Critical Infrastructure
Monitoring and response designed for environments where you cannot simply reboot the affected system.
What you receive
- OT-aware detection and passive monitoring
- IT/OT boundary assessment
- NIS2 governance and reporting
- Tabletop exercises with operations
When you need this
Three situations that call for it. If none of them is yours, it probably is not the right spend.
You cannot take the plant down to patch
Maintenance windows in a process environment are measured in years, so the finding is often not fixable on the timeline the report assumes. The work becomes compensating controls at the boundary and detection inside the zone, rather than a patch queue.
A maintenance vendor holds standing access
Remote support accounts for turbines, pumps or building management are commonly shared, rarely rotated, and outlive the contract that created them. They are a routine route inwards precisely because they are legitimate, and nobody wants to break the support agreement.
IT was hit and nobody can prove OT is clean
The decision to keep producing or to stop gets made in the first hour, usually with no evidence about whether the boundary held. A precautionary shutdown can cost more than the incident would have, so passive monitoring exists to put data behind that call.
How it runs
Where you actually are
A working session to establish what is already in place and what your regulator, your auditor or your board is going to ask for. Usually the gap is narrower than feared and differently shaped.
What the obligation really requires
We separate what the text mandates from what a consultancy has told you it mandates. Several of the controls sold against these regimes are not required by them.
A scoped programme
The specific modules and engagements that close the gap, sequenced by what your deadline is and what depends on what — not by what is easiest to sell you.
Evidence, not a gap report
The output is the artefact your assessor accepts: test results, control evidence and a record of what changed. A document describing your gaps is not evidence that you closed them.
No lock-in
Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.
Who turns up
The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.
Scope
What this does not cover
We do not run active scanning or exploitation inside a live process network; testing there is passive, or done against a lab replica.
Functional safety and safety instrumented system design are a separate engineering discipline, assessed by a different body, and are not part of this.
Rebuilding control systems after an incident is the vendor's work under their support terms; the investigation runs alongside it, not instead of it.
- NIS2 Directive (EU) 2022/2555, Art. 23
- An early warning within 24 hours, a full incident notification within 72, and a final report within one month.
- IEC 62443-3-2
- Requires the system to be partitioned into zones and conduits, each with its own risk assessment and target security level.
- CER Directive (EU) 2022/2557
- Physical and organisational resilience duties for identified critical entities, running in parallel with the NIS2 obligations.
If the scope is wrong
Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.
Questions
The ones we are actually asked.
Can you monitor OT without touching the control network?
Passive collection from a tap or span port adds no traffic and installs no agents, which is usually the only acceptable answer in a safety-rated environment. The limit is that it sees only what crosses the tap — serial links and local engineering laptops stay invisible.
Does NIS2 apply if we are a supplier, not an operator?
Often not directly, but it reaches you contractually. NIS2 obliges in-scope entities to manage supply-chain risk, so the requirement arrives as security clauses in your customers' contracts rather than as a letter from a regulator.
Would you find an attacker already inside the OT network?
Sometimes, and less often than in IT. Process networks are quiet and predictable, which helps, but they retain almost no history — without earlier capture there is frequently nothing to look back at, so monitoring buys evidence you cannot obtain retroactively.
See what an attacker sees
We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.
30 min
A scoping call, with an engineer rather than a sales rep.
What it costs
Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.
Under attack now?
Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.