Industrial Cybersecurity

On a plant floor, an incident does not end in data loss: it ends with the line stopped, product wasted or people at risk. And industrial equipment cannot be patched on a Tuesday: many controllers have been running for twenty years and were never designed for anything on the corporate network to talk to them.

Why IT security does not transfer as-is

IT
Confidentiality first
In the office, the serious outcome is a data leak. A server can be rebooted at lunchtime if needed.
OT
Availability and physical safety
On the plant floor, the serious outcome is stopping or a process misbehaving. Nothing is rebooted without a window, and an aggressive scan can take down a PLC.
Consequence
A different method
Passive reconnaissance, non-intrusive testing, and any active test always agreed and run during planned downtime.

What we do

OT asset inventory by passive means: what is connected, on which firmware and talking to whom. Equipment that appears on no drawing turns up almost every time.
Architecture and segmentation reviewed against the zones and conduits model of IEC 62443: whether there is genuine separation between corporate and plant, or just a firewall with allow-all rules.
Remote access by vendors and maintenance contractors, which is the most common entry route and the least controlled.
Industrial protocol analysis and whether traffic is authenticated or in the clear.
SCADA and HMI systems: shared accounts, passwords on screens, unsupported operating systems and workstations connected to the internet «just for updates».
Continuity: whether backups of controller logic exist and whether anyone has ever tried restoring them.

How we work

1
Meeting with production
Before IT. Without understanding the production process and its hazards, an OT audit is dangerous.
2
Passive reconnaissance
Traffic listening and inventory without injecting anything into the industrial network.
3
Documentation and configuration review
Architecture, firewall rules, remote access and user management.
4
Active testing, if appropriate
Only within an agreed scope and, where required, during planned downtime. No window, no active testing.
5
OT risk assessment
Using impact criteria based on production and personnel safety, not confidentiality.
6
A realistic action plan
Compatible with industrial equipment lifecycles. Recommending the replacement of a controller that works is not a plan.

What you get

OT asset inventory with firmware and observed communications.
Map of the real architecture, against the one in the drawings.
Findings report prioritised by impact on production and physical safety.
Gap analysis against the IEC 62443 zones and conduits model.
Phased action plan, compatible with planned shutdowns.
Who does the work. The same team that audits, not an account manager. Governance, risk and compliance: CISSP, CISM, ISO 27001 Lead Auditor, ENS and Risk Analysis (CCN), certified DPO, CCSP and CDPP (ISMS Forum) and PMP (PMI). On the technical side: OSCP, CRTO II and eWPTX, ranked in the top 1% of the CCN-CERT Atenea platform. We have run compliance projects for crypto exchanges, universities and public administrations.

Questions we get asked

Will you stop production?
No. The bulk of the work is passive and does not touch the industrial network. Any test that could affect the process is agreed in writing and run in the window you choose.
Our plant is air-gapped. Why audit it?
Total isolation almost never exists. There is usually a maintenance laptop, a vendor modem, a link to the production management system or a USB stick that travels between both networks. Checking costs little; assuming costs a lot.
Does NIS2 affect us?
Very probably, yes. Manufacturing, energy, water, food and waste are among the covered sectors. And NIS2 does not distinguish between IT and OT: it asks for measures on the systems that support the service.
Do you work with our integrator?
Yes, and it is usually the best arrangement. The integrator knows the process and we bring the security judgement. What we do not do is sell the equipment we then recommend.
Start by knowing what is connected
Half an hour with an auditor to scope a passive inventory and an architecture review that does not touch production.

Book 30 min with an auditor

Phone: +34 686 250 244 (Mon-Fri, 9:00 to 18:00 CET)  ·  Email: info@jaymonsecurity.com
We reply within 2 working hours.
ENES