Services

Security for the plant, not just the office

Industrial control systems follow different laws from classic IT. Where the office puts the confidentiality of data first, production and energy generation care above all that the plant keeps running. A security assessment that does not grasp this reversal of priorities does more harm than good. Ours is built for operational technology from the ground up.

Why OT security is different

In IT the order is confidentiality, integrity, availability. In OT it reverses: availability and operational safety first. On top of that come constraints IT does not know: controllers often run for decades, cannot simply be updated, and tolerate no aggressive scans. Maintenance windows are rare and short. An outage costs not data but production, feed-in, or in the worst case the safety of people.

The zone model and the separation of IT and OT

A central check is segmentation. Under the Purdue reference model and the logic of IEC 62443, control levels should be separated from corporate IT and the transitions controlled. In practice we often find flat networks in which a compromised office workstation has a direct path to the controller. We assess the zones and transitions, the data flow between IT and OT, and the buffer areas where the two worlds meet under control.

What we examine

  • Asset inventory and topology — a complete picture of all components, often for the very first time.
  • Network segmentation — zones, transitions and the separation of IT and OT.
  • Remote access — maintenance access by manufacturers and service providers, a frequently underestimated way in.
  • Firewall rules and logging — what is permitted, what is recorded, what stands out.
  • Vulnerabilities — known weaknesses in controllers, protocols and legacy systems.

Passive where possible

We work as passively as possible: we observe network traffic and evaluate configurations rather than intervening in running systems. Active tests are carried out only where they are risk-free or within agreed maintenance windows. You get a reliable picture without putting operations at risk.

Assessment against IEC 62443

We classify our findings along the ISA/IEC 62443 series and use the protection levels to place each finding in a traceable category. That makes the results comparable and connectable to your NIS2 and — for manufacturers — CRA evidence.

Experience from practice

We have carried out eleven OT audits in the energy sector, including solar and hydropower installations. This experience with distributed sites, remote maintenance and control systems (SCADA) transfers directly to production environments in manufacturing: the same method, a different plant. The result is a prioritised report with concrete findings and an implementable action plan — intelligible for the engineers and for management alike.

Typical weaknesses in operational technology

Again and again we meet the same weaknesses: default passwords that were never changed; remote-maintenance access left permanently open; controllers that have seen no update in years; and networks where production and administration sit side by side without separation. Added to this is often a blind spot: nobody in the building has a complete picture of which devices are even on the network. We create that picture first — because what you do not know, you cannot protect.

Why availability and security belong together

In operational technology, security is not the opposite of availability but its precondition. A compromised control system fails or returns false values — both threaten exactly the availability that matters in production. So we always assess risk from the operational point of view: what does a finding mean for the plant, not only for data security? Only when security supports operations rather than hindering them will it be accepted on the plant floor.

From assessment to architecture

An assessment is not an end in itself. Its purpose is a resilient security architecture: clear zones, controlled transitions, secured remote access, and logging that provides answers when it matters. So we do not stop at the report but accompany the path to the target architecture — in stages that fit your maintenance windows.

Managing IT/OT convergence safely

Production and corporate IT are growing together — intended and economically sensible, but it creates new risk. The right path is not to prevent the connection but to shape it under control: through clearly defined transitions, buffer zones, and logging that shows what passes between the two worlds. We help you reap the benefits of connectivity without exposing production to the risk of the office network.

Process and duration

An OT security assessment takes from a few days to a few weeks depending on the environment. We begin with the inventory and network analysis, assess the findings against IEC 62443, and deliver a prioritised action plan. If you wish, we take on the implementation or ongoing support as a vCISO.

When an assessment is especially worthwhile

An OT security assessment is particularly worthwhile before a plant is modernised or connected, after a near miss, when NIS2 obligations are approaching, or simply when there is no overview of which systems are on the network at all. In each case it creates a fact-based basis for the next decisions.

Further reading: IEC 62443 – Assessment & Security Architecture · Manufacturing & Automation · Energy & Industrial Technology

Request an OT assessment

A free intro call, no commitment, a reply within 24 hours.