Platform deployment
- On-site installation
- SPAN / TAP configuration
- Network integration
- Initial baseline setup
- First 30 days of monitoring, within the agreed scope
OT · IoT · IIoT SECURITY & RISK INTELLIGENCE
Specialist OT consulting. Passive OT, IoT and IIoT visibility—turning evidence into action.
13 years of OT security experience · ISA/IEC 62443 ExpertFounder’s qualifications and experience
Assessment support: IEC 62443 · NIS2 readiness · NIST SP 800-82
Start with authorised capture data, then validate identity and scope with your plant team.
| Asset | Protocol |
|---|---|
| PLC — Line 01 | Modbus TCP |
| HMI — Packaging | EtherNet/IP |
| Engineering station | OPC UA |
| Telemetry gateway | MQTT |
Capture coverage determines what can be observed.
ILLUSTRATIVE 4 × 4 RISK MATRIX
Select likelihood and consequence to show a rating.
| Likelihood | 1 Minor | 2 Moderate | 3 Significant | 4 Major |
|---|---|---|---|---|
| 4 Likely | ||||
| 3 Possible | ||||
| 2 Unlikely | ||||
| 1 Rare |
Local assessment bands: Low 1–4 · Medium 5–8 · High 9–12 · Critical 13–16. These are illustrative bands, not an IEC-defined universal scale. Acceptance requires the responsible owner’s decision.
Industrial expertise meets passive risk intelligence. Assess your environment, strengthen the architecture, and build evidence for informed decisions. Consulting available now; platform pilots in preparation.
Standards-informed consulting and evidence workflows
Passive at the coreVisibility from authorised OT capture data.
Offline by designKeep production operation independent of the internet.
Evidence you can useBring technical findings into practical decisions.
CONSULTING SERVICES
Work with OTCogniShield on OT security, architecture and delivery. OTCogniShield adds a platform for ongoing visibility and evidence alongside the consulting engagement.
Choose a focused review or support across the project lifecycle. Scope, deliverables and fees are agreed around your environment.
Translate the relevant IEC 62443 requirements into a practical programme, with clear responsibilities, assessment evidence and a plan for implementation.
Develop an architecture that reflects the way your plant operates, including access needs, legacy constraints and the boundaries between IT and OT.
Agree the assessment scope, understand the threats and consequences, and develop recommendations that your engineering and management teams can review.
Bring OT security requirements into project decisions and supplier interfaces, with support through design assurance, testing and acceptance.
Identify gaps, organise the supporting evidence and prepare your team for an assessment or audit. Certification decisions remain with the relevant assessment bodies.
DEPLOYMENT & INTEGRATION
One-time engagements connect your plant’s architecture, team and evidence requirements to the platform. Platform deployment is currently being prepared through controlled pilots.
ONGOING SERVICES & SOFTWARE
Combine consultancy with an annual platform licence, managed monitoring or continuing evidence support. The platform subscription offering is being developed alongside early pilots.
Local visibility and an evidence workspace for your team.
Practitioner support to operate the platform and review the findings.
Maintain a reviewable record as your environment changes.
For offline environments, monitoring, reporting and escalation arrangements are designed around agreed local access and controlled evidence transfer.
| Service | Engagement | Commercial basis |
|---|---|---|
| IEC 62443-3-2 risk assessment | Consulting | Day rate |
| OT network architecture design | Consulting | Day rate |
| Zone and conduit design | Consulting | Day rate |
| NIS2 readiness assessment | Consulting | Day rate |
| Cyber Essentials Plus preparation | Consulting | Day rate |
| IEC 62443 certification preparation | Consulting | Day rate |
| Supplier assurance reviews | Consulting | Day rate |
| FAT / SAT / ISAT support | Consulting | Day rate |
| OTCogniShield deployment | One-time, pilot-stage platform engagement | Project fee |
| OTCogniShield subscription | Planned recurring platform licence | Annual licence |
| Managed monitoring service | Recurring, subject to agreed platform scope | Monthly retainer |
| Compliance evidence service | Recurring | Monthly retainer |
| Incident response retainer | Recurring | Annual retainer |
| Annual architecture review | Recurring | Annual retainer |
| Executive reporting | Recurring | Quarterly retainer |
Fees, deliverables, coverage and service terms are agreed after scoping. Platform-dependent services follow pilot readiness and the agreed release scope.
CONSULTING + PLATFORM
An assessment. A roadmap.
A route to continuous monitoring.
Combine practitioner-led consulting with OTCogniShield in one scoped engagement. Begin with the plant’s risks and architecture, then agree how ongoing monitoring and evidence can support the team.
Scope a combined engagementAssessment fees, annual platform licensing and managed service support are scoped separately. Deployment timing and operational safeguards are agreed before work starts.
WHO WE WORK WITH
Manufacturers with 20–250 employees, including UK and West Midlands factories with small IT teams. Our approach combines specialist support, passive visibility and offline operation, with engagements scoped around your site’s priorities and resources.
ONE CONNECTED PICTURE
Bring engineering, security, and management together around observed assets, operational risk, and clear next steps.
Where the platform fits: OT, IoT & IIoT architecture · See the topology view →
OTCOGNISHIELD APPLIANCE

Passive OT, IoT and IIoT visibility from authorised capture data, with offline-capable monitoring and risk intelligence.
Capture points, site coverage and deployment requirements are agreed around your network.
NETWORK & TOPOLOGY
Explore a simplified ICS / SCADA relationship map, with a highlighted review example and clear visibility limits.
Totals from the supplied platform screenshot. Missing links do not establish that an asset is offline.
See the topology view →COMMAND CENTRE
EXAMPLE PRIORITIES
Review access to the production control zone.
Confirm the installed version before planning updates.
Ask the asset owner to validate the observed flow.
OPERATIONAL CONTEXT
Review asset importance, consequences and ownership before deciding what to change.
ASSET DISCOVERY
Bring observed device details, protocols and communication into an inventory your plant team can review.
| Asset | Role | Observed protocol | Assessment scope |
|---|---|---|---|
| PLC — Line 01192.0.2.20 | Process control | Modbus TCP | In scope |
| HMI — Packaging192.0.2.30 | Operator interface | EtherNet/IP | In scope |
| Engineering station192.0.2.40 | Maintenance | OPC UA | In scope |
| Telemetry gateway192.0.2.50 | Sensor aggregation | MQTT | Review required |
Observed details depend on the capture, protocol and available traffic. Your team validates asset identity and scope.
RISK ASSESSMENT
Assess the likelihood and operational consequences, record existing measures, and give the next action a named owner.
Select likelihood and consequence to show a rating.
| Likelihood | 1 Minor | 2 Moderate | 3 Significant | 4 Major |
|---|---|---|---|---|
| 4 Likely | ||||
| 3 Possible | ||||
| 2 Unlikely | ||||
| 1 Rare |
Local assessment bands: Low 1–4 · Medium 5–8 · High 9–12 · Critical 13–16. These are illustrative bands, not an IEC-defined universal scale. Acceptance requires the responsible owner’s decision.
EVIDENCE & REPORTING
OTCogniShield / Assessment evidence
Connect technical findings to scope, consequences, recommendations and evidence. Support conversations with management, auditors and insurers.
Evidence supports review. It does not establish certification or legal compliance by itself.
THE BUSINESS COST OF DISRUPTION
A cyber incident can interrupt output, delay deliveries and put recovery pressure on your team. Bring those operational consequences into your risk assessment.
Discuss your factory’s risk prioritiesMANUFACTURING & PRODUCTION · 2025 STUDY
US$1.3 million
Sophos surveyed 332 manufacturing and production organisations affected by ransomware. Respondents represented organisations with 100–5,000 employees across multiple countries.
An organisation-level benchmark, not a forecast for an individual factory or a UK small-business average.
Source: Sophos manufacturing report (2025)WHY OTCOGNISHIELD
Founded by an ICS/OT cybersecurity practitioner with experience defending industrial environments against cyber adversaries across oil and gas, rail, manufacturing and the chemical industry.
Small and medium-sized businesses are part of the same threat landscape. They deserve strong protection for their operations, even when budgets and specialist resources are limited.
Our aim is to make enterprise-level OT security expertise accessible and affordable for smaller manufacturers, with practical advice, clear priorities and a scope that fits the plant.
Discuss your plant’s needsBUILT AROUND YOUR OPERATIONS
PRACTICAL SECURITY FOR SMALLER PLANTS
Give your team the context to understand your OT environment and focus on the risks that matter to production.
Use authorised PCAP data or a planned passive capture arrangement. Agree the visibility scope with engineering before collection begins.
Combine asset information and threat scenarios with the consequences that matter to your operation. Prioritise actions your team can review.
Designed for offline and air-gapped production environments, with controlled update packages and a local evidence workflow.
Build visibility and evidence around your plant’s connectivity rules. Agree collection, updates and recovery as part of the pilot.
DECISIONS YOU CAN EXPLAIN
Connect technical observations, risk decisions, and supporting evidence in a clear record for engineering, management, and audit review.
Explore reportingUnderstand observed assets, communication and recommended actions in the context of production.
Bring risk priorities, responsibility and next steps into a conversation your decision-makers can follow.
Organise assessment records and control evidence for review against your applicable requirements.
EARLY PILOT PROGRAMME
Up to three SMB manufacturing sites in the West Midlands and across the UK. A no-cost, scoped IEC 62443-3-2 aligned assessment, passive deployment and direct founder support.
Applications open · Deployment subject to readiness and agreed scope
BEFORE WE TALK
Yes. Consulting services include IEC 62443 assessments, OT architecture design, project delivery and audit preparation. The platform remains in pre-launch validation, with controlled factory pilots and subscription services being prepared separately.
Yes. A combined engagement can include an observed asset inventory, an IEC 62443-3-2 aligned risk assessment, architecture review, readiness report and a scoped platform pilot. Deliverables, fees, access arrangements and readiness are agreed before deployment.
Production operation is designed to work offline, including air-gapped environments. Update delivery and verification should follow an agreed controlled process.
The discovery approach is based on passive visibility and authorised capture data. Collection arrangements and any separately authorised diagnostic activity are agreed before the pilot. The pilot includes review of operational impact.
No tool can establish compliance on its own. OTCogniShield helps organise risk assessment and supporting evidence. Your organisation still needs to determine applicable obligations, review controls and obtain specialist advice or certification where required.
An engineering or operations contact, an agreed scope, and an authorised way to provide relevant capture data. We will agree success criteria, access boundaries and data handling before testing begins.
LET’S TALK ABOUT YOUR FACTORY
Tell us about your consulting project, architecture challenges, evidence needs, or interest in a factory pilot.
info@otcognishield.comConsulting engagements, deployment planning and ongoing services.