OT Security Services

From Risk Assessment to Incident Response. 8 OT-specific services aligned with international standards: IEC 62443, NIST CSF, ISO/IEC 27001/27019 and EU NIS2. Operations-first, evidence-based, executive-ready.

What we offer

Standards-Aligned OT Cybersecurity

Whether you're starting an OT security program from scratch or maturing an existing one: our consultants bring industry-aware expertise, methodology aligned with international standards (IEC 62443, NIST CSF, ISO 27019) and an operations-first approach. Not a single-product vendor: independent advisor.

ISA/IEC 62443 NIST CSF ISO/IEC 27001 ISO/IEC 27019 EU NIS2 NERC-CIP
Sequence

The Order That Works

The eight services are not a parallel menu but steps building on each other. Starting with segmentation and no asset inventory means writing firewall rules blindly, and after the first outage you will not be allowed near the network again.

01

First: see what you have

Passive asset discovery, then risk assessment. Without it every subsequent decision is guesswork, and any quote can only be an estimate.

02

Second: separate

Network segmentation with an industrial DMZ and channelled remote access. These two steps deliver the largest risk reduction in the whole programme.

03

Third: harden

Asset hardening, vulnerability assessment and compensating controls for what cannot be patched. Most industrial devices fall in this category.

04

Fourth: prepare and prove

Incident response capability, penetration testing to verify segmentation, and documenting regulatory compliance.

The eight services

What the Full Portfolio Covers

What you need when

Which Service Answers Which Problem

If you know where you stand, this table shows the next step. If you do not, start with the risk assessment.

If this is your situationThis serviceTypical duration
We do not know what is on the networkAsset inventory5-7 weeks
We know, but not what the risk isRisk assessment4-6 weeks
Flat network, everything reaches everythingNetwork segmentation4-12 weeks
Suppliers dial in with their own VPNsNetwork segmentation (remote access)2-4 weeks
Old, unpatchable devicesVulnerability assessment, asset hardening3-6 weeks
We do not know if segmentation holdsPenetration testing2-4 weeks
No plan for an incidentIncident response3-6 weeks
An inspection is comingRegulatory compliance4-6 weeks gap analysis
Frequently asked

OT Services: The Questions We Hear Most

Do we need all of these services?

No, and not at once. The eight services cover the elements of a full programme, but most organisations start with two or three. The minimum is asset inventory and risk assessment, because without them every other step would be blind. From there the risk picture decides what comes next, and that differs by organisation.

How long does a full OT security programme take?

Realistically 12-18 months from zero. The first 3 months cover discovery and risk assessment, months 3-9 segmentation and sorting out remote access, months 9-18 asset hardening, monitoring and incident response capability. This does not mean continuous work: there are phases where delivery happens on your side.

Does production have to stop?

The bulk of the work needs no downtime. Discovery is passive, risk assessment is document and interview based, segmentation design and monitoring mode run during production. Downtime is needed to switch segmentation to enforcement zone by zone (a short maintenance window), and occasionally for the active part of a penetration test. We align these with your existing maintenance schedule in advance.

Our plant engineers dislike IT interference. How do you handle that?

It is justified caution rather than obstruction: the cost of error on the plant floor is orders of magnitude higher than in the office. That is why we work with passive methods, why everything starts in monitoring mode, and why every active step carries prior agreement and a rollback plan. The language of IEC 62443 helps because the plant engineer, IT and the auditor all understand it.

Which technologies do you work with?

We design vendor-independently: the solution fits the environment and existing estate. On the OT-specific side txOne (EdgeIPS, EdgeFire, Stellar, Portable Inspector), on the network side Fortinet and Check Point, for access control Genians. The first question in any assessment is what is already in place and what can be extracted from it.

Industry-specific?
See industry profiles.

12 industries from energy and pharma to maritime and automotive, each with unique threats and OT controls.