Independent technical practice
Critical Infrastructure & OT Security
Engineers independently assess the operational systems that cannot be allowed to fail, then report the findings for the board.
Who we serve
- Utilities
- Water Authorities
- Energy
- Transportation
- Municipalities
- Electric Co-operatives
Scope
What we deliver
-
OT Assessment
Asset inventory, exposure analysis and prioritized remediation for operational technology.
-
SCADA Security Review
Protocol, remote-access and vendor-connection review of control systems.
-
Network Segmentation Review
Validation that IT and OT are actually separated, not nominally separated.
-
Incident Response Review
Testing the plan against a realistic scenario before an operator has to use it.
-
NERC CIP Compliance
Gap analysis and evidence packaging for audit readiness.
-
Executive Briefing
One session that gives the board a defensible view of operational cyber risk.
Nothing touches production without written agreement and an operations-approved window.
Methodology
How the engagement runs
-
Scope
Define the systems, sites and constraints. Nothing touches production without written agreement.
-
Assess
Passive discovery first; active testing only where it is safe and authorized.
-
Validate
Confirm findings with operators and engineers so nothing rests on assumption.
-
Report
Findings ranked by operational consequence, not by CVSS score alone.
-
Brief the board
A plain-language session on what the risk is, what it would cost, and what to do first.
What counsel receives
A file another examiner could pick up.
The record separates observed configuration, validated exposure and operational consequence without treating a live plant as a laboratory.
Safety and availability constraints remain part of the finding, not a footnote added after testing.
- Scope letter and stated assumptionsWhat was asked, what was examined, what was out of scope, and the assumptions the analysis rests on.
- Evidence handling recordAcquisition details, hash values, storage and transfer, and a chain-of-custody log for each item.
- Methodology statementTools, versions and procedures described so a second qualified examiner can repeat the work.
- Findings, separated from interpretationObserved facts first; expert opinion identified as opinion, with the basis for each conclusion.
- Limitations and unresolved questionsWhat the evidence cannot show, what was unavailable, and what further work would be required.
- Exhibits and supporting materialExtracted artifacts, timelines and schedules in a form that can be attached to a filing or a board pack.
- Operational constraints registerSafety, availability and process limits that shaped testing, and the risks accepted to keep the plant running.
Proof
Utility breach analysis, regional operator
A regional operator identified suspicious remote access into an engineering workstation. Technical analysis established the entry path through a vendor connection, confirmed that control systems had not been reached, and produced the segmentation and remote-access changes that closed the route.
Credentials & standards
- OT and ICS engagements for utilities and public authorities
- NERC CIP evidence-ready deliverables
- Passive-first assessment methodology
- Findings ranked by operational consequence
Field context
Assessment beyond the checklist
How security testing changes when physical processes and older control systems are involved.
Why control systems stay exposed
SCADA estates supervise pumps, valves, motors and PLCs across energy, water, power generation and processing. Much of that equipment was commissioned when security was not a design consideration, so the operating environment combines outdated platforms, physically accessible access points and bolt-on controls that do not integrate cleanly with what is already installed. Documented incidents at water utilities have turned on weak credentials and insider access rather than sophisticated capability.
Harden first, then test
Breaking into an untested network proves little and usually takes under an hour. Our sequence is scope, pre-test assessment from inside and outside the perimeter, remediation alongside the operator's own team, and only then the penetration test against the hardened environment. Targets have included networks, web and mobile applications, email systems, IoT deployments and SCADA, including tests run to evidence PCI, HIPAA, NIST 800-171/DFARS, SEC, DISA and FedRAMP obligations.
Both attack vectors, and the plant around them
Security is assessed against the insider path and the external path together, and against the organization as it actually exists, including its physical plant, personnel, networks and equipment, rather than against a control list. Assessment, planning, testing, validation and, where it becomes necessary, response and remediation are treated as one continuum instead of separate purchases.
Related
Related services
Frequently asked
Common questions
Will testing disrupt operations?
No. Assessment begins passively, and any active step is scheduled, scoped and approved by your operations team in advance. Production systems are never touched without written authorization.
Do you work within NERC CIP evidence requirements?
Yes. Deliverables are structured so findings and remediation records can be used directly in audit evidence packages, rather than rewritten for the auditor afterwards.
Can you support an active incident?
Yes. The 24/7 hotline reaches an examiner, and retainer clients receive a priority response commitment with responders who already know the environment.
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189