We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

OT & Industrial Security

OT and ICS security assessment

Assessment and audit of operational technology environments against IEC 62443 and NIST SP 800-82 — zone and conduit architecture, asset inventory, remote access and monitoring — carried out without interfering with live control systems.

What we assess

  • Zone and conduit architecture against IEC 62443 — how the plant is segmented, where the IT/OT boundary actually sits, and whether the DMZ does what the diagram claims.
  • Asset inventory and criticality: what is actually on the network, including the devices nobody documented and the engineering laptop that moves between zones.
  • Remote access — vendor, integrator and employee paths into the OT network, which is the route most incidents take.
  • Patch and lifecycle reality: unsupported operating systems, vendor-locked systems, and compensating controls where patching is genuinely not an option.
  • Monitoring, logging and OT-specific incident response, including whether the SOC can interpret an OT alert at all.
  • Governance against IEC 62443-2-1 — the security programme, roles, and the contractual security terms placed on integrators.

What we do not do — deliberately

We do not run active scans, exploit attempts or intrusive tests against live control systems, PLCs or safety instrumented systems. In OT, an availability incident is a safety incident, and a scan that would be routine on a corporate network can trip a controller. Our assessment relies on architecture and configuration review, interviews, documentation, passive review, and where testing is appropriate it is confined to the IT/DMZ boundary or to an offline or vendor-provided test environment, agreed in writing beforehand. If your requirement is live testing inside the process network, you need a specialist OT testing firm and we will tell you so rather than take the work.

Why OT security is not IT security with different acronyms

  • The priority order inverts. IT optimises for confidentiality; OT optimises for safety and availability. A control that protects data but risks a trip is the wrong control.
  • Protocols were not designed for hostile networks. Modbus, DNP3 and similar carry no authentication by design, so segmentation and monitoring carry the load that authentication carries in IT.
  • Patch windows are measured in years, not days, and are set by production schedules and vendor validation — compensating controls are the realistic answer, not a patching SLA.
  • The vendor owns the system. Touching it can void support, so remediation has to be negotiated with the OEM rather than scheduled by IT.
  • Flat networks are common. Segmentation that exists on the drawing and not in the switch configuration is the most frequent finding we raise.

The standards we assess against

  • IEC 62443 — the industrial automation and control systems series: zones and conduits, security levels, the 62443-2-1 security programme for asset owners and the 62443-3-3 system requirements.
  • NIST SP 800-82 — the OT security guidance, including how the general control catalogue is tailored for operational technology.
  • Sector expectations where they apply — power, oil and gas, water, pharmaceutical manufacturing and critical infrastructure obligations in the jurisdictions you operate in.

What you receive

  • A zone and conduit model of the environment as it actually is, not as documented.
  • A gap register mapped to IEC 62443 and NIST SP 800-82, with each finding rated for safety and production impact rather than CVSS alone.
  • A remediation roadmap sequenced around real outage windows and vendor constraints.
  • Evidence suitable for your board, your insurer or a regulator asking what you have done about OT risk.

Related

OT assessments sit alongside security architecture review for the enterprise side of the boundary, identity and access management for the remote-access paths that reach the plant, and business continuity, since an OT incident is an availability event before it is a security one.

Free tool
Free Security Assessment
Get a complimentary, no-obligation assessment from CERT-In empanelled senior auditors.
Try it free →
PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

OT & ICS security — common questions

Will the assessment disrupt production?

No. We do not run active scans, exploit attempts or intrusive tests against live control systems, PLCs or safety instrumented systems. The work is architecture and configuration review, interviews, documentation and passive review, with any testing confined to the IT/DMZ boundary or an offline environment, agreed in writing in advance.

Do you assess against IEC 62443 or NIST SP 800-82?

Both, and they complement each other. IEC 62443 provides the zone and conduit model, security levels and the asset-owner security programme; NIST SP 800-82 provides OT-specific guidance and control tailoring. Findings are mapped to whichever your stakeholders report against.

What is the most common finding in Indian OT environments?

Segmentation that exists on the architecture diagram but not in the switch configuration, closely followed by uncontrolled vendor remote access. Both are structural rather than technical, and both are fixable without touching a controller.

We cannot patch our control systems. Is an assessment still useful?

Yes, and that constraint is assumed rather than treated as a failing. Where patching is not viable because of vendor validation or production schedules, the assessment focuses on compensating controls — segmentation, access control, monitoring and recovery — and documents the accepted risk in a form your board and insurer can rely on.

Do you perform penetration testing inside the process network?

Not on live control systems. In OT an availability incident is a safety incident, so intrusive testing belongs in an offline or vendor-provided environment with specialist support. If that is your requirement we will say so rather than take the engagement — our OT work is assessment and audit.

Ready to discuss your OT / ICS security assessment requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.

Talk to an expert →Request a scope review

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →