From Risk Assessment to Incident Response. 8 OT-specific services aligned with international standards: IEC 62443, NIST CSF, ISO/IEC 27001/27019 and EU NIS2. Operations-first, evidence-based, executive-ready.
Whether you're starting an OT security program from scratch or maturing an existing one: our consultants bring industry-aware expertise, methodology aligned with international standards (IEC 62443, NIST CSF, ISO 27019) and an operations-first approach. Not a single-product vendor: independent advisor.
Standards-aligned, OT-aware risk discovery, operations-first methodology, executive-ready output.
NIS2, IEC 62443, ISO 27019, verifiable compliance instead of risk.
Targeted hardening of PLCs, HMIs, RTUs and gateways, from factory defaults to a hardening baseline.
Non-intrusive scanners and controlled exploit, primary focus on operational continuity.
Accurate OT asset register: passive discovery, manual verification, live updates.
Purdue-model zones, secure conduits, IT/OT boundary defense, without disruption.
Controlled OT pentest, safety-focused, with live-system protection.
OT-readiness, IR playbook, tabletop exercises and industrial recovery plans.
The eight services are not a parallel menu but steps building on each other. Starting with segmentation and no asset inventory means writing firewall rules blindly, and after the first outage you will not be allowed near the network again.
Passive asset discovery, then risk assessment. Without it every subsequent decision is guesswork, and any quote can only be an estimate.
Network segmentation with an industrial DMZ and channelled remote access. These two steps deliver the largest risk reduction in the whole programme.
Asset hardening, vulnerability assessment and compensating controls for what cannot be patched. Most industrial devices fall in this category.
Incident response capability, penetration testing to verify segmentation, and documenting regulatory compliance.
If you know where you stand, this table shows the next step. If you do not, start with the risk assessment.
| If this is your situation | This service | Typical duration |
|---|---|---|
| We do not know what is on the network | Asset inventory | 5-7 weeks |
| We know, but not what the risk is | Risk assessment | 4-6 weeks |
| Flat network, everything reaches everything | Network segmentation | 4-12 weeks |
| Suppliers dial in with their own VPNs | Network segmentation (remote access) | 2-4 weeks |
| Old, unpatchable devices | Vulnerability assessment, asset hardening | 3-6 weeks |
| We do not know if segmentation holds | Penetration testing | 2-4 weeks |
| No plan for an incident | Incident response | 3-6 weeks |
| An inspection is coming | Regulatory compliance | 4-6 weeks gap analysis |
No, and not at once. The eight services cover the elements of a full programme, but most organisations start with two or three. The minimum is asset inventory and risk assessment, because without them every other step would be blind. From there the risk picture decides what comes next, and that differs by organisation.
Realistically 12-18 months from zero. The first 3 months cover discovery and risk assessment, months 3-9 segmentation and sorting out remote access, months 9-18 asset hardening, monitoring and incident response capability. This does not mean continuous work: there are phases where delivery happens on your side.
The bulk of the work needs no downtime. Discovery is passive, risk assessment is document and interview based, segmentation design and monitoring mode run during production. Downtime is needed to switch segmentation to enforcement zone by zone (a short maintenance window), and occasionally for the active part of a penetration test. We align these with your existing maintenance schedule in advance.
It is justified caution rather than obstruction: the cost of error on the plant floor is orders of magnitude higher than in the office. That is why we work with passive methods, why everything starts in monitoring mode, and why every active step carries prior agreement and a rollback plan. The language of IEC 62443 helps because the plant engineer, IT and the auditor all understand it.
We design vendor-independently: the solution fits the environment and existing estate. On the OT-specific side txOne (EdgeIPS, EdgeFire, Stellar, Portable Inspector), on the network side Fortinet and Check Point, for access control Genians. The first question in any assessment is what is already in place and what can be extracted from it.