Independent technical practice

Security for systems that cannot go down

OT, ICS and SCADA work for operators whose failures mean outages, service interruptions and public-safety consequences, not help-desk tickets.

Water treatment and electrical utility infrastructure.

Exposure

What can disrupt the operation

Operational technology was designed for availability and long service life, not for authentication and patching. Controllers, historians and engineering workstations frequently run software generations behind the corporate estate, and the maintenance window in which anything can be changed is narrow and scheduled around load.

Segmentation is the recurring finding. Business networks, vendor remote access, shared credentials and dual-homed jump hosts create paths between IT and OT that are not on any diagram, and those paths are usually discovered during an assessment rather than during design review.

Third parties compound both. Integrators, equipment vendors and managed service providers hold standing access to control environments, often through tooling the operator does not monitor, and an incident inside a supplier becomes an incident inside the plant without anyone crossing the fence line.

Scoping

Questions the engagement must answer

  1. Which assets can be tested live, and which require passive or lab-based methods?
  2. Where does the boundary between the IT network and the control environment actually sit?
  3. If a control system is compromised, what is the safe sequence for containment?
  4. What evidence would survive an outage, and what is lost when systems are restarted?
  5. What must be reported, to whom, and on what clock?

Services

How we help

Context

Regulatory context

NERC CIP
Bulk electric system operators carry mandatory reliability standards for asset identification, access control, monitoring and incident reporting, and evidence of compliance has to be producible on request.
TSA security directives
Pipeline and rail operators are subject to federally directed cybersecurity requirements covering segmentation, access control, monitoring and incident response planning.
State public utility commissions
State regulators increasingly ask for demonstrated cyber program maturity and incident reporting as part of rate and reliability oversight.
Water and wastewater oversight
Federal and state authorities have pushed drinking-water and wastewater systems toward formal cyber risk assessment and response planning, particularly for remotely accessible control systems.

Applicability depends on sector, size and jurisdiction; we scope assessments against the regimes that actually bind you.

Related case study

Corporate Investigation: Industrial Sector

Corporate engagement combining device forensics with employee conduct review.

Corporate Investigation

See all case studies

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.