay preserves monotonic timestamps | §4.4, v0.2 §11.4 | Managem Tizert (remote site, weak WAN), OCP Safi Pilot |
| CNDP / data sovereignty | In-Morocco hosting default; CBAM XML only egress; audited transfer agreement | §5.3 | OCP Group (OCIV), Tanger Med |
| EU verifier rejection of CBAM XML | Producer-side Ed25519 signing; replayable raw payloads; quarterly verifier dry-run | v0.2 §11.6, Carbon Compliance | YNNA Steel, Sonasid |
| Production interruption from pilot | Phase 0 simulation gate; no rung-skipping; non-critical target on R3 | §6 | All |
| Vendor lock-in concern | Standard is CC-BY-4.0 (planned v1.0), open-source edge stack (MaestroHub partnership or IIoT Platform Build Intelligence — Open Source Stack 2026) | Morocco UNS Standard v0.1 license clause | All |
8. What this framework explicitly does not yet cover (open items for v1.1)
These are deliberately deferred so v1.0 ships:
- Hardware root of trust on edge nodes (TPM-attested edge identity). Deferred to Morocco UNS Standard v0.1 v0.3. Until then, mTLS cert protection relies on OS-level keystore + physical access control.
- Formal safety case for closed-loop MQTT control. v0.2 forbids this. v1.1 may re-open under a separate IEC 61508 / 61511 review for specific non-safety-instrumented loops only.
- Vulnerability disclosure process. Governance, not standard. Tracked in Partnership Strategy under IEIA obligations.
- Cross-tenant signal sharing in shared brokers. Relevant for the Tanger Med CBAM apportionment use case (multiple shippers on one terminal). v0.2 ACL model handles it; the operational governance does not yet exist.
- Insurance / liability framework for pilot writes. R3+ writes need a contractual liability clause we have not finalised. Currently capped at the MAD value of the pilot SOW; this is insufficient for OCP Group scale and must be revisited before Phase 4 at OCP.
9. Closing principle
A pilot we cannot defend to a hostile automation engineer is a pilot we should not start. Every rung on the trust ladder, every architectural rule, every regulatory frame in this document exists so that when the question comes — and it will come, in the first kickoff meeting — the answer is already on paper, in French and Arabic, signed by their own engineer, mapped to CNDP and DGSSI, and bounded by the Morocco UNS Standard v0.2 — Security & i18n envelope.
The Moroccan industrial buyer is not unreasonable. They are protecting a plant that runs on a 30-year-old logic program and feeds a town. The job of this framework is to make saying yes to us the safe, defensible, paper-trail-rich choice — and saying no to us the harder one.