Incident Response & Forensics
We contain the incident, identify the root cause and guide recovery following NIST SP 800-61.
Service
We assess your industrial control systems (IT/OT segmentation, IEC 62443 and NERC CIP) without stopping operations.
The challenge
The SCADA, DCS and PLC systems that run plants, substations and production lines were designed for availability, not to withstand attacks. Today they are connected to corporate networks, the cloud and vendor remote access.
In these environments an incident is not limited to data loss: it can halt production, damage equipment or put people at risk. That is why IT assessment techniques cannot be applied without adaptation.
We work alongside your operations team, favor passive methods, and never run an active test without approval from the process owner.
What we assess
Assessments designed for environments where availability and human safety come first.
Passive identification of PLCs, HMIs, RTUs, historians and engineering workstations, including firmware versions and the protocols they use (Modbus, DNP3, EtherNet/IP, S7, OPC UA).
Review based on the Purdue model and the IEC 62443 zones and conduits approach: industrial DMZ, firewall rules and undocumented communication paths.
Assessment of VPNs, jump servers and vendor access solutions: authentication, session logging and least privilege.
Active testing on replicas, labs or during agreed maintenance windows; never on live processes without explicit approval.
Comparison between target and achieved security levels per zone, with NERC CIP as an additional reference for the power sector.
Assessment of your monitoring visibility over the industrial network, plus tabletop exercises for incidents that affect operations.
How we work
01
We identify critical processes, safety constraints and available windows. Nothing runs without the plant manager’s approval.
02
We capture traffic from SPAN ports or TAPs to inventory assets and communications without generating traffic on the control network.
03
We analyze diagrams and firewall and switch configurations against the zones and conduits model.
04
Only on authorized assets and schedules, preferably on replicas or in a lab, with a defined rollback plan.
05
We prioritize findings by their impact on human safety, production and the environment, not just technical severity.
06
We deliver a phased plan aligned with IEC 62443 and with your operation’s maintenance cycles.
Deliverables
Reference frameworks
Frequently asked questions
We favor passive techniques. Active tests are only performed on authorized assets, on replicas or during maintenance windows, coordinated with operations and backed by a rollback plan.
Usually a SPAN port or a temporary TAP is enough to capture traffic. We do not install agents on PLCs or HMIs.
Yes. We can work at mining and industrial sites, following your health and safety and site access protocols.
It is the family of international standards for the security of industrial automation and control systems. It defines requirements for asset owners, integrators and manufacturers, and is the most widely used reference in OT environments.
With a passive inventory and an architecture review: they carry low risk to operations and give you the foundation to prioritize your next investments.
Other services
We contain the incident, identify the root cause and guide recovery following NIST SP 800-61.
We prepare your organization for ISO 27001, SBS Resolution No. 504-2021, PCI DSS and Law No. 29733, with controls that work in practice.
Outsourced security leadership: strategy, roadmap and board reporting, without the cost of a full-time executive.
Tell us about your objectives and constraints. We will send you a proposal with scope, rules of engagement, timeline and deliverables.