SPC / SPC-01
Industrial environment security — OT/ICS
Assess and strengthen systems controlling physical processes while respecting availability and safety. Standard IT methods must be adapted with operators and control-system engineers.

WHEN IT HELPS
A focused response
to a defined need.
Plant connected to corporate IT, remote maintenance, legacy equipment, poor industrial-traffic visibility or a new IT/OT convergence project.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Documentary inventory and passive-first observation
- criticality
- traffic
- remote access
- IT/OT separation
- administration
- backups
- patch constraints
- suitable detection
- governance
Deliverables
- Asset map
- risk assessment
- zone architecture
- security plan
- maintenance procedures
- constraint register
- authorised tests and compensating controls
Acceptance evidence
Operations approves scope and constraints; access and separation are tested without unapproved risk; controls are documented; residual risks have an accountable decision-maker.
DELIVERY
How the work is structured.
Approach
Verify expertise and authorisation; scope constraints; collect without unapproved risk; assess and propose; validate with competent owners.
Prerequisites & responsibilities
Customer: decision authority, operators, control engineers or transaction leads as applicable. Provider: validated expertise; specialist partners where needed and approved.
Scope factors
Sites, systems, safety, evidence access, independence and qualification requirements. Bespoke engagement; effort and subcontracting confirmed before proposal.
Questions to clarify
Which actions could affect safety or stop production? Who authorises testing? Which equipment supports neither agents nor active scanning?
IMPORTANT BOUNDARIES
Industrial safety and operational continuity govern the engagement. Intrusive scans, load tests and process changes require explicit authorisation, safety approval and the appropriate specialist resources.
Delivery is conditional on the specialist resources, authorisations and framework requirements established during scoping. Formal qualifications and clearance are confirmed where required.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A plant retains permanent supplier access. Project: map and restrict access and require maintenance approval. Target outcome: workable, better-tracked maintenance without risky controller changes.
Scenario 02
An industrial site uses unsupported equipment. Project: analyse traffic, isolate systems and plan replacement. Target outcome: reduced exposure through compensating controls; unpatchable components remain a documented risk.
Technology and reference context
Reference: NIST SP 800-82 Rev. 3; observation and segmentation tools compatible with industrial constraints.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
