OT and ICS security for plant environments
Operational technology runs the plant: the controllers, the HMIs, the historians and the network between them. Most of it was installed before anyone planned to connect it to anything, and it cannot be patched, scanned or rebooted the way IT can. We establish what is actually on the network and how far it is reachable, without touching the process — then help you rehearse for the bad day and respond to it.
| Asset | State | |
|---|---|---|
| Line 2 PLC — packaging | Level 1 | Unmanaged |
| HMI station — filler | Level 2 | Shared login |
| Historian — plant east | Level 3 | Local admin |
| Engineering workstation | Level 3 | No MFA |
| Vendor jump host | Level 3.5 | Brokered |
| Safety controller — press | Level 1 | Isolated |
Placeholder values. The real inventory comes out of discovery, which is where every OT engagement starts.
Why an OT network cannot be secured like an IT one
The instinct is to point the IT security stack at the plant floor and call it covered. It does not work, and the reasons are practical rather than technical. A controller that has run untouched for eleven years has no agent to install and no patch window to install it in. A vulnerability scan that is routine on a corporate subnet can knock a PLC offline, which on a production line is an outage and on a press is a safety event.
So the controls have to fit the plant. Discovery is passive rather than active. Monitoring watches the industrial protocols — EtherNet/IP, OPC UA, Modbus — not just Windows event logs. Testing stops at proof rather than execution. And every change is weighed against uptime and safety before it is made, because the plant does not stop for security work.
Built to be patched
- A window every month, and a reboot inside it
- Endpoints replaced on a refresh cycle
- Downtime costs money
- Scanning is routine
Built to keep running
- A window once a year, if the plant allows one
- Controllers that have run untouched for a decade
- Downtime stops production, and can be a safety event
- A scan can knock a controller over
Same attacker, different constraints. The controls have to fit the plant, not the other way round.
OT cyber assessment
Network design and architecture review, passive asset discovery, and control gap analysis, delivered as a written report with risk-ranked findings. Most engagements start here, because most plants do not have a current list of what is on the network. The inventory itself is usually the finding that changes the conversation.
Discovery is passive throughout. We read the traffic already on the network rather than probing devices, so nothing we do can interrupt the process. The report names the gap, the fix, and the effort — so it can be taken to a budget meeting rather than filed.
- Flat network between business and plant floorSegmentation
- Vendor VPN with a shared accountRemote access
- Engineering workstation with local adminPrivilege
- Historian reachable from the corporate LANExposure
- No asset inventory older than the last auditGovernance
Risk-ranked, with the fix and the effort beside each one.
OT incident response
Investigation, containment and recovery inside OT. A retainer pre-clears the contract and shortens the call-out, which is the part people underestimate: on the day it happens, the delay is rarely technical. It is procurement, scope and an NDA being negotiated while the plant sits idle.
Containment inside OT is also a different judgement call. Isolating a host in an office is free. Isolating a historian mid-batch is not, and someone has to weigh that against the process in real time.
The retainer is what removes the procurement delay from the worst day.
OT tabletop exercises
Simulated drills against the scenarios that actually reach plant environments, in standard or custom formats, closing with an after-action report.
- Ransomware reaching the plant floor. The business network is encrypted and nobody can say whether the plant is safe to keep running. The decision is who makes that call, on what evidence, and how fast.
- Insider and contractor access. An engineer or a vendor with legitimate credentials does something they should not. Most plants find they cannot tell the difference between that and normal work.
- Supply chain compromise. An integrator's remote access is the way in. The drill usually reveals nobody has a current list of who holds that access.
- Custom scenarios. Built around your own architecture and the incident your team already worries about.
IEC 62443 and NERC CIP
IEC 62443 is the framework most industrial environments are measured against, and NERC CIP applies if you are in the bulk electric system. Both ask for the same foundations in different language: know what you own, segment it, control who reaches it remotely, review privileged accounts, and be able to show an incident was handled.
We map your controls to the framework, close the gaps we find, and assemble the evidence. The certificate comes from your assessor, not from us. If NERC CIP is your driver specifically, the energy and utilities page covers that programme in more detail.
| Control | Evidence | State | |
|---|---|---|---|
| Asset inventory maintained | IEC 62443-2-1 | Ready | |
| Zones and conduits defined | IEC 62443-3-2 | Gap | |
| Remote access brokered and logged | NERC CIP-005 | Gap | |
| Privileged accounts reviewed | NERC CIP-004 | Ready | |
| Patch and vulnerability process | IEC 62443-2-3 | Open | |
| Incident response tested | NERC CIP-008 | Gap |
Placeholder values. We close the gaps; the certificate comes from your assessor, not from us.
Industries we secure OT in
- Manufacturing and food and beverage. Production lines, batch processes, and the historians that prove what was made when.
- Energy, oil and gas, and water and wastewater. Distributed sites, remote access as the default, and NERC CIP or state regulators in the background.
- Data centers and building automation. Power, cooling and access control, all of it networked and rarely inventoried.
- Chemical and pharmaceuticals. Safety instrumented systems and validated environments, where change control is already strict and security has to work inside it.
- Electric and public sector. Substations, municipal utilities and the shared-service arrangements around them.
Independent of the platforms we verify
We do not resell, implement or take commission on OT security platforms. We hold no partnership or reseller agreement with any OT vendor.
That matters because a verification is only worth something if the people doing it have nothing to sell you afterwards. What we sell in OT is the assessment, the exercises and the response retainer — none of which depend on which platform you end up choosing.
If you are running a commissioning or acceptance process and need the verification done by someone with no stake in the outcome, that is the work we are built for.
Common questions about OT security
No. Discovery is passive — we read the traffic already on the network rather than probing devices. We do not run active scans against live controllers. The default assumption is that a controller cannot be touched.
Usually you do not need a separate provider so much as OT-specific competence, and independence from whatever you are being sold. The failure mode we see is an IT team applying IT judgement to a plant: scanning a subnet that includes PLCs, or isolating a host mid-process.
An assessment, because almost nobody has a current asset inventory. Until you know what is on the network and how it is reachable, every other decision is guesswork.
No. We hold no vendor partnership, take no commission, and do not implement OT platforms. If a product is the right answer for you, we will say so, and you will buy it from somebody else.
We get you ready for it and assemble the evidence. Certification comes from an accredited assessor. Anyone offering to both prepare and certify you is worth a question.
Start with what is actually on the network
A 30-minute review of your OT estate with a certified engineer. You get the findings in writing, with no obligation. If the answer is that your current arrangements are sound, that is what the findings will say.
Find out what is reachable from your business network
A free consultation covers what you run on the plant floor, how it connects to everything else, and where the gaps are. Findings in writing, no obligation.