OT/ICS Security
We assess your industrial control systems (IT/OT segmentation, IEC 62443 and NERC CIP) without stopping operations.
Industry
Remote operations, critical OT assets and extended supply chains. We protect production continuity.
The context
Mining operations increasingly depend on technology: control systems in processing plants, fleet telemetry, remotely operated equipment, satellite links and management platforms connected to the cloud.
That digitalization brings efficiency, but it also connects worlds that used to be separate. An intrusion that starts with an email on the corporate network can end up halting production or affecting people’s safety at a site thousands of meters above sea level.
We understand the reality of remote operations, contractors and legacy industrial systems, and we adapt every assessment so it does not interfere with operational continuity.
Key threats
We prioritize the scenarios with the greatest impact on production, safety and reputation.
An attack that encrypts corporate servers can spread to historians, engineering workstations and control systems when IT/OT segmentation is weak.
Vendors and manufacturers that maintain equipment remotely are a frequent entry point when their access is not controlled or logged.
Equipment running unsupported operating systems and industrial protocols without authentication, which cannot be updated at IT’s pace.
Exploration data, reserves, production plans and commercial contracts are targets for espionage and extortion.
Emails and messages targeting those who approve payments or manage access, exploiting the distance between offices and operations.
Cameras, access control and networked monitoring systems that, if poorly protected, become an additional way in.
Regulation and frameworks
The international reference for protecting industrial automation and control systems through zones, conduits and security levels.
Security guidance for industrial control systems, useful to prioritize controls without affecting availability.
An information security management system for corporate processes and strategic information.
A framework to govern cybersecurity risk and report it to the board in a common language.
Protection of the personal data of employees, contractors and surrounding communities under Peruvian law.
International buyers, lenders and cyber insurance policies increasingly ask for evidence of effective controls.
How we help
We combine industrial security and offensive security to protect everything from the corporate office to the plant.
We assess your industrial control systems (IT/OT segmentation, IEC 62443 and NERC CIP) without stopping operations.
Human-led adversary exercises that test whether your organization detects and contains a real attack, with tactics mapped to MITRE ATT&CK.
We contain the incident, identify the root cause and guide recovery following NIST SP 800-61.
Manual testing of web applications, APIs, mobile apps, infrastructure and cloud that goes where a scanner can’t.
Controlled phishing, vishing and malicious QR campaigns that measure the human factor and turn it into a line of defense.
Consulting to design and adopt a zero trust model: identity, segmentation and continuous verification.
Frequently asked questions
Yes. Our consultants can work on site, following your health and safety protocols, inductions and site access requirements.
We favor passive techniques on the industrial network and run active tests only on authorized assets, on replicas or during maintenance windows coordinated with operations.
With an OT asset inventory and a review of contractor remote access: they carry low risk to operations and usually reveal the most important gaps.
We assess how your vendors connect, what they can reach and how their activity is logged, and propose secure, auditable access controls.
Yes. Our incident response team coordinates with operations to contain the threat, prioritizing people’s safety and production continuity.
Other industries
SBS and PCI DSS requirements, digital fraud and exposed APIs. We assess your risk through an attacker’s eyes.
Digital citizen services, personal data and legacy systems. We help public entities protect them.
Tell us about your objectives and constraints. We will send you a proposal with scope, rules of engagement, timeline and deliverables.