Industrial and OT security for the systems that run physical operations.
Plants, grids, meters and city infrastructure run on control systems that were never designed to be connected — and cannot simply be taken offline to be fixed. Our industrial practice works to IEC 62443 across the full estate, with availability and safety treated as the first constraints rather than obstacles.
- IEC 62443
- Programme backbone
- SL-T / SL-A
- Security level driven
- Zones & conduits
- Risk-based design
Standards in scope
IEC 62443
Industrial automation and control systems security
IEC 62351 / 61850
Power system communications and substation automation
NIST CSF / ISO 27001
Governance and management system alignment
Sector directives
Regulatory and national cybersecurity requirements
The standards an industrial programme is measured against.
IEC 62443 provides the method and the vocabulary. Sector standards and national guidelines sit on top of it — we map one set of evidence across all of them rather than running parallel compliance exercises.
Industrial automation and control systems security
The core series across asset owner programmes (2-1), system risk assessment and design (3-2, 3-3) and product supplier obligations (4-1, 4-2).
How we support you
- Security programme (CSMS) design and rollout
- Zone and conduit partitioning with risk register
- Target and achieved security level analysis
- Cybersecurity requirements specification
- Vendor and contractor security requirements
- Certification readiness for recognised schemes
Power system communications and substation automation
Protocol-level security for power environments — authentication, integrity and key management across substation and control-centre traffic.
How we support you
- Protocol security assessment
- Substation architecture and IED hardening review
- Certificate and key management approach
- Station and process bus segmentation
- Legacy protocol migration planning
- Commissioning-stage security verification
Governance and management system alignment
Where the industrial programme has to interface with enterprise security governance, risk reporting and an existing information security management system.
How we support you
- Maturity assessment against NIST CSF functions
- IT and OT governance interface definition
- Risk reporting suited to board consumption
- Policy harmonisation across IT and OT
- Control mapping to avoid duplicated effort
- Integrated audit preparation
Regulatory and national cybersecurity requirements
NIS2 for European operations, national critical-infrastructure guidance and sector regulator expectations, translated into concrete technical obligations.
How we support you
- Applicability analysis for your operating regions
- Clause mapping onto existing technical evidence
- Incident notification and reporting processes
- Supply chain and third-party risk requirements
- Audit readiness review
- Gap closure plan with owners and timelines
Sectors we work across
What an industrial engagement covers.
The same seven services run across every practice, so you can compare scope without re-learning the menu.
Risk assessment
Zone and conduit risk assessment to IEC 62443-3-2 across ICS, SCADA, DCS and PLC environments, producing defensible target security levels.
Advisory & consulting
OT security strategy, governance and architecture review — deciding who owns what across the IT and OT boundary, and what good looks like for your estate.
VA-PT & security testing
Passive assessment and configuration review on live plant; active testing confined to lab, FAT or planned outage windows. Availability is never the price of a test.
Compliance & audit readiness
Readiness for IEC 62443 certification, sector regulators and internal audit, with evidence traceable clause by clause.
Implementation support
Segmentation, industrial DMZ, secure remote access, endpoint hardening and OT monitoring integration, sequenced around outage windows.
Security operations
Extending detection and response into OT, with incident procedures that account for safety, physical consequence and service continuity.
Training & capability
Awareness for engineers and operators, IEC 62443 training for practitioners, and governance briefings for leadership.
Systems we work across
- SCADA, DCS and plant control systems
- PLC, RTU and safety instrumented systems
- Substation automation and protection relays
- Metering head-end and AMI infrastructure
- Historians, engineering workstations and HMIs
- Industrial networks, firewalls and remote access
- OT monitoring and asset discovery platforms
- Greenfield projects and brownfield migrations
What you receive
- Asset inventory and system under consideration definition
- Zone and conduit architecture with risk register
- Cybersecurity requirements specification for vendors and EPC contracts
- Target versus achieved security level analysis
- Policy, procedure and security programme documentation
- Prioritised remediation roadmap with outage-aware sequencing
Building or repairing an industrial security programme?
Tell us the assets in scope and any audit or certification milestone you are working to, and we will come back with a practical starting point.