# OT Cyber Program Review

> Governance, policy, asset management and response readiness measured against NERC CIP, AWIA, the TSA security directives and IEC 62443-2-1.

Canonical: https://blackbirdcyber.com/capabilities/ot-cyber-program-review  
Blackbird Cyber · https://blackbirdcyber.com/ · sales@blackbirdcyber.com

## Engagement

- Engagement: 4–6 weeks
- Delivery: Remote + interviews
- Mapped to: NERC CIP · AWIA · TSA SD

## Scope — The program, not the packets.

A documentation and interview based review of how OT security is owned, funded, staffed and measured across the organization.

- Governance, ownership and budget
- Policy gap analysis against your applicable standard
- Asset management and change control maturity
- Incident response and recovery readiness
- Three-year roadmap with cost ranges

## Purdue levels in scope

| Level | Name | Systems | Scope |
| --- | --- | --- | --- |
| L5 / L4 | Enterprise | ERP, Email, Corporate AD | In scope |
| L3.5 | Industrial DMZ | Jump host, Patch relay, Historian mirror | In scope |
| L3 | Site operations | Historian, Eng. workstation, Domain ctrl | In scope |
| L2 | Supervisory | SCADA server, HMI, Alarm server | Out of scope |
| L1 | Control | PLC, RTU, Safety PLC | Out of scope |
| L0 | Process | Sensors, Actuators, Drives | Out of scope |

## Engagement timeline — Six weeks to a defensible program.

- PH 1 · WK 1 · **Collect**: Policies, procedures, prior audits, org chart, asset lists.
- PH 2 · WK 2–3 · **Interview**: Operations, IT, engineering, leadership. Where the paper and the plant differ.
- PH 3 · WK 4–5 · **Assess**: Maturity scoring against the standard, gap register, risk statements.
- PH 4 · WK 6 · **Present**: Board-ready readout and a three-year roadmap with cost ranges.

## You receive

Maturity scorecard, gap register, risk statements, board readout, three-year roadmap.

## We need from you

Program documents, six to ten interviews, and one leadership readout.

## Other capabilities

- [OT Cyber Consulting](https://blackbirdcyber.com/capabilities/ot-cyber-consulting): Fractional OT security leadership for operators without a full-time ICS team.
- [OT Network Architecting](https://blackbirdcyber.com/capabilities/ot-network-engineering): Segmented control networks designed and built to keep the process running.
- [OT Cyber Audit](https://blackbirdcyber.com/capabilities/ot-cyber-audit): A site-level assessment of control system exposure, ranked by consequence.

## Scope this engagement

Use the [contact form](https://blackbirdcyber.com/contact) or email sales@blackbirdcyber.com.
