Assess

Assessment & Risk Review

Understand your exposure without touching production.

A complete picture of what is on your OT network and what it would actually take to disrupt it — gathered passively, with no risk to live processes.

What This Engagement Covers

Most sites cannot answer basic questions about their OT network with confidence: what is connected, what talks to what, and which paths reach the plant floor from outside. Assessment establishes that baseline.

Everything in the core engagement is passive. We work from a mirrored copy of network traffic rather than probing devices, so no packets are sent to controllers and nothing is taken offline to be examined. Active testing, where it is warranted, is scoped separately and scheduled into a planned shutdown.

Included in Scope

Asset Discovery & Inventory

A continuously observed inventory of every device on the OT network, built without active scanning.

  • PLCs, RTUs, HMIs, SCADA nodes and network devices
  • Protocols in use and the conversations between them
  • External and remote access paths, including undocumented ones

Risk Assessment

Threat scenarios expressed in terms of process consequence, not abstract severity.

  • Scenario-based threat modelling against your process
  • Impact assessed in production and safety terms
  • Risk register your operations team can actually use

Vulnerability & Gap Assessment

Exposure identified passively, then measured against the standard you are held to.

  • Vulnerabilities correlated from asset and firmware data
  • Prioritised by reachability and consequence, not CVSS alone
  • Gap analysis against IEC 62443 with a remediation roadmap

Penetration Testing

Offered separately, under strict rules of engagement, never against a running process by default.

  • Scope and rules of engagement agreed in writing
  • Executed in a planned window or against a test environment
  • Findings documented with concrete remediation guidance

Standards Applied

Work on this engagement is mapped to the standards below, alongside whichever Indian obligations apply to your sector.

IEC 62443NIST CSFNIST SP 800-82

Common Questions

Will the assessment disrupt production?
No. Discovery is passive — we listen to mirrored traffic rather than probing devices, so there is no active scanning and nothing is sent to controllers. Where active testing would genuinely add value, it is scoped as a separate engagement with agreed rules of engagement and scheduled into a planned shutdown.
How long does an assessment take?
It depends on the number of sites, the size of the estate and how much network documentation already exists. We scope it after a short call rather than quoting a standard duration, because a single-line facility and a multi-site estate are very different exercises.
What do we actually receive at the end?
An asset inventory, a risk register written in process terms, a gap analysis against IEC 62443, and a prioritised remediation roadmap. The roadmap is sequenced by operational consequence and by what can realistically be done inside your maintenance windows.

Part of a Wider Practice

This is one of five OT engagements

Design, assessment, implementation, monitoring and training. Most programmes combine several — see how they fit together.

Back to OT Cybersecurity Services

Ready to Modernize?

Schedule a deep-dive session with our senior architects to explore how we can accelerate your digital roadmap.

Book Consultation

Ready to scope this engagement?

Tell us about your environment and we will come back with a scope, not a brochure.