Skip to content
Client access

Service

OT/ICS Security

We assess your industrial control systems (IT/OT segmentation, IEC 62443 and NERC CIP) without stopping operations.

Automation
Kynapt watches the internet-facing edge of your industrial network. Inside the OT network we use passive methods only, never active scanning.
Human validation
Our specialists validate every test in a lab before touching a production environment, and you see the status in your portal.

The challenge

IT/OT convergence expands your operation’s attack surface

The SCADA, DCS and PLC systems that run plants, substations and production lines were designed for availability, not to withstand attacks. Today they are connected to corporate networks, the cloud and vendor remote access.

In these environments an incident is not limited to data loss: it can halt production, damage equipment or put people at risk. That is why IT assessment techniques cannot be applied without adaptation.

We work alongside your operations team, favor passive methods, and never run an active test without approval from the process owner.

What we assess

Visibility, segmentation and control of your industrial systems

Assessments designed for environments where availability and human safety come first.

OT asset inventory

Passive identification of PLCs, HMIs, RTUs, historians and engineering workstations, including firmware versions and the protocols they use (Modbus, DNP3, EtherNet/IP, S7, OPC UA).

IT/OT architecture and segmentation

Review based on the Purdue model and the IEC 62443 zones and conduits approach: industrial DMZ, firewall rules and undocumented communication paths.

Remote and third-party access

Assessment of VPNs, jump servers and vendor access solutions: authentication, session logging and least privilege.

Controlled OT testing

Active testing on replicas, labs or during agreed maintenance windows; never on live processes without explicit approval.

IEC 62443 gap analysis

Comparison between target and achieved security levels per zone, with NERC CIP as an additional reference for the power sector.

OT detection and response

Assessment of your monitoring visibility over the industrial network, plus tabletop exercises for incidents that affect operations.

How we work

Security without compromising continuity

01

Planning with operations

We identify critical processes, safety constraints and available windows. Nothing runs without the plant manager’s approval.

02

Passive discovery

We capture traffic from SPAN ports or TAPs to inventory assets and communications without generating traffic on the control network.

03

Architecture review

We analyze diagrams and firewall and switch configurations against the zones and conduits model.

04

Controlled active testing

Only on authorized assets and schedules, preferably on replicas or in a lab, with a defined rollback plan.

05

Operational risk analysis

We prioritize findings by their impact on human safety, production and the environment, not just technical severity.

06

Roadmap

We deliver a phased plan aligned with IEC 62443 and with your operation’s maintenance cycles.

Deliverables

A plan your operations team can execute

Reference frameworks

  • IEC 62443
  • NIST SP 800-82
  • NERC CIP
  • Purdue model
  • MITRE ATT&CK for ICS
  • OT asset inventoryList of devices, versions and protocols, with the observed communications map.
  • Zones and conduits diagramCurrent and proposed architecture, with the communications allowed between zones.
  • Findings reportEvery finding with evidence, attack scenario and risk to operations.
  • IEC 62443 gap analysisTarget versus achieved security level per zone, with reference to NERC CIP where applicable.
  • Prioritized roadmapControls and segmentation projects ranked by risk, effort and maintenance windows.
  • Management briefingA session with operations, maintenance and security leadership to agree on priorities.

Frequently asked questions

What clients usually ask before we start

Can testing shut down the plant?

We favor passive techniques. Active tests are only performed on authorized assets, on replicas or during maintenance windows, coordinated with operations and backed by a rollback plan.

Do we need to install anything on the control network?

Usually a SPAN port or a temporary TAP is enough to capture traffic. We do not install agents on PLCs or HMIs.

Do you work on site, including remote operations?

Yes. We can work at mining and industrial sites, following your health and safety and site access protocols.

What is IEC 62443 and why does it matter?

It is the family of international standards for the security of industrial automation and control systems. It defines requirements for asset owners, integrators and manufacturers, and is the most widely used reference in OT environments.

Where should we start if we have never assessed our OT network?

With a passive inventory and an architecture review: they carry low risk to operations and give you the foundation to prioritize your next investments.

Other services

A comprehensive view of your security

Compliance & Risk Management

We prepare your organization for ISO 27001, SBS Resolution No. 504-2021, PCI DSS and Law No. 29733, with controls that work in practice.

CISO as a Service

Outsourced security leadership: strategy, roadmap and board reporting, without the cost of a full-time executive.

Kamaya Secure logo on an office wall

Let’s define the right scope for your organization

Tell us about your objectives and constraints. We will send you a proposal with scope, rules of engagement, timeline and deliverables.

Chat on WhatsApp (opens in a new tab)