Skip to content

Industrial & OT Technology

ICS & SCADA Security Assessment

Passive asset discovery, vulnerability triage and a ranked, costed remediation roadmap.

Overview

Most industrial security assessments produce a vulnerability dump: hundreds of findings, no ranking, no cost, and no route to acting on any of it. The report gets filed.

We assess against IEC 62443 and NIST SP 800-82, then rank every finding by operational risk and remediation cost, so the roadmap is something a plant manager can actually fund.

What is included

  • Passive asset discovery with no impact on live processes
  • Asset inventory the operations team can maintain
  • Vulnerability identification and exploitability triage
  • Assessment against IEC 62443 and NIST SP 800-82
  • Architecture and segmentation review
  • Risk ranking weighted by safety and production impact
  • Costed remediation roadmap
  • Board-level and engineer-level reporting

How we run it

  1. 01

    Scope

    Agree scope, safety constraints and the standards the assessment reports against.

  2. 02

    Build

    Passive discovery and interviews, with no active scanning on production networks.

  3. 03

    Launch

    Triage findings by exploitability and consequence, then cost the remediation.

  4. 04

    Measure

    Present to both the operations team and the board, in the language each needs.

Questions

Before you enquire

Is active scanning involved?
Not on production control networks. Passive discovery avoids the risk of tipping over legacy devices that were never built for scanning.
How long does an assessment take?
Four to six weeks for a single site, including the walkdown and reporting.
Do you retest afterwards?
Yes, and we recommend it once the first remediation phase is complete so progress is evidenced.

Often bought together

Next step

Need ics & scada security assessment?

Tell us what you are trying to achieve and by when. We will come back with scope, price and an honest view on fit.