You can’t secure what you can’t see.

Cybersecurity for SCADA, DCS, PLC and safety systems across manufacturing, power, smart cities and critical public infrastructure. Assessment, design, implementation and monitoring.

Aligned with IEC 62443 NIST SP 800-82 NIST CSF NCIIPC CEA

Why OT Security Is Not IT Security

In IT, confidentiality usually comes first. On the plant floor, safety and availability do — a control system taken offline to apply a patch can halt a production line or compromise safety, so the tools and tactics that work in the corporate network are often the wrong ones here.

Industrial environments also run equipment measured in decades, not refresh cycles. Controllers that cannot be patched, protocols designed before network security was a consideration, and vendor systems under warranty restrictions all have to be defended as they are, rather than replaced. Meanwhile the air gap most sites believe they have has usually been bridged — by a maintenance laptop, a vendor's remote connection, or the analytics link someone added to feed plant data upstream.

That is the real exposure created by IT/OT convergence: the business network and the process network are already connected, but the security model has not caught up. Routex Technologies closes that gap with controls built around production continuity — so protection is added without becoming the thing that stops the line.

New Builds and Running Plants

Securing a plant still on the drawing board is a different exercise from securing one that has been running for fifteen years. We work at both ends, and the approach changes accordingly.

Greenfield

Designed in from the start

On new builds and expansions, security requirements enter at design stage rather than being retrofitted after handover — when changing them is cheapest and least disruptive.

  • Security requirements written into the specification and tender documents
  • Architecture and zone/conduit design reviewed before procurement is locked
  • Security acceptance built into factory and site acceptance testing
  • Verified again at commissioning, then handed over with documentation
Brownfield

Retrofitted around live production

On plants already in production, nothing can be taken offline to be secured. Every control is chosen and sequenced around the operating schedule.

  • Passive discovery first, so the assessment itself carries no process risk
  • Findings ranked by operational consequence, not CVSS score alone
  • Compensating controls where equipment cannot be patched or replaced
  • Changes staged into existing maintenance windows and shutdowns

What We Deliver

Five engagements, each scoped to a distinct point in an OT security programme. Most clients start with an assessment and progress from there; new-build projects usually start at design.

Engineer working on technical drawings
Design

Security Architecture & Design

Security requirements and network architecture for new plants and expansions — zone and conduit design, secure topology, and requirements written into specifications and tender documents, then verified before handover.

  • Zone & conduit design
  • Tender specification support
  • Factory & site acceptance testing
IEC 62443Purdue Model
Learn more
Structured network cabling and patch panel
Assess

Assessment & Risk Review

Assessment of an operating environment using passive, non-intrusive methods, so nothing is taken offline to be examined. Findings are ranked by operational consequence, not CVSS score alone.

  • Risk assessment
  • Vulnerability assessment
  • Gap assessment against IEC 62443
  • Penetration testing, scoped separately
IEC 62443NIST CSF
Learn more
Technician working on industrial machinery
Implement

Implementation & Hardening

Hands-on deployment inside live production: network segmentation and the IT/OT DMZ, firewall policy, industrial IDS sensor placement, switch and device hardening, and brokered secure remote access.

  • Segmentation & IT/OT DMZ
  • Industrial IDS deployment
  • Secure remote access for vendors
IEC 62443NIST SP 800-82
Learn more
Operators monitoring systems in a control room
Operate

OT Monitoring & SOC Build

Standing up monitoring for the plant: detection use cases, sensor placement, tuning for ICS and SCADA protocols, escalation paths between operations and security, and incident playbooks written for an environment where stopping a process is itself a consequential decision.

  • Detection use cases & SIEM tuning
  • OT-specific detection rules
  • Incident playbooks and team handover
IEC 62443NIST CSF
Learn more
Instructor leading a training session
Enable

Training & Tabletop Exercises

Practical sessions for the people who run the plant — awareness training for operators and engineers, and tabletop exercises that rehearse an OT incident with plant and security teams together, before a real one arrives.

  • OT security awareness training
  • Incident response tabletop exercises
IEC 62443
Learn more

Core Capabilities

OT Asset Discovery & Visibility

Building a complete, continuously updated inventory of every PLC, RTU, HMI, and SCADA node on your network using passive monitoring — establishing what you actually have before deciding how to protect it, with no active scanning and no risk to live processes.

Threat Detection & Anomaly Monitoring

Deploying detection tuned to ICS and SCADA protocols rather than generic IT signatures, so unexpected commands, rogue devices, and abnormal process behaviour surface as alerts your operations team can act on immediately.

Network Segmentation & Purdue Model Architecture

Designing and implementing segmented zones and conduits along Purdue model boundaries, including a properly governed IT/OT DMZ that stops an incident on the business network from ever reaching the plant floor.

OT Vulnerability & Risk Assessment

Assessing exposure using safe, non-disruptive techniques chosen specifically for live production environments — prioritising findings by real operational consequence, not by CVSS score alone, since not every vulnerability can or should be patched in OT.

IT/OT Convergence Security

Securing the connections that convergence depends on: brokered remote access for vendors and integrators, zero trust principles applied to industrial networks, and controlled data flows that let business systems consume plant data without opening a path back in.

Compliance & Framework Alignment

Mapping your OT security programme to the frameworks that govern your sector — IEC 62443 and NIST SP 800-82, alongside the Indian obligations that actually apply to you, from NCIIPC guidance to the CEA power-sector rules — and translating them into a practical, auditable roadmap rather than a compliance paperwork exercise.

Technology Partners

Vendor-Neutral

We are deliberately vendor-neutral. Rather than resell a single platform, we assess your environment — protocol mix, site topology, existing toolchain, and in-house capacity — and then recommend and deploy whichever platform fits each use case. In multi-site estates that frequently means different tools at different plants.

Nozomi Networks

Deep OT and IoT network visibility with process-aware anomaly detection, widely deployed across energy, utilities, and heavy manufacturing.

Armis Centrix

Agentless asset intelligence spanning OT, IoT, and unmanaged devices — useful where a single view across converged environments matters most.

Claroty

Strong industrial protocol coverage with segmentation and secure remote access capabilities suited to complex, multi-site production estates.

Tenable OT Security

Combines OT asset inventory with vulnerability prioritisation, and integrates cleanly where an organisation already runs Tenable on the IT side.

Dragos

ICS-specific threat detection and incident response built on dedicated industrial threat intelligence, with deep expertise in critical infrastructure sectors.

Control Systems We Assess

Passive discovery works at the protocol layer, so coverage does not depend on which brand is on the cabinet. In practice that means the platforms and protocols already running in most plants.

Siemens Rockwell Automation Schneider Electric ABB Honeywell Emerson Yokogawa Mitsubishi Electric
Modbus/TCP PROFINET EtherNet/IP OPC UA DNP3 S7comm IEC 61850 BACnet

Standards & Frameworks

We map your programme to the standards that genuinely apply to your sector and geography. For most Indian operators that means an international reference standard plus a set of domestic obligations — not the North American rules often quoted by default.

IEC 62443
International International Electrotechnical Commission

The reference standard for industrial automation and control system security. Defines security levels and the zone-and-conduit model that most OT architectures are designed against.

Security LevelsZones & ConduitsIACSRisk Assessment
NIST SP 800-82
USA / Global National Institute of Standards and Technology

NIST’s Guide to Operational Technology Security. Practical, control-level guidance written specifically for ICS, SCADA and DCS environments rather than adapted from IT.

ICS SecurityDefence-in-DepthRisk ManagementOT Architecture
NIST CSF
USA / Global National Institute of Standards and Technology

A common language for security outcomes across the organisation. Useful mainly as the shared vocabulary between the plant, the security team and the board.

IdentifyProtectDetectRespondRecover
NCIIPC Guidelines
India National Critical Information Infrastructure Protection Centre

Protection guidance for organisations operating designated critical information infrastructure across sectors such as power, telecom, transport and government.

Critical InfrastructureProtected SystemsAdvisories
CEA Guidelines
India Central Electricity Authority

Cyber security guidelines for the Indian power sector, covering generation, transmission and distribution utilities and their control system estates.

Power SectorGenerationTransmissionDistribution
CERT-In Directions
India Indian Computer Emergency Response Team

National incident reporting obligations, including the six-hour window for reporting cyber incidents and the associated log retention requirements.

Incident ReportingSix-Hour WindowLog Retention

Sector-specific regimes differ. We confirm which apply to your operations during discovery rather than assuming a default set.

Zero
Production Downtime
24/7
ICS Threat Monitoring
IEC 62443
Framework Aligned

Our Engagement Model

01

Discovery & Asset Inventory

We start by establishing ground truth: every device, protocol, and connection on your OT network, gathered passively so production is never interrupted. Most sites find assets and external links here that no one knew existed.

02

Architecture & Segmentation Design

With visibility established, we design the target-state architecture — zones, conduits, and the IT/OT DMZ — and sequence the rollout around your maintenance windows so each change lands without unplanned stoppage.

03

Continuous Monitoring & Response

Once the architecture is in place we operate it: tuned ICS detection, defined escalation paths between plant and security teams, and response playbooks rehearsed against the reality that shutting a process down is itself a decision with consequences.

Common Questions

Will an OT security assessment disrupt production?
No. Discovery is done passively — we listen to a mirrored copy of network traffic rather than probing devices, so there is no active scanning and no traffic sent to controllers. Nothing we do during assessment touches a live process. Where active testing would add value, it is scoped separately and scheduled into a planned shutdown, never run against a production line.
Our plant is air-gapped. Do we still need OT security?
Almost certainly. In practice the air gap has usually been bridged long before anyone documents it — by an engineer's maintenance laptop, a vendor's remote support connection, a USB drive carrying a firmware update, or an analytics link added to feed plant data to the business. Discovery routinely surfaces external connections that nobody on site knew existed. A genuine air gap is also a single control, and it fails completely the moment it is crossed.
We cannot patch our PLCs. What can actually be done?
A great deal, because patching was never going to be the primary control in OT. Much industrial equipment cannot be patched at all, or is locked by vendor warranty. The answer is compensating controls: segment the network so an exposed device is not reachable from anywhere it should not be, monitor it for abnormal commands, and control who can connect to it and how. Prioritise by what an attacker could actually reach and what it would do to the process, rather than by CVSS score.
How is this different from the IT security we already have?
The priorities invert. IT security generally puts confidentiality first; on the plant floor, safety and availability come first, because taking a control system offline to secure it can halt production or create a hazard. The protocols are different too — Modbus, PROFINET and DNP3 were designed before network security was a consideration, and generic IT tooling neither speaks them nor understands what a normal command looks like. Tools built for the corporate network tend to be the wrong ones here, and some of them are actively unsafe to point at a controller.
Which OT security platform should we buy?
That depends on your protocol mix, site topology, existing toolchain and in-house capacity, which is why we stay vendor-neutral rather than reselling one platform. We work across Nozomi Networks, Armis, Claroty, Tenable OT Security and Dragos, and in multi-site estates the right answer is often different tools at different plants. The assessment comes first; the platform recommendation follows from it.
Where should we start?
With an asset inventory. You cannot segment, monitor or risk-rank an estate you cannot see, and most sites do not have a current picture of what is on their OT network. A passive discovery engagement establishes that baseline without touching production, and the findings usually reshape the priority order of everything that follows.

Where We Apply This

Operational technology is not confined to factories. The same control systems, protocols and constraints appear across the sectors we serve.

Related Service

Need to secure the corporate network instead?

Our IT-side practice covers Zero Trust, identity and access management, SIEM and EDR monitoring, and penetration testing across enterprise infrastructure. Most convergence programmes need both.

Explore Cybersecurity & Network Security

Ready to Modernize?

Schedule a deep-dive session with our senior architects to explore how we can accelerate your digital roadmap.

Book Consultation

Do you know what is on your OT network?

Start with a passive OT discovery assessment. We build a complete asset inventory and map your IT/OT exposure without touching a single live process.