Home / Capabilities / OT Cyber Program Review
OT Cyber Program Review
Governance, policy, asset management and response readiness measured against NERC CIP, AWIA, the TSA security directives and IEC 62443-2-1.
ENGAGEMENT4–6 weeks
DELIVERYRemote + interviews
MAPPED TONERC CIP · AWIA · TSA SD
Scope
The program, not the packets.
A documentation and interview based review of how OT security is owned, funded, staffed and measured across the organization.
■Governance, ownership and budget
■Policy gap analysis against your applicable standard
■Asset management and change control maturity
■Incident response and recovery readiness
■Three-year roadmap with cost ranges
Levels in scope
L5 / L4Enterprise
ERPEmailCorporate AD
In scopeL3.5Industrial DMZ
Jump hostPatch relayHistorian mirror
In scopeL3Site operations
HistorianEng. workstationDomain ctrl
In scopeL2Supervisory
SCADA serverHMIAlarm server
Out of scopeL1Control
PLCRTUSafety PLC
Out of scopeL0Process
SensorsActuatorsDrives
Out of scopeEngagement timeline
Six weeks to a defensible program.
PH 1WK 1
CollectPolicies, procedures, prior audits, org chart, asset lists.PH 2WK 2–3
InterviewOperations, IT, engineering, leadership. Where the paper and the plant differ.PH 3WK 4–5
AssessMaturity scoring against the standard, gap register, risk statements.PH 4WK 6
PresentBoard-ready readout and a three-year roadmap with cost ranges.You receiveMaturity scorecard, gap register, risk statements, board readout, three-year roadmap.
We need from youProgram documents, six to ten interviews, and one leadership readout.
Other capabilities
