OT · IoT · IIoT SECURITY & RISK INTELLIGENCE

OT Security &
Risk IntelligenceFrom floor to boardroom.

Specialist OT consulting. Passive OT, IoT and IIoT visibility—turning evidence into action.

13 years of OT security experience · ISA/IEC 62443 ExpertFounder’s qualifications and experience

Assessment support: IEC 62443 · NIS2 readiness · NIST SP 800-82

  • Passive monitoring
  • Offline-capable
  • OT · IoT · IIoT
  • Practitioner-led
Example production cellILLUSTRATIVE PLATFORM PREVIEW

Command Centre

Sample assets and risk priorities
24Observed assets
6Risks to review
3Priority actions

Priorities for your team

  • HIGH
    Engineering accessReview the production control zone.
  • MEDIUM
    Controller firmwareValidate the installed version.
  • MEDIUM
    Communication pathConfirm the flow with its owner.
Illustrative sample data · pre-launch platformFull platform tour

Industrial expertise meets passive risk intelligence. Assess your environment, strengthen the architecture, and build evidence for informed decisions. Consulting available now; platform pilots in preparation.

Standards-informed consulting and evidence workflows

  • IEC 62443
  • NIST SP 800-82
  • NIS2 readiness
Assessment and evidence support. Certification and compliance require separate review.
01

Passive at the coreVisibility from authorised OT capture data.

02

Offline by designKeep production operation independent of the internet.

03

Evidence you can useBring technical findings into practical decisions.

CONSULTING SERVICES

Specialist OT expertise.
From assessment to handover.

Work with OTCogniShield on OT security, architecture and delivery. OTCogniShield adds a platform for ongoing visibility and evidence alongside the consulting engagement.

Consulting engagements available

Choose a focused review or support across the project lifecycle. Scope, deliverables and fees are agreed around your environment.

01IEC 62443 compliance consultingSecurity management, systems and product security

Translate the relevant IEC 62443 requirements into a practical programme, with clear responsibilities, assessment evidence and a plan for implementation.

  • IEC 62443-2-1 — security management
  • IEC 62443-2-3 — patch management
  • IEC 62443-2-4 — service provider requirements
  • IEC 62443-3-2 — risk assessment
  • IEC 62443-3-3 — system security requirements
  • IEC 62443-4-1 / 4-2 — product security processes and requirements
Discuss IEC 62443 consulting
02OT security architecture designZones, conduits and secure industrial connectivity

Develop an architecture that reflects the way your plant operates, including access needs, legacy constraints and the boundaries between IT and OT.

  • Zone and conduit design
  • Purdue-aligned network segmentation
  • OT DMZ design
  • Secure remote access
  • Unidirectional controls
  • IT / OT integration
Discuss your architecture
03Risk assessmentOperational consequences, priorities and ownership

Agree the assessment scope, understand the threats and consequences, and develop recommendations that your engineering and management teams can review.

  • IEC 62443-3-2 aligned risk assessment
  • Assessment informed by NIST SP 800-82
  • TS 50701-aligned rail cybersecurity assessment
  • NIS2 readiness and gap assessment
Discuss a risk assessment
04Project deliveryFrom early design through commissioning and handover

Bring OT security requirements into project decisions and supplier interfaces, with support through design assurance, testing and acceptance.

  • Front-end engineering design (FEED) support
  • Detailed design and design reviews
  • Supplier coordination and assurance reviews
  • Factory, site and integrated site acceptance testing (FAT / SAT / ISAT)
  • Commissioning support
  • Handover and acceptance evidence
Discuss project support
05Compliance and audit preparationReadiness, gap reviews and evidence preparation

Identify gaps, organise the supporting evidence and prepare your team for an assessment or audit. Certification decisions remain with the relevant assessment bodies.

  • Cyber Essentials Plus preparation
  • NIS2 readiness assessment
  • IEC 62443 certification preparation
Discuss audit preparation

DEPLOYMENT & INTEGRATION

Start with a defined scope.
Leave with a usable baseline.

One-time engagements connect your plant’s architecture, team and evidence requirements to the platform. Platform deployment is currently being prepared through controlled pilots.

01 / DEPLOY

Platform deployment

  • On-site installation
  • SPAN / TAP configuration
  • Network integration
  • Initial baseline setup
  • First 30 days of monitoring, within the agreed scope
Pilot-stage platform engagement
02 / ONBOARD

Compliance onboarding

  • Map observed assets into the platform
  • Configure CE+, NIS2 and IEC 62443 evidence mappings
  • Train the customer team on the Simple View
  • Establish an evidence baseline
Pilot-stage platform engagement
03 / REVIEW

OT architecture assessment

  • Review available passive discovery evidence
  • Deliver a Purdue-aligned architecture review
  • Identify segmentation gaps
  • Recommend zones and conduits
Consulting engagement
04 / PREPARE

Incident response retainer

  • Named OT incident responder
  • Agreed escalation path for critical detections
  • Annual tabletop exercise
  • Post-incident forensic support
Coverage and response terms agreed individually

ONGOING SERVICES & SOFTWARE

Keep the assessment useful.
Keep the evidence current.

Combine consultancy with an annual platform licence, managed monitoring or continuing evidence support. The platform subscription offering is being developed alongside early pilots.

ANNUAL PLATFORM LICENCE

OTCogniShield subscription

Local visibility and an evidence workspace for your team.

  • Passive OT monitoring
  • Register-change tracking
  • Compliance evidence generation
  • Incident response workspace
  • Simple / Analyst views
MONTHLY RETAINER

Managed platform service

Practitioner support to operate the platform and review the findings.

  • Platform operation and maintenance
  • Monitoring of agreed OT visibility
  • Detection review and response support
  • Monthly compliance evidence reports
MONTHLY EVIDENCE SERVICE

Compliance-as-a-Service

Maintain a reviewable record as your environment changes.

  • Ongoing compliance evidence preparation
  • Monthly Cyber Essentials Plus readiness reports
  • NIS2 evidence preparation
  • IEC 62443-3-2 risk assessment maintenance

For offline environments, monitoring, reporting and escalation arrangements are designed around agreed local access and controlled evidence transfer.

Explore the full service catalogue 15 services
OTCogniShield consulting, deployment and ongoing service catalogue
ServiceEngagementCommercial basis
IEC 62443-3-2 risk assessmentConsultingDay rate
OT network architecture designConsultingDay rate
Zone and conduit designConsultingDay rate
NIS2 readiness assessmentConsultingDay rate
Cyber Essentials Plus preparationConsultingDay rate
IEC 62443 certification preparationConsultingDay rate
Supplier assurance reviewsConsultingDay rate
FAT / SAT / ISAT supportConsultingDay rate
OTCogniShield deploymentOne-time, pilot-stage platform engagementProject fee
OTCogniShield subscriptionPlanned recurring platform licenceAnnual licence
Managed monitoring serviceRecurring, subject to agreed platform scopeMonthly retainer
Compliance evidence serviceRecurringMonthly retainer
Incident response retainerRecurringAnnual retainer
Annual architecture reviewRecurringAnnual retainer
Executive reportingRecurringQuarterly retainer

Fees, deliverables, coverage and service terms are agreed after scoping. Platform-dependent services follow pilot readiness and the agreed release scope.

CONSULTING + PLATFORM

OT Security in a Box.

An assessment. A roadmap.
A route to continuous monitoring.

Combine practitioner-led consulting with OTCogniShield in one scoped engagement. Begin with the plant’s risks and architecture, then agree how ongoing monitoring and evidence can support the team.

Scope a combined engagement

A practical set of deliverables

  1. Observed asset inventoryScope and coverage validated with your team.
  2. IEC 62443-3-2 aligned risk assessmentThreats, consequences, responsibilities and actions.
  3. Architecture and segmentation reviewZones, conduits and a prioritised roadmap.
  4. Compliance readiness reportEvidence and gaps against the agreed requirements.
  5. Platform pilot and monitoring planAuthorised collection, handover and ongoing support.

Assessment fees, annual platform licensing and managed service support are scoped separately. Deployment timing and operational safeguards are agreed before work starts.

WHO WE WORK WITH

Industrial security for smaller teams.

Manufacturers with 20–250 employees, including UK and West Midlands factories with small IT teams. Our approach combines specialist support, passive visibility and offline operation, with engagements scoped around your site’s priorities and resources.

ONE CONNECTED PICTURE

Understand your environment.
Prioritise what matters.

Bring engineering, security, and management together around observed assets, operational risk, and clear next steps.

Where the platform fits: OT, IoT & IIoT architecture · See the topology view →

OTCogniShield PLATFORM TOURIllustrative view · sample data

COMMAND CENTRE

Your priorities, in one place.

Example manufacturing cell
Observed assets24In this example environment
Risks to review06Assigned for assessment
Priority actions03Ready for owner review
Evidence statusIn reviewApproval remains with your team

EXAMPLE PRIORITIES

HIGH
Engineering workstation exposure

Review access to the production control zone.

01
MEDIUM
Controller firmware evidence

Confirm the installed version before planning updates.

02
MEDIUM
Unapproved communication path

Ask the asset owner to validate the observed flow.

03

OPERATIONAL CONTEXT

Security decisions need
production context.

Review asset importance, consequences and ownership before deciding what to change.

ControlSupervisionOperations
Illustrative platform tour. Relationship totals from the supplied stored-evidence screenshot.

THE BUSINESS COST OF DISRUPTION

When production stops,
the costs keep moving.

A cyber incident can interrupt output, delay deliveries and put recovery pressure on your team. Bring those operational consequences into your risk assessment.

Discuss your factory’s risk priorities

MANUFACTURING & PRODUCTION · 2025 STUDY

US$1.3 million

Mean ransomware recovery cost,
excluding ransom payments.

Sophos surveyed 332 manufacturing and production organisations affected by ransomware. Respondents represented organisations with 100–5,000 employees across multiple countries.

An organisation-level benchmark, not a forecast for an individual factory or a UK small-business average.

Source: Sophos manufacturing report (2025)

WHY OTCOGNISHIELD

Industrial experience.
Protection within reach.

Founded by an ICS/OT cybersecurity practitioner with experience defending industrial environments against cyber adversaries across oil and gas, rail, manufacturing and the chemical industry.

Small and medium-sized businesses are part of the same threat landscape. They deserve strong protection for their operations, even when budgets and specialist resources are limited.

Our aim is to make enterprise-level OT security expertise accessible and affordable for smaller manufacturers, with practical advice, clear priorities and a scope that fits the plant.

Discuss your plant’s needs

BUILT AROUND YOUR OPERATIONS

Experience that understands the factory floor

  • Practitioner-led supportIndustrial cybersecurity experience across demanding sectors.
  • Production-aware assessmentPassive visibility and an agreed scope, shaped around your operational constraints.
  • Clear priorities for smaller teamsUnderstand what matters, what to address next and what evidence to keep.
  • Proportionate engagementScope and deliverables agreed around your needs and available resources.
Meet the founder and view qualifications

PRACTICAL SECURITY FOR SMALLER PLANTS

Built around your operations.
Designed for your team.

Give your team the context to understand your OT environment and focus on the risks that matter to production.

01

Discover with care.

Use authorised PCAP data or a planned passive capture arrangement. Agree the visibility scope with engineering before collection begins.

PASSIVE DISCOVERY
02

Put risk in context.

Combine asset information and threat scenarios with the consequences that matter to your operation. Prioritise actions your team can review.

OPERATIONAL PRIORITIES
03

Keep control locally.

Designed for offline and air-gapped production environments, with controlled update packages and a local evidence workflow.

OFFLINE OPERATION

No permanent internet connection required.

Build visibility and evidence around your plant’s connectivity rules. Agree collection, updates and recovery as part of the pilot.

Discuss your environment

DECISIONS YOU CAN EXPLAIN

Operational evidence.
Confidence in every review.

Connect technical observations, risk decisions, and supporting evidence in a clear record for engineering, management, and audit review.

Explore reporting
01

Engineering & operations

Understand observed assets, communication and recommended actions in the context of production.

02

Management & ownership

Bring risk priorities, responsibility and next steps into a conversation your decision-makers can follow.

03

Compliance & audit review

Organise assessment records and control evidence for review against your applicable requirements.

Risk workflow informed by IEC 62443-3-2.Compliance tools support evidence preparation. Applicability, compliance decisions and certification require the appropriate review.

EARLY PILOT PROGRAMME

Real factory insight.
A focused pilot partnership.

Up to three SMB manufacturing sites in the West Midlands and across the UK. A no-cost, scoped IEC 62443-3-2 aligned assessment, passive deployment and direct founder support.

Applications open · Deployment subject to readiness and agreed scope

Apply for the pilot

BEFORE WE TALK

Your questions, answered.

Can we engage you for consulting now?

Yes. Consulting services include IEC 62443 assessments, OT architecture design, project delivery and audit preparation. The platform remains in pre-launch validation, with controlled factory pilots and subscription services being prepared separately.

Can we combine consulting and the platform?

Yes. A combined engagement can include an observed asset inventory, an IEC 62443-3-2 aligned risk assessment, architecture review, readiness report and a scoped platform pilot. Deliverables, fees, access arrangements and readiness are agreed before deployment.

Does the platform need an internet connection?

Production operation is designed to work offline, including air-gapped environments. Update delivery and verification should follow an agreed controlled process.

Will a pilot actively scan our control network?

The discovery approach is based on passive visibility and authorised capture data. Collection arrangements and any separately authorised diagnostic activity are agreed before the pilot. The pilot includes review of operational impact.

Does it make our factory compliant?

No tool can establish compliance on its own. OTCogniShield helps organise risk assessment and supporting evidence. Your organisation still needs to determine applicable obligations, review controls and obtain specialist advice or certification where required.

What would you need from our factory?

An engineering or operations contact, an agreed scope, and an authorised way to provide relevant capture data. We will agree success criteria, access boundaries and data handling before testing begins.

LET’S TALK ABOUT YOUR FACTORY

Move your OT security
forward with confidence.

Tell us about your consulting project, architecture challenges, evidence needs, or interest in a factory pilot.

info@otcognishield.com

Consulting engagements, deployment planning and ongoing services.

This opens a draft in your email app. Nothing is submitted or stored on this website.

WEBSITE PRIVACY

A simple enquiry path.

Website operator and data controller: OTCogniShield Ltd, company number 17476467. Contact info@otcognishield.com about your personal information or this website.

Website AI assistant: topic buttons show prewritten public information without an AI request. If AI is configured and you accept the processing notice, your free-text question is sent through our hosting server to OpenAI to generate a reply. Each question is handled separately; previous questions and replies are not included. This website does not save chat text in an application database or server session, and it does not accept uploads. The current question and answer remain visible in your browser until cleared or the page is closed. Limited session identifiers and request counters protect the service against abuse.

OpenAI API data is not used for model training by default. Responses are requested with storage disabled; OpenAI may still retain abuse monitoring data, normally for up to 30 days, with exceptions under its policies. Processing may occur outside the UK. Read OpenAI data controls. Our host may process technical request information. You can use the topic buttons or contact the team instead of AI. For privacy questions or rights requests, email info@otcognishield.com. AI answers can be incorrect and cannot establish site security, certification or compliance. This internet-connected website assistant is separate from the offline industrial platform.

This website does not use an enquiry database, analytics scripts or advertising trackers. When direct email is enabled, your form details are sent through our mail provider to info@otcognishield.com so we can respond. Otherwise the form prepares a draft for your email app. There is no website enquiry database. Limited session and request information is used to protect the forms against abuse.

Direct form messages are processed by our hosting provider and 123 Reg Professional Email powered by Titan. Email drafts sent from your email app also pass through your chosen provider. Avoid including passwords, confidential captures or sensitive plant information in an initial enquiry.

Hosting and access services may process technical request information. Contact OTCogniShield with questions about handling your enquiry or agreeing pilot data requirements.