Independent technical practice

Critical Infrastructure & OT Security

Engineers independently assess the operational systems that cannot be allowed to fail, then report the findings for the board.

Water treatment and electrical utility infrastructure.

Who we serve

  • Utilities
  • Water Authorities
  • Energy
  • Transportation
  • Municipalities
  • Electric Co-operatives

Scope

What we deliver

  • OT Assessment

    Asset inventory, exposure analysis and prioritized remediation for operational technology.

  • SCADA Security Review

    Protocol, remote-access and vendor-connection review of control systems.

  • Network Segmentation Review

    Validation that IT and OT are actually separated, not nominally separated.

  • Incident Response Review

    Testing the plan against a realistic scenario before an operator has to use it.

  • NERC CIP Compliance

    Gap analysis and evidence packaging for audit readiness.

  • Executive Briefing

    One session that gives the board a defensible view of operational cyber risk.

Nothing touches production without written agreement and an operations-approved window.

Methodology

How the engagement runs

  1. Scope

    Define the systems, sites and constraints. Nothing touches production without written agreement.

  2. Assess

    Passive discovery first; active testing only where it is safe and authorized.

  3. Validate

    Confirm findings with operators and engineers so nothing rests on assumption.

  4. Report

    Findings ranked by operational consequence, not by CVSS score alone.

  5. Brief the board

    A plain-language session on what the risk is, what it would cost, and what to do first.

What counsel receives

A file another examiner could pick up.

The record separates observed configuration, validated exposure and operational consequence without treating a live plant as a laboratory.

Safety and availability constraints remain part of the finding, not a footnote added after testing.

  • Scope letter and stated assumptionsWhat was asked, what was examined, what was out of scope, and the assumptions the analysis rests on.
  • Evidence handling recordAcquisition details, hash values, storage and transfer, and a chain-of-custody log for each item.
  • Methodology statementTools, versions and procedures described so a second qualified examiner can repeat the work.
  • Findings, separated from interpretationObserved facts first; expert opinion identified as opinion, with the basis for each conclusion.
  • Limitations and unresolved questionsWhat the evidence cannot show, what was unavailable, and what further work would be required.
  • Exhibits and supporting materialExtracted artifacts, timelines and schedules in a form that can be attached to a filing or a board pack.
  • Operational constraints registerSafety, availability and process limits that shaped testing, and the risks accepted to keep the plant running.

Proof

Utility breach analysis, regional operator

A regional operator identified suspicious remote access into an engineering workstation. Technical analysis established the entry path through a vendor connection, confirmed that control systems had not been reached, and produced the segmentation and remote-access changes that closed the route.

Credentials & standards

  • OT and ICS engagements for utilities and public authorities
  • NERC CIP evidence-ready deliverables
  • Passive-first assessment methodology
  • Findings ranked by operational consequence

Field context

Assessment beyond the checklist

How security testing changes when physical processes and older control systems are involved.

Why control systems stay exposed

SCADA estates supervise pumps, valves, motors and PLCs across energy, water, power generation and processing. Much of that equipment was commissioned when security was not a design consideration, so the operating environment combines outdated platforms, physically accessible access points and bolt-on controls that do not integrate cleanly with what is already installed. Documented incidents at water utilities have turned on weak credentials and insider access rather than sophisticated capability.

Harden first, then test

Breaking into an untested network proves little and usually takes under an hour. Our sequence is scope, pre-test assessment from inside and outside the perimeter, remediation alongside the operator's own team, and only then the penetration test against the hardened environment. Targets have included networks, web and mobile applications, email systems, IoT deployments and SCADA, including tests run to evidence PCI, HIPAA, NIST 800-171/DFARS, SEC, DISA and FedRAMP obligations.

Both attack vectors, and the plant around them

Security is assessed against the insider path and the external path together, and against the organization as it actually exists, including its physical plant, personnel, networks and equipment, rather than against a control list. Assessment, planning, testing, validation and, where it becomes necessary, response and remediation are treated as one continuum instead of separate purchases.

Related

Related services

Frequently asked

Common questions

Will testing disrupt operations?

No. Assessment begins passively, and any active step is scheduled, scoped and approved by your operations team in advance. Production systems are never touched without written authorization.

Do you work within NERC CIP evidence requirements?

Yes. Deliverables are structured so findings and remediation records can be used directly in audit evidence packages, rather than rewritten for the auditor afterwards.

Can you support an active incident?

Yes. The 24/7 hotline reaches an examiner, and retainer clients receive a priority response commitment with responders who already know the environment.

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.