Oman United Kingdom Norway Support portal
Talk to an expert
AboutContact

OT and ICS security

Protection for control systems where availability and safety come first. Passive discovery, zone and conduit design, and incident plans built for environments you cannot simply switch off.

Assess OT security
Regions
Oman · UK · Norway
Scope
Written before it is quoted

The problem this solves

Most organisations do not lack security tools. They lack the time, the coverage and the evidence to prove those tools are working. OT and ICS security is built to close that gap with people who do this every day.

What the service covers

Each area below is a defined part of the engagement, with an owner, an output and a date.

Discovery

Passive asset identification that will not disturb production processes.

Segmentation

Zone and conduit design between enterprise IT and operational technology.

Risk

Risk expressed in terms of safety, availability and financial impact.

Monitoring

Continuous observation with alerting tuned to your risk profile.

Incident readiness

Plans and exercises built for environments that cannot simply be switched off.

Training

Role-specific training delivered by practitioners, not presenters.

IT and OT segmentation

ENTERPRISE ITLevel 4-5DEMILITARISED ZONELevel 3.5SUPERVISORYLevel 2-3CONTROLLevel 1PROCESSLevel 0All traffic between IT and OT crosses one inspected boundary.Below the DMZ, availability and safety take precedence over confidentiality.
One inspected boundary between the two.

How the work runs

The same sequence on every engagement, so you know what happens next.

STEP 01

Scope

A scoping call establishes what is in scope, what is explicitly out, and which constraints apply. You get a written scope before any quotation.

STEP 02

Mobilise

Named consultants, access, escalation contacts and a delivery schedule are agreed and recorded.

STEP 03

Deliver

Work is carried out by the consultants you met at scoping, with progress visible rather than reported only at the end.

STEP 04

Report

Findings are peer-reviewed by a second consultant before release, then walked through with your team.

STEP 05

Improve

Remediation support, retesting and a follow-up review so the work produces a measurable change.

What you get out of it

Evidence you can show

Reports written so they can be handed to an auditor, a regulator or a board without translation.

Fewer surprises

Coverage gaps identified explicitly, including the ones outside our scope.

Regional delivery

Consultants based in Oman, the UK and Norway, not flown in for the week.

Standards and references: ISO/IEC 27001:2022 · NIST CSF 2.0 · MITRE ATT&CK · OWASP ASVS · CIS Benchmarks

Before you enquire

How quickly can this start?
Scoping usually takes one call. Delivery start depends on access and approvals; we will give you a date in the proposal rather than after you sign.
Who actually does the work?
Named consultants from our regional teams. You will meet them before the engagement begins, and the same people write the report.
How is this priced?
A fixed price against a written scope wherever the work can be scoped that way, and a day rate where it genuinely cannot. Either way you see the basis before you commit.

Assess OT security

One scoping call with the consultant who would run the work. No obligation, no charge.

Assess OT security
Talk to an expert