Assess
IEC 62443 Assessment and Attestation
Independent assessment against the applicable parts of IEC 62443. We define the scope
and criteria, evaluate implementation evidence, and issue a clear attestation of the
assessed alignment for owners, regulators, and lenders.
Specify
Cybersecurity Requirements and Procurement Assurance
We translate risk into testable requirements for technical specifications, tender
documents, and contracts. We support supplier qualification, bid evaluation,
deviation management, and acceptance criteria so security commitments remain
enforceable throughout delivery.
Evaluate
Independent Vendor and Tool Evaluation
Independent evaluation of operational technology suppliers, platforms, and security
tools. We assess functional fit, integration risk, component capabilities, lifecycle
support, maintainability, and evidence against the system requirements and operating
constraints.
Architect
OT Architecture and Design Assurance
We review and develop operational technology architecture from the system boundary
through every external interface. Work covers zones and conduits, vendor remote
access, enterprise and cloud connectivity, boundary protection, monitoring,
resilience, and operational constraints.
Verify
Commissioning and Handover Verification
We verify that design and contract requirements are implemented before operational
acceptance. Reviews cover configurations, access, asset inventories, logging,
backups, recovery evidence, test results, deviations, and handover records across
factory and site acceptance.
Improve
Operational Security Improvement
Focused posture assessments and prioritised improvement roadmaps for operating
assets. We address asset management, access governance, vulnerability and patch
processes, monitoring, incident response, change control, supplier management,
competence, and assurance evidence.
Recover
Resilience and Recovery Engineering
We engineer systems to maintain essential functions during cyber incidents and
restore controlled operation. Work includes degraded modes, cyber-independent
safeguards, backup and recovery arrangements, response interfaces, restoration
testing, and exercises that expose dependencies before an incident.
Decide
Technical Cyber Due Diligence
Independent review for acquisitions, financing, investment, and portfolio oversight.
We assess architecture, control maturity, IEC 62443 alignment, regulatory exposure,
supplier dependencies, inherited vulnerabilities, recovery capability, and
remediation priorities.