Phi Tech Solutions

Engineering for process plants since 2005

phitech.com.pk (opens in a new tab)

Process engineering, process control and OT security, in one company.

Phi Tech Solutions has worked in process plants since 2005. PhiSecure is its OT cybersecurity practice, working alongside the company's process engineering, process control and reliability teams.

Visit phitech.com.pk (opens in a new tab)
A magnifying glass beside instrument components on a workbench

Assess

Risk Assessment

We divide your control system into zones and conduits and assess the risks in each one against your own process.

Our approach

  1. Stage 01AssessMeasure your exposure
  2. Stage 02DesignPlan the architecture
  3. Stage 03DeployInstall the technology
  4. Stage 04SustainMaintain security
01

Overview

What the service covers and why it matters

We divide the control system into zones and conduits and assess, zone by zone, what a security failure would mean for your process, your product and your safety case.

Each zone is given a target security level and an assessment of its current level. The difference between the two shows where to invest first.

At a glance

Standard
IEC 62443-3-2
Stage
Assess, stage 1 of 4
Usually follows
Gap assessment
Sectors
All

What the assessment covers

  • Where the zone boundaries are, and why they are placed there
  • Which conduits cross those boundaries, and what traffic each one allows
  • What could go wrong in each zone, considered against your process
  • What the consequences would be for production and safety
  • The security level each zone should reach
  • The level each zone is at today, and the gap between the two

Why it matters

Most plants have more to fix than they can afford to fix at once. A clear way of ranking the work makes sure the budget goes where it has the most effect.

Generic severity ratings do not reflect what a failure would cost you in production, product quality or safety. This assessment does.

A zone with a target security level of 3 and a current level of 1 gives decision makers a clear, measurable case for investment.

02

Scope

What this service does not include

  • Not a vulnerability scan.A vulnerability scan lists missing patches. This assessment considers what would happen if a weakness were exploited, and whether it matters in your plant.
  • Not a generic threat report.Every scenario is written for your process. Threats that cannot reach your plant are left out.
  • Not a design.This assessment shows where the risk is. Designing the fixes is a separate service, IT and OT network architecture design.
  • No shutdown.We do not change or interrupt any running system during this work.
03

How it works

The steps and what you receive

  1. The system divided into zones and conduits with your engineers
  2. Each asset assigned to a zone, with the reasons recorded
  3. Threat scenarios written for each zone
  4. Consequences assessed together with operations staff
  5. Target and current security levels set for every zone
  6. A risk register delivered, ranked by the size of each gap

What you receive

  • Asset and zone mapThe control system divided into zones, with every asset placed and the reasons recorded.
  • Threat scenariosWritten for your process and assessed together with your operations staff.
  • Security levels by zoneTarget and current levels for each zone, so the gap can be measured.
04

Who it is for

When this service is the right choice

  • You have a list of issues and no clear way to prioritize them
  • A gap assessment has shown that your programme needs work and you need to know where to start
  • You need to justify OT security spending in terms of operational risk
  • A safety case or an insurer requires a formal risk assessment

Related services