
Assess
Risk Assessment
We divide your control system into zones and conduits and assess the risks in each one against your own process.
Our approach
- Stage 01AssessMeasure your exposure
- Stage 02DesignPlan the architecture
- Stage 03DeployInstall the technology
- Stage 04SustainMaintain security
Overview
What the service covers and why it matters
We divide the control system into zones and conduits and assess, zone by zone, what a security failure would mean for your process, your product and your safety case.
Each zone is given a target security level and an assessment of its current level. The difference between the two shows where to invest first.
- Standard
- IEC 62443-3-2
- Stage
- Assess, stage 1 of 4
- Usually follows
- Gap assessment
- Sectors
- All
At a glance
What the assessment covers
- Where the zone boundaries are, and why they are placed there
- Which conduits cross those boundaries, and what traffic each one allows
- What could go wrong in each zone, considered against your process
- What the consequences would be for production and safety
- The security level each zone should reach
- The level each zone is at today, and the gap between the two
Why it matters
Most plants have more to fix than they can afford to fix at once. A clear way of ranking the work makes sure the budget goes where it has the most effect.
Generic severity ratings do not reflect what a failure would cost you in production, product quality or safety. This assessment does.
A zone with a target security level of 3 and a current level of 1 gives decision makers a clear, measurable case for investment.
Scope
What this service does not include
- Not a vulnerability scan.A vulnerability scan lists missing patches. This assessment considers what would happen if a weakness were exploited, and whether it matters in your plant.
- Not a generic threat report.Every scenario is written for your process. Threats that cannot reach your plant are left out.
- Not a design.This assessment shows where the risk is. Designing the fixes is a separate service, IT and OT network architecture design.
- No shutdown.We do not change or interrupt any running system during this work.
How it works
The steps and what you receive
- The system divided into zones and conduits with your engineers
- Each asset assigned to a zone, with the reasons recorded
- Threat scenarios written for each zone
- Consequences assessed together with operations staff
- Target and current security levels set for every zone
- A risk register delivered, ranked by the size of each gap
What you receive
- Asset and zone mapThe control system divided into zones, with every asset placed and the reasons recorded.
- Threat scenariosWritten for your process and assessed together with your operations staff.
- Security levels by zoneTarget and current levels for each zone, so the gap can be measured.
Who it is for
When this service is the right choice
- You have a list of issues and no clear way to prioritize them
- A gap assessment has shown that your programme needs work and you need to know where to start
- You need to justify OT security spending in terms of operational risk
- A safety case or an insurer requires a formal risk assessment

