Applied IAM

OT and ICS security for plant environments

Operational technology runs the plant: the controllers, the HMIs, the historians and the network between them. Most of it was installed before anyone planned to connect it to anything, and it cannot be patched, scanned or rebooted the way IT can. We establish what is actually on the network and how far it is reachable, without touching the process — then help you rehearse for the bad day and respond to it.

Passive asset discoveryArchitecture reviewTabletop exercisesIncident response retainerIEC 62443
OT asset estateApplied IAM
OT asset estate6 of 214 assets
Plant eastPlant westRemote sites
AssetPurdueProtocolState
Line 2 PLC — packagingLevel 1EtherNet/IPUnmanaged
HMI station — fillerLevel 2RDPShared login
Historian — plant eastLevel 3OPC UALocal admin
Engineering workstationLevel 3SSH, RDPNo MFA
Vendor jump hostLevel 3.5VPNBrokered
Safety controller — pressLevel 1SerialIsolated

Placeholder values. The real inventory comes out of discovery, which is where every OT engagement starts.

IndependentNo resaleno OT vendor partnership, and no commission
The difference

Why an OT network cannot be secured like an IT one

The instinct is to point the IT security stack at the plant floor and call it covered. It does not work, and the reasons are practical rather than technical. A controller that has run untouched for eleven years has no agent to install and no patch window to install it in. A vulnerability scan that is routine on a corporate subnet can knock a PLC offline, which on a production line is an outage and on a press is a safety event.

So the controls have to fit the plant. Discovery is passive rather than active. Monitoring watches the industrial protocols — EtherNet/IP, OPC UA, Modbus — not just Windows event logs. Testing stops at proof rather than execution. And every change is weighed against uptime and safety before it is made, because the plant does not stop for security work.

An IT network

Built to be patched

  • A window every month, and a reboot inside it
  • Endpoints replaced on a refresh cycle
  • Downtime costs money
  • Scanning is routine
An OT network

Built to keep running

  • A window once a year, if the plant allows one
  • Controllers that have run untouched for a decade
  • Downtime stops production, and can be a safety event
  • A scan can knock a controller over

Same attacker, different constraints. The controls have to fit the plant, not the other way round.

Service line 01

OT cyber assessment

Network design and architecture review, passive asset discovery, and control gap analysis, delivered as a written report with risk-ranked findings. Most engagements start here, because most plants do not have a current list of what is on the network. The inventory itself is usually the finding that changes the conversation.

Discovery is passive throughout. We read the traffic already on the network rather than probing devices, so nothing we do can interrupt the process. The report names the gap, the fix, and the effort — so it can be taken to a budget meeting rather than filed.

OT cyber assessmentApplied IAM
ScopePlant eastAssets214MethodPassive discovery
  • Flat network between business and plant floorSegmentation
  • Vendor VPN with a shared accountRemote access
  • Engineering workstation with local adminPrivilege
  • Historian reachable from the corporate LANExposure
  • No asset inventory older than the last auditGovernance

Risk-ranked, with the fix and the effort beside each one.

Service line 02

OT incident response

Investigation, containment and recovery inside OT. A retainer pre-clears the contract and shortens the call-out, which is the part people underestimate: on the day it happens, the delay is rarely technical. It is procurement, scope and an NDA being negotiated while the plant sits idle.

Containment inside OT is also a different judgement call. Isolating a host in an office is free. Isolating a historian mid-batch is not, and someone has to weigh that against the process in real time.

1Retainer signedContract and scope pre-cleared
before anything happens
2Call outOne number, plant and IT on the same bridge
hours, not days
3ContainInside OT, around the process
production weighed at every step
4Recover and reportRoot cause in writing

The retainer is what removes the procurement delay from the worst day.

Service line 03

OT tabletop exercises

Simulated drills against the scenarios that actually reach plant environments, in standard or custom formats, closing with an after-action report.

  • Ransomware reaching the plant floor. The business network is encrypted and nobody can say whether the plant is safe to keep running. The decision is who makes that call, on what evidence, and how fast.
  • Insider and contractor access. An engineer or a vendor with legitimate credentials does something they should not. Most plants find they cannot tell the difference between that and normal work.
  • Supply chain compromise. An integrator's remote access is the way in. The drill usually reveals nobody has a current list of who holds that access.
  • Custom scenarios. Built around your own architecture and the incident your team already worries about.
Compliance

IEC 62443 and NERC CIP

IEC 62443 is the framework most industrial environments are measured against, and NERC CIP applies if you are in the bulk electric system. Both ask for the same foundations in different language: know what you own, segment it, control who reaches it remotely, review privileged accounts, and be able to show an incident was handled.

We map your controls to the framework, close the gaps we find, and assemble the evidence. The certificate comes from your assessor, not from us. If NERC CIP is your driver specifically, the energy and utilities page covers that programme in more detail.

OT control readinessApplied IAM
OT control readiness2 frameworks mapped
IEC 62443NERC CIP
ControlMaps toEvidenceState
Asset inventory maintainedIEC 62443-2-1Ready
Zones and conduits definedIEC 62443-3-2Gap
Remote access brokered and loggedNERC CIP-005Gap
Privileged accounts reviewedNERC CIP-004Ready
Patch and vulnerability processIEC 62443-2-3Open
Incident response testedNERC CIP-008Gap

Placeholder values. We close the gaps; the certificate comes from your assessor, not from us.

Where we work

Industries we secure OT in

  • Manufacturing and food and beverage. Production lines, batch processes, and the historians that prove what was made when.
  • Energy, oil and gas, and water and wastewater. Distributed sites, remote access as the default, and NERC CIP or state regulators in the background.
  • Data centers and building automation. Power, cooling and access control, all of it networked and rarely inventoried.
  • Chemical and pharmaceuticals. Safety instrumented systems and validated environments, where change control is already strict and security has to work inside it.
  • Electric and public sector. Substations, municipal utilities and the shared-service arrangements around them.
Independence

Independent of the platforms we verify

We do not resell, implement or take commission on OT security platforms. We hold no partnership or reseller agreement with any OT vendor.

That matters because a verification is only worth something if the people doing it have nothing to sell you afterwards. What we sell in OT is the assessment, the exercises and the response retainer — none of which depend on which platform you end up choosing.

If you are running a commissioning or acceptance process and need the verification done by someone with no stake in the outcome, that is the work we are built for.

Questions

Common questions about OT security

No. Discovery is passive — we read the traffic already on the network rather than probing devices. We do not run active scans against live controllers. The default assumption is that a controller cannot be touched.

Usually you do not need a separate provider so much as OT-specific competence, and independence from whatever you are being sold. The failure mode we see is an IT team applying IT judgement to a plant: scanning a subnet that includes PLCs, or isolating a host mid-process.

An assessment, because almost nobody has a current asset inventory. Until you know what is on the network and how it is reachable, every other decision is guesswork.

No. We hold no vendor partnership, take no commission, and do not implement OT platforms. If a product is the right answer for you, we will say so, and you will buy it from somebody else.

We get you ready for it and assemble the evidence. Certification comes from an accredited assessor. Anyone offering to both prepare and certify you is worth a question.

Next step

Start with what is actually on the network

A 30-minute review of your OT estate with a certified engineer. You get the findings in writing, with no obligation. If the answer is that your current arrangements are sound, that is what the findings will say.

Find out what is reachable from your business network

A free consultation covers what you run on the plant floor, how it connects to everything else, and where the gaps are. Findings in writing, no obligation.