Home Services About CASTLE™ Uplink Contact Get Started
Flagship Service · OT Security Assessments

Know Your Real OT Risk. Then Fortify It.

Validated, operationally-aware assessments built on our CASTLE™ methodology, purpose-built for environments where availability and safety come first.

Methodology
CASTLE™ six-pillar framework
Validation
Tested under live operating conditions
Outcome
Board, insurer & audit-ready evidence
Why now

Five signals it's time for an OT assessment

OT environments were built for uptime and safety, not today's threats. A scan tells you almost nothing; a validated assessment shows where you actually stand, without disrupting operations.

A real OT environment — industrial process plant at night
The environments we secure: OT, ICS & building automation
01You face compliance or government cybersecurity requirements.

Frameworks, audits, and contractual mandates now demand OT visibility and control.

Why it mattersCompliance is no longer IT-only. OT is now in audits, procurement, and risk reviews.

ISA/IEC 62443NIST SP 800-82 Rev. 3DoD UFC 4-010-06NIST CSF 2.0
02Your OT and IT networks are connected (or partially integrated).

Control networks sharing pathways with enterprise IT extend your attack surface beyond the original design.

Why it mattersOT needs intentional segmentation, not inherited connectivity.

03You rely on vendors for remote access into critical systems.

Third parties reaching HVAC, BMS, or industrial systems through VPNs and unmanaged gateways mean limited visibility and control.

Why it mattersRemote access is the most common pathway into OT.

04You don't have a complete or current OT asset inventory.

If you can't quickly identify every PLC, HMI, and BAS device, risk management becomes reactive.

Why it mattersYou can't secure what you can't see.

05Your systems were integrated over time by multiple vendors.

Environments grown across projects and acquisitions carry inconsistent configurations and security assumptions.

Why it mattersComplexity breeds risk in mixed BACnet, Modbus, and proprietary BAS environments.

The Assessment Ladder

Four scoped packages, one methodology

Each tier is the same proven methodology at greater depth, so you can start small and step up as risk and budget allow. Scope is banded by environment size, so every tier is quotable.

Entry Diagnostic

OT Recon

Fast risk snapshot to see where you stand and what to fix first.

Typical timeline
~1 week
Essentials

OT Foundations

Validated vulnerabilities, architecture review, and a prioritized roadmap.

Typical timeline
2–4 weeks
Continuous Program

OT Stronghold

Recurring assessment with remediation support.

Cadence
Ongoing

Recon fee can credit toward an upgrade.

Package matrix

See exactly what each package includes

A full capability-by-capability breakdown across all four tiers: discovery, architecture, risk & compliance, validation, and reporting, plus add-ons and deliverables.

OT ReconTier 1
OT FoundationsTier 2
OT FortifiedTier 3
OT StrongholdTier 4
Beyond the assessment

Where your findings lead next

Your assessment ends with a prioritized roadmap. This is how we help you act on it: close the gaps, keep watch, and prove the risk went down.

01 Defend

Remediation & Hardening

Close the gaps your assessment found. We turn your roadmap into action and fix the environment you already run.

  • Network segmentation & secure remote access
  • Device & configuration hardening
  • Compensating controls for legacy systems
Schedule a Remediation Scoping Call →
02 Sustain

Continuous OT Monitoring

Keep the gaps closed. Managed passive visibility and threat detection so new exposures surface early, not at next year's assessment.

  • Passive OT asset & threat visibility
  • Managed detection & alerting
  • Early warning on new exposures
Schedule a Monitoring Discovery Call →
03 Prove

Validation & Reassessment

Prove the risk went down. After your remediation we re-test to confirm the gaps closed and update your risk register, producing the before-and-after evidence your board, insurer, and auditor want.

  • Post-remediation re-testing
  • Updated risk register & evidence
  • Board, insurer & audit ready
Schedule a Validation Call →
A one-time, post-remediation validation. Need it on a recurring cadence? Continuous reassessment is built into OT Stronghold →
Other Services

A full-spectrum OT security partner

Engage these independently or alongside an assessment, from design through audit to ongoing leadership.

New Construction · BAS / OT

Secure-by-Design for New Buildings & OT Projects

Cyber belongs in the design phase, not bolted on after turnover. We embed security into building automation and ICS/OT projects from the first drawing: smart buildings, new plants, campuses, and major retrofits.

Bring cyber into your design phase
Cyber in every phase
Designcyber starts here
SpecDiv 25 / 28
Buildsubmittals
CommissionFAT / SAT
BAS / BACnetIEC 62443Div 25 / 28 SpecsFAT / SAT
What we do
  • Cyber requirements in the basis of design & construction specs
  • Segmented BAS/OT network backbone & secure remote access, designed in
  • Vendor submittal & shop-drawing security reviews
  • FAT/SAT cyber testing & commissioning support through turnover
Best for

Building owners, developers, engineers of record, and design-build teams delivering new facilities, smart buildings, or major BAS/ICS retrofits.

Readiness

Cybersecurity Audit Readiness

Don't meet your auditor unprepared. We get you audit-ready before the real thing: find the gaps, close them, organize the evidence, and rehearse, so audit day is a formality, not a fire drill.

Start your audit prep
The path to audit day
Gapsfind it
Fixclose it
Evidenceprove it
Rehearsemock audit
Audit daywalk in ready
CMMCSOC 2NIST 800-171RMF
How we prepare you
  • Gap assessment against your exact framework: CMMC Level 1–2, SOC 1 & SOC 2 Type II, NIST SP 800-171
  • Prioritized remediation plan, with hands-on help closing the gaps
  • Evidence packages organized the way auditors ask for them
  • Mock audit & interview dry-runs so your team knows what's coming
Best for

Organizations facing a CMMC assessment, a SOC 2 Type II audit window, or DoD / prime-contractor requirements, and teams that want no surprises when the auditor arrives.