Defend
Defensive guides
Each guide states the goal, why it matters in OT, how to implement it without disrupting the process, what good looks like, and how to verify it.
Why should I care?
Generic IT hardening advice fails in plants because it ignores availability, reliability and safety constraints. These guides are written for equipment that cannot be rebooted on demand.
Group
Foundations
OT Asset Inventory
Maintain a current, accurate record of every OT asset, its function, and its criticality.
Legacy & Unsupported Systems
Manage systems that cannot be patched with compensating controls and a lifecycle plan.
Physical Security for OT
Prevent physical access to control equipment that would bypass network controls entirely.
Group
Architecture
Group
Access
Secure Remote Access
Make every remote session into OT identified, approved, mediated, time-bounded and logged.
Identity & Privileged Access
Ensure every action in OT is attributable to a person and privileges are minimal and time-bound.
Third-Party & Vendor Management
Hold vendors to the same access and security standards you hold yourself to.
Group
Endpoints
Group
Resilience
Group
Vulnerability
Group