IT and OT on one policy language
Zero-trust roadmap, identity and access governance, segmentation and OT security
Identity and network are the preconditions for every other control. We assess IAM maturity and design the zero-trust roadmap, roll out PAM / IGA and conditional access, implement segmentation and SASE, and run dedicated assessments of OT and IoT environments. IT and OT run under one policy framework, with no second rulebook at the boundary.
Our approach
One team scopes, executes and retests; conclusions are delivered as evidence, not checklists.
Access mapping comes first
Who reaches which resource from which device. The assessment maps actual access paths across identity sources, devices and resources against the NIST SP 800-207 zero-trust model, then phases work by risk.
Privileged access is governed first
Privileged accounts are few and high-risk. PAM session audit and least privilege go ahead of company-wide MFA, and typically show measurable reduction within 6–8 weeks.
OT assessment without active scanning
Control networks are sensitive to interference. Assessment relies on passive traffic analysis, configuration review and site interviews; active testing runs only in offline or shutdown windows, with IEC 62443 as the framework.
Deliverables
IAM maturity assessment and zero-trust roadmap
Current score, gaps and phased plan, with technology selection and budget range.
Identity and network policy pack
PAM / IGA / conditional access policy, segmentation design, firewall and SASE policy baselines.
OT security assessment report
Asset inventory, network topology, risks and tiered remediation, organised by IEC 62443 zones and conduits.
How we deliver
Four stages, each with defined inputs, outputs and a client sign-off.
Access mapping
Identity sources, devices, resources and existing policy.
Assessment and roadmap
IAM maturity, network architecture and OT assessment; roadmap delivered.
Phased rollout
PAM / IGA live, network segmentation, OT remediation.
Verification
Policy effectiveness checks and retest.
Case
Provincial power company, China — smart warehouse plant penetration test and OT assessment
Passive assessment of the warehouse plant's OT network without interrupting production, active testing inside authorised windows, lateral paths across the IT / OT boundary identified, segmentation design and remediation list delivered.
Frequently asked questions
Notes on scope, execution and delivery standards. Contact us for anything not covered here.
Zero trust is an access-control model and can be implemented in phases on existing identity sources, network devices and endpoints. The roadmap states which parts reuse current investment and which need new components.
Start from where you stand
Security, data and AI each start with a review of where you stand. The report and its findings are yours, whether or not the engagement continues.