Skip to main content
NexITC
B12 · CYBERSECURITY · 6–10 WEEKS · BUILD

Edge and device security.
Without breaking operations.

B12 · OT/IoT Security Hardening Build™ hardens OT and IoT environments — device inventory, segmentation, access governance, logging, and edge incident playbooks — without breaking operations. The controls we recommend against are as important as the controls we implement. Safety interlocks stay untouched.

DURATION
6–10 wks
DELIVERABLES
4 named
COMMERCIAL
Fixed fee
B12·PROJECTION / KNOWN DEVICE COVERAGE
B12
BEFORE
30%
DEVICES · PARTIAL INVENTORY
B12
AFTER
95%
DEVICES · ATTRIBUTED INVENTORY
WK 00
WK 03
WK 06
WK 09
STEADY
DEVICE COVERAGE
95%
CRITICAL EXPOSURE ↓
70%
OPERATIONAL DISRUPTION
0
SCENARIO · UAE UTILITY · N=1
ILLUSTRATIVE
§ 00 · THESIS
01
WHY OT HARDENING
IS DIFFERENT.

In IT, a control that causes an outage is an incident. In OT, a control that causes an outage can be a safety event. That asymmetry is why most OT security programmes stall: the security team proposes a segmentation design drawn from an IT playbook, the plant engineer refuses it because it would interrupt a control loop, and the conversation ends with a spreadsheet of unimplemented recommendations and an estate nobody has inventoried.

The instinct is to apply the IT hardening standard harder. The instinct is wrong and it costs credibility on the plant floor. What works is discovery that is passive by default, segmentation designed with the plant engineer against control-loop and safety-interlock preservation, compensating controls for devices that cannot be patched safely, and an explicit record of the controls we recommend against and why. B12 does that work on a fixed scope in 6–10 weeks. Safety interlocks stay untouched.

STATE · UNKNOWN
Devices partially inventoried. IT and OT converged on a flat network. No OT logging. No edge playbooks.
STATE · GOVERNED
Devices attributed to owners. Segmentation change-windowed and tested. Logging at boundaries. Playbooks rehearsed on site.
§ 01 · WORK STREAMS

Six streams,
ending in hardened continuity.

Discovery and risk assessment front-load weeks 1–3. Segmentation design, logging, and playbooks overlap through weeks 3–9. Validation and on-site handover close weeks 9–10.

STREAM 01
WK 01–02

Device discovery

Passive discovery preferred, active only where the plant engineer confirms it is safe. Complete device inventory with owner attribution.

STREAM 02
WK 02–03

Risk assessment

Per-device criticality, patch status, exposure, and compensating-control candidates for devices that cannot be patched safely.

OUTCOME
95
KNOWN DEVICE COVERAGE
+ ZERO OPERATIONAL DISRUPTION
STREAM 03
WK 03–06

Segmentation design

Designed with the plant engineer and tested against control-loop and safety-interlock preservation. Designs that would trip an interlock are recommended against, in writing.

STREAM 04
WK 05–08

Logging

Collection from OT devices where the protocol supports it, from segmentation boundaries where it does not.

STREAM 05
WK 07–09

Edge incident playbooks

Playbooks for the specific incident classes your estate actually faces, tested with the on-site team rather than written for them.

STREAM 06
WK 09–10

Validation & handover

Device coverage verified, segmentation change-window validated, on-site team trained. 30/60/90-day check-ins scheduled.

EXPLICITLY NOT COVERED
Firmware patching without vendor sign-off
we will not patch an OT device outside the vendor's supported path. Compensating controls instead, documented as such.
Continuous OT security operations
run by your industrial partner's SOC or by C7 SecOpsCommand™ with OT-competent operators.
§ 02 · TIMELINE

Ten weeks maximum.
Six minimum. Four phases.

Phase count is fixed. Duration flexes with estate size, site count, and the change windows the plant can actually offer. Milestones are signed gates — not aspirations.

WK 010203040506070809 · 10Phase 1 · Discovery & riskPhase 2 · Segmentation designPhase 3 · Logging & playbooksPhase 4 · Validation & handoverInventory & risk signedEND WK 03 · GATE 01Segmentation design acceptedEND WK 06 · GATE 02Logging & playbooksEND WK 09 · GATE 03Handover completeEND WK 10 · GATE 04OPERATING RHYTHMDaily standup · Weekly plant-engineer check-in · Bi-weekly Practice Lead reviewNAMED ACCOUNTABILITYPractice Lead — Cybersecurity (CEO escalationavailable)
§ 03 · APPROACH

Controls scored,
not on IT-first assumptions.

Every engagement runs a six-criteria scorecard in weeks 1–2. Each candidate platform scored 1–5 against your estate and its safety context. Signed by the CISO and the plant engineer before Phase 2 begins.

OT SECURITY PLATFORM SCORECARD · TEMPLATE
CRITERIA · 06 · WEIGHTED 1–5
ILLUSTRATIVE SAMPLE RENDERING — actual scores are engagement-specific and derived from evidence gathered during discovery.
01
OT-vendor safety compatibility
Whether segmentation and monitoring will disrupt process control. A platform that voids a vendor's support position is not a candidate.
5/5
02
Passive-discovery capability
Active scans risk destabilising some OT devices. Passive discovery depth decides how much of the estate can be inventoried safely.
5/5
03
Bidirectional IT-side integration
Integration with the SIEM and logging estate you already run. Single pane, not two consoles nobody watches.
4/5
04
Legacy protocol support
Modbus, DNP3, and industrial Ethernet variants present in your plant. Unsupported protocols become blind spots.
4/5
05
On-site engineer partnership model
Whether the vendor delivers with the plant engineer or to them. The second model produces designs that never get implemented.
4/5
06
Three-year TCO
Total cost including sensor replacement and expansion cycles, not the first-year licence.
3/5
!
DISCLOSURE · VENDOR-NEUTRALITY
NexITC maintains commercial arrangements with several OT security platforms and network monitoring vendors — these are how specialist consultancies build sustainable practices. We do not disclose which arrangements exist publicly because we do not want them to influence tool choice by anyone reading this page. The scorecard exists precisely so selection happens on evidence, not on economics. In practice, we have recommended tools with which we have no partnership when the scorecard result favoured them.
§ 04 · ARCHITECTURE

From unknown estate
to governed edge.

A typical pre-engagement state has a partially inventoried OT estate on a flat converged network, no logging on OT segments, and no edge incident playbooks. The engagement adds a security overlay without touching the process it protects.

BEFORE · T=0
TYPICAL STATE
ESTATE_01
OT devices partially inventoried
OWNER UNKNOWN
ESTATE_02
Flat network, IT and OT converged
NO BOUNDARY
ESTATE_03
No logging on OT segments
BLIND
ESTATE_04
No edge incident playbooks
IMPROVISED
LEGACY · DEVICES
Unpatchable devices with no compensating controls
OPERATIONAL REALITY
  • Nobody can name every device on the plant network
  • One compromised IT endpoint reaches process control
  • Incidents on OT segments are invisible until they surface physically
  • IT-drafted segmentation designs sit unimplemented
B12 · HARDEN
AFTER · STEADY STATE
TARGET-STATE
PLATFORM_01
OT Security Overlay
Discovery · Segmentation · Logging · Monitoring
PLATFORM_02
Operational Continuity
Safety Interlocks Untouched · Control Loops Preserved · Change-Windowed
↓ DISCOVERED · SEGMENTED · LOGGED · CONTINUITY PRESERVED ↓
PROCESS CONTROL · RETAINED
Untouched · security added around it, never through it
STEADY-STATE OUTCOME
  • Every known device attributed to a named owner
  • Segmentation implemented inside agreed change windows
  • Compensating controls documented for unpatchable devices
  • Recommended-against designs recorded with the reason

Reference pattern. Some engagements keep a coarser segmentation model than an IT estate would accept, because the finer design would interrupt a control loop. That trade-off is documented, not quietly dropped.

§ 05 · REPRESENTATIVE SCENARIO

A UAE utility,
edge hardened.

Representative pattern for a UAE utility of this scale — no OT inventory, flat segmentation, unpatchable legacy devices in service. Ranges reflect target outcomes NexITC underwrites in scope for this class of engagement. N=1 — illustrative composite, not a specific client.

SCENARIO / B12 / UAE UTILITY · MULTI-SITE OT ESTATE
DURATION · 09 WKS
DEVICE VISIBILITY
95%
Known devices with owner attribution
CRITICAL EXPOSURE REDUCTION
−70%
Exposure on crown-jewel process assets
OPERATIONAL DISRUPTION
zero
No control-loop or interlock events
SITUATION

UAE utility operating a multi-site OT estate. No maintained device inventory, IT and OT converged on a flat network, no logging on OT segments, and several legacy devices in service that the vendor will not support patching on. A previous IT-drafted segmentation design had been refused by plant engineering.

ENGAGEMENT

9-week B12. Weeks 1–3 passive discovery and per-device risk assessment. Weeks 3–6 segmentation designed with the plant engineer and tested against control-loop and safety-interlock preservation. Weeks 5–9 boundary logging, edge incident playbooks tested with the on-site team, and validation inside agreed change windows.

OUTCOME

Known device coverage at 95% with owner attribution. Critical exposure down 70% through segmentation and compensating controls on the unpatchable devices. Zero operational disruption across the engagement. Two proposed segmentation designs recommended against and recorded with the interlock reasoning. Utility moved to C7 SecOpsCommand™ with OT-competent operators.

§ 06 · DELIVERABLES

Four artifacts,
each with signed acceptance.

Every deliverable has documented acceptance criteria signed at engagement kickoff. Nothing more, nothing less.

D_01

Device Inventory & Governance

Complete inventory with owner attribution, criticality, patch status, and the compensating controls applied where patching is unsafe.

D_02 · CORE

Segmentation Model

Designed with the plant engineer and tested against process integrity — control loops preserved, safety interlocks untouched.

D_03

Logging Improvements

Collection from OT devices where the protocol supports it and from segmentation boundaries where it does not.

D_04 · OPERATOR-READY

Edge Incident Playbooks

Playbooks for the specific incident classes your estate faces, tested with the on-site team, plus a documented list of segmentation designs we recommended {{i:against}} and why — the record that survives the audit conversation about "why isn't this segmented too."

HANDOVER
WK 10
§ 07 · OUTCOMES

Six outcome metrics,
measured pre and post.

Success is not "the estate is hardened." It is measured against six specific outcomes captured in a baseline report at engagement start and re-measured at post-handover steady state — including the one that must stay at zero.

THE DEVICE COVERAGE JOURNEY · REPRESENTATIVE
Thirty to ninety-five, across the four phases.
95%DEVICE COVERAGE
100%75%50%25%030%BaselinePRE-ENGAGEMENT65%Discovery completeEND WK 0388%Segmentation liveEND WK 0995%Steady state30 DAYS POST
01 · COVERAGE
90+%
Known device coverage with owner attribution.
02 · EXPOSURE
60–80%
Reduction in critical exposure on process-critical assets.
03 · DISRUPTION
zero
Operational disruption events caused by implemented controls.
04 · SEGMENTATION
Meas.
Segmentation coverage against the agreed IT/OT boundary model.
05 · PLAYBOOKS
Top
Edge playbook coverage across the top incident classes your estate faces.
06 · LOGGING
Meas.
Log collection completeness across devices and segmentation boundaries.
§ 08 · FIT

Honest scoping.

B12 is a fit when specific conditions are met. It is not a fit when other conditions are. We say so before the scope conversation, not after the commercial commitment.

PREREQUISITES
Move fast when these five conditions are in place at kickoff.
01
The OT/IoT estate is defined

Sites, process areas, and rough device populations known. Full inventory is our work; the perimeter of that work is yours.

02
A plant engineer available as counterpart

Segmentation is designed with them. Without that seat filled, designs get refused in week six.

03
Operational change windows agreed

Named windows for segmentation and logging changes. Windows decide the timeline more than estate size does.

04
An agreed IT/OT boundary policy

Hardware-based or process-based — either works, but the choice must be made rather than assumed.

05
An executive sponsor who can fund compensating controls

Where patching isn't possible, compensating controls cost money. That decision needs authority behind it.

NOT SUITABLE IF
Four patterns indicate a different engagement is a better fit.
Pure IT security scope

That's B9 Zero-Trust Core Build™ — identity, privileged access, segmentation, logging on the IT estate.

IoT operational integration, not security

That's B11 EdgeSense™ Build — telemetry into tickets and runbooks.

No OT/IoT estate to speak of

A different engagement entirely. We will say so in the clinic rather than scope around it.

Willing to disrupt operations for security wins

Hard no. We do not sign to that trade-off, and we will recommend against controls that buy posture with a safety risk.

§ 09 · COMMERCIAL

Fixed fee.
Milestone-based.

Total engagement fee agreed in the scope statement. Not time-and-materials. Not day rate. Every engagement is preceded by a scope conversation to ensure fit before commitment.

STANDARD MODEL
ENGAGEMENT MODEL
Fixed fee
PAYMENT CADENCE
Milestone-based

Payment schedule aligned to engagement phases and defined delivery milestones agreed upfront.


INCLUDED IN SCOPE
  • All 4 named deliverables with acceptance criteria
  • Named Practice Lead throughout the engagement
  • Bi-weekly executive sponsor reviews
  • 30/60/90-day post-handover check-ins
  • Written scope amendment process for any changes
01

Signed scope statement

Every engagement begins with a signed scope statement fixing deliverables, timeline, milestones, and commercial terms. No verbal agreements. No moving targets.

02

No scope creep

Scope changes require a signed scope amendment. If scope changes, so does the commercial arrangement — always in writing, always signed by both parties.

03

Named accountability

The Practice Lead is accountable for commercial and delivery outcomes throughout the engagement, with escalation to the CEO within 24 hours if needed.

§ 10 · QUESTIONS

Five, most asked.

Q_01Won't segmentation break OT operations?

Some proposed segmentation absolutely would. We identify which specific segmentation designs would trip a safety interlock or interrupt a control loop, and we recommend against them explicitly — in writing, with the reason recorded.

Segmentation that survives industrial context is designed with the plant engineer, not for them.

Q_02Which OT vendors do you work with?
Selection runs the scorecard. Common OT security platforms (Claroty, Nozomi, Dragos, Tenable OT), network monitoring vendors, and industrial firewalls are all in the candidate set — evidence-based selection per your estate and safety context, not per our partner list.
Q_03How do you handle unpatched legacy devices?
Compensating controls. Legacy devices that cannot be patched safely stay behind additional segmentation with more aggressive monitoring. Patching without vendor sign-off in OT is often more dangerous than not patching, and we will say so rather than close a finding for the sake of the report.
Q_04Do you cover industrial IoT specifically?
Yes, including sensor networks, control systems, and historian integration. The boundary between IT and OT gets negotiated per engagement — some estates draw it hardware-based, others process-based. Agreeing that boundary in week one prevents an argument in week six.
Q_05What comes next?
C7 SecOpsCommand™ with OT-competent operators, or your industrial partner's SOC if they operate OT security separately. Continuous operation matters more here than anywhere else — segmentation change control and compensating-control review are ongoing disciplines, not handover artefacts.
§ 11 · NAMED ACCOUNTABILITY

One name
on the engagement letter.

A named Practice Lead is accountable for delivery, commercial outcomes, and the client relationship throughout the engagement. Not a project manager who disappears after kickoff. Not a partner who nods at the SOW and vanishes.

THE ROLE

Practice Lead — Cybersecurity

Present at every phase gate, every scope decision, every difficult conversation. Available for 30/60/90-day post-handover check-ins as part of the engagement.

SIX ACCOUNTABILITIES
01
Commercial arrangement

Including scope amendments.

02
Deliverables acceptance

Signs off all 4 deliverables.

03
Bi-weekly reviews

With executive sponsor.

04
Change orders

Authorised to negotiate.

05
Escalation path

CEO within 24 hours.

06
Post-handover

30/60/90-day check-ins.

§ 13 · BOOK A CLINIC

Thirty minutes.
No slide deck.

A structured 30-minute scope conversation with the Practice Lead. You describe the estate, the sites, and the change windows the plant can offer. We describe whether B12 is the right engagement — and if not, what is.

Book a clinic →Email directly
DURATION
30 minutes
PREPARATION
None required
FOLLOW-UP
Written scope, 5 business days