Scope of work
From audit to architecture to operations.
01 Risk & gap assessments
IEC 62443 and NIST CSF / 800-82r3 baselining of the current OT estate. Findings ranked by exploitability, blast radius, and remediation cost.
02 Segmentation & Purdue-model design
Cell / Area / Zone architecture from L0 (field instruments) up through L4 (enterprise) — with explicit, documented conduits between zones.
03 Vulnerability remediation
Patch planning that respects production windows. Compensating controls when patching isn't safe. Documented evidence for every change.
04 Targeted penetration testing
OT-aware penetration tests with explicit out-of-scope guardrails. Never against live safety systems without a side-by-side test bench.
05 Incident response runbooks
Plant-specific runbooks for the most likely OT incident classes — ransomware on the EWS, compromised vendor remote access, lateral movement from IT to OT.
06 Ongoing compliance evidence
Configuration baselines, change records, and access logs collected as a side effect of normal operations — not retroactively for audit week.
Audit something real.
Send your highest-stakes site — refinery, substation, packaging line. We start there.