Fixes, not a fortune
The gaps AI-driven attackers walk through are basic OT hygiene, not exotic hacks: PLCs exposed to the public internet, remote access with no VPN, default or shared passwords, flat networks, and no tested backups. Most of what stops the next attack costs little. We assess your operation the way an attacker would look at it, tell you plainly what is exposed, and hand you a prioritized plan your own staff can act on. This complements, not replaces, your security specialists, and you will not be oversold.
Independent and vendor-neutral. There is no product to push and no rip-and-replace pitch. All engagements begin with a mutual NDA before any system data is reviewed.
What the assessment checks
1. Exposure & remote access
Find internet-facing PLCs and SCADA and any insecure remote access, the exact attack vector.
2. Credentials & access control
Default, weak, or shared passwords, and exactly who can reach your controllers.
3. IT / OT segmentation
Whether your control network is truly separated from the office network and the internet.
4. Backups & recovery
Config and program backups, tested restore steps, and manual-operation runbooks.
5. Operator detection & alarms
Whether operators will notice a loss of control and can run the plant by hand.
6. Obsolescence & patch status
Aging PLCs, firmware levels, and open vendor advisories that need attention.
What you walk away with
- A prioritized findings report — red / amber / green, so you know what is exposed and what to fix first.
- A fix-it-this-week quick-wins list — mostly free configuration and procedure changes your staff can make now.
- Ready-to-use procedures & policy templates — remote access, credentials, backup, incident response, manual operation.
- Alignment to CISA, EPA / AWIA, AWWA and IEC 62443 — so the work is audit-, grant- and board-ready.
- A funding-ready action plan — one page you can take straight to your board or into a grant application.
It is fixes, not a fortune. Take PLCs off the public internet, put remote access behind a VPN, change default passwords, segment the network, and back up your configs. We find the gaps and hand you the plan. You do not need a million-dollar platform to close the doors the attackers used.
Independent, vendor-neutral, and grant-eligibleHow it works
- We start with a free OT-exposure snapshot to size the risk and confirm the fit.
- We assess your operation across the six areas above, on-site or remotely.
- We deliver the prioritized findings report, quick-wins list, and procedure templates.
- We hand you a funding-ready action plan, and can stay on to help your team close the gaps.
Who it is for
Water & wastewater utilities
Small and mid-size systems that carry SCADA and PLC risk but have no dedicated OT security staff. Assessment findings map directly to EPA / AWIA and AWWA expectations and to state and federal grant programs.
Industrial plants
Refining, chemical, food and beverage, power, and manufacturing sites that need an independent read on OT exposure without a vendor sales pitch attached to the answer.
Related: Water & Wastewater · Obsolescence & Reliability · AI-Attack-Era one-pager (PDF)