OT Cybersecurity Risk Assessments That Are Safe for Live Plant

A structured assessment of your SCADA and control systems using IEC 62443-3-2, rated on your own corporate risk matrix, with a prioritised plan you can fund. Delivered by an independent, IEC 62443-certified consultant based in Brisbane and working Australia-wide.

What You Get

Every assessment answers three questions for the people who own the risk: what could go wrong, how likely and how bad it would be, and what to do first.

Architecture and inventory

An up-to-date picture of what is connected to what: control system servers, PLCs and RTUs, networks, telemetry links, and the remote access paths and vendor connections that often never made it onto the drawings.

Zone and conduit model

Your system partitioned into security zones and conduits according to IEC 62443-3-2, with a target security level for each zone.

Threat scenarios and consequences

Credible attack and failure scenarios described in operational terms: what would stop, spill, overflow or trip, and what that would mean for safety, the environment, customers and the regulator.

A risk register on your own risk matrix

Risks rated with your enterprise risk framework (typically ISO 31000-based), so OT risk sits next to every other risk the executive and board already see, instead of in a separate cyber language.

Gap assessment against your obligations

Current controls compared with the frameworks you answer to: IEC 62443-3-3, the SOCI Act CIRMP rules, the AESCSF, the Essential Eight and NIST SP 800-82.

A prioritised roadmap

Quick wins, projects to fund, and risks to formally accept, in order and with indicative effort, plus an executive summary the board can act on.

How an Assessment Runs

  1. Scoping and document request

    A short call to agree the sites and systems in scope, then a request for what already exists: network drawings, asset lists, firewall configurations, previous audits and incident history.

  2. Workshops

    Sessions with operations, engineering, IT and whoever manages vendors, to understand how the system is really run and supported.

  3. Site walk-downs

    Visits to representative sites, such as control rooms, treatment plants, pump stations or substations, to check the drawings against reality.

  4. Passive technical review

    Firewall rule and configuration reviews, checks of servers and network devices and, where useful, passive traffic capture to confirm assets and data flows. Nothing sends traffic to live controllers.

  5. Analysis and risk rating

    Scenarios, likelihood and consequence rated with you, so the results reflect your operating context.

  6. Report and debrief

    A draft for your review, a walkthrough with the technical team, and a final report with an executive summary.

Is This a Penetration Test?

Not by default. Active scanning and penetration testing of live control systems can crash older PLCs, RTUs and protocol stacks, and an outage caused by a security test is still an outage. Most of what a test would find in OT, such as flat networks, shared accounts, unpatched servers and uncontrolled remote access, can be found safely with the passive methods above.

Where active testing does add value, it should be scoped to be safe: run against test systems, standby servers or plant that is down for maintenance, with operations agreeing every step. If you have been asked for an "OT penetration test", I can help you work out what you actually need and scope it safely.

When to Commission One

  • Before your SOCI Act CIRMP annual report, so the board approves it with current OT risk in front of them
  • Before a SCADA upgrade or migration, so security requirements go into the design instead of being retrofitted
  • When connecting OT to the cloud or adding IIoT devices
  • After an acquisition, a new site, or a major change to how the system is supported
  • After an incident or near miss
  • When a regulator, auditor or insurer asks how OT risk is managed

Frequently Asked Questions

How long does an OT risk assessment take?

It depends on the size and complexity of the environment. A targeted assessment of a single facility can take one to two weeks; an enterprise-wide assessment across many sites and systems can take four to eight weeks or more. A scoping call is the best way to estimate the effort.

Will the assessment disrupt operations?

No. The default method is passive: documents, workshops, site walk-downs, configuration reviews and, where useful, passive traffic capture. Nothing sends traffic to live controllers unless you have agreed a specifically scoped test.

What do you need from us?

Time with the people who run and support the system, the drawings and configuration you already have, and escorted access where site walk-downs are needed. Missing or outdated documentation is normal; finding out what is really there is part of the job.

How is an OT risk assessment different from an IT one?

IT assessments centre on confidentiality and data. In OT the priorities are safety and availability, and the question is what happens to the physical process. OT also brings long-lived equipment that can't simply be patched or scanned, industrial protocols, and consequences measured in spills, outages and injuries rather than lost records.

Does an OT risk assessment satisfy the SOCI Act?

It supports it. The SOCI Act's risk management program rules require you to identify and minimise material risks, including cyber and information security hazards, and to comply with a recognised cyber framework. An OT risk assessment provides the evidence for the operational technology part of that. The program also covers personnel, supply chain, and physical and natural hazards, which usually sit with other teams.