OT security for critical infrastructure
Securing industrial control and automation systems, where availability and safety come first.
OT follows different priorities than IT.
Industrial control and automation systems make demands that classic IT does not. Three points shape the starting position.
Different priorities
In OT, availability comes before confidentiality. A plant must not stop, a process must not tip. Systems run for decades and speak proprietary protocols for which patches are rare.
A growing attack surface
With IT/OT convergence, process networks are connected to the corporate network, remote maintenance arrives, and old controllers become reachable. That seam is where we test.
Non-disruptive
Every test runs without interrupting operations. Critical steps are agreed beforehand; we work in agreed windows or on test rigs, and we stay reachable throughout.
Five categories for OT.
Each category is cut for industrial environments. One sentence to place it, the rest is on its own page.
- OT penetration testing and assessments OT and ICS, SCADA, IEC 62443 risk assessment.
- OT SOC, SIEM and monitoring OT monitoring, anomaly detection, SIEM integration.
- OT cyber exercises and crisis management Red, blue and purple team, tabletop, crisis simulation.
- OT compliance and consulting KRITIS, IEC 62443, NIS2, network segmentation.
- OT training OT awareness, live hacking on ICS.
Tested in our own OT lab.
Our procedures come from real plant, not from a whiteboard. In the OT lab we run demonstrators from several sectors, on which attacks and defences can be played through reproducibly.
YekCity
Built from the analysis of real attacks on power and utility networks: a model city with real controllers, on which those attacks can be replayed, detected and practised.
YekTrain
Vehicle systems on MVB and CANopen, built from recordings of real trains. Attacks and their detection can be shown on it reproducibly.
YekCar
Emulated control units with CAN, UDS and keyless entry, with an attacker dashboard and an IDS monitor in the same case.
What OT has to be measured against.
These frameworks are the reference for our tests. The formal classification is one you make with your own compliance people.
IEC 62443
The technical structuring model for OT security.
NIST SP 800-82
Guide to securing industrial control systems.
ISO 27019
Information security for energy supply in particular.
KRITIS
German duties for operators of critical infrastructure.
NIS2
EU directive to raise cyber resilience.
Keep your OT in view.
A first conversation usually takes 30 minutes. We listen, place your situation and say frankly which test fits your plant.