Report an Incident Become a Partner Careers Contact
Book a Demo
OT · IoT · Building systems

Security monitoring for the systems
you cannot take offline.

OT, IoT and building systems, watched around the clock by the same SOC that runs our IT customers. Built for environments where availability comes first and equipment cannot be patched on your schedule.

Operational estateMonitored
PLANTIndustrial control systemsavailability first
IOTConnected device estatesat scale
BMSBuilding management & accessfacilities-owned
CONVIT/OT convergence pointsthe crossing
SOCSame 24/7 SOC as ITone queue

What is an OT SOC?

An OT SOC is a security operations centre that monitors operational technology — the control systems, sensors and devices that run physical processes — rather than only the corporate IT estate. It watches passively so it cannot disturb a running process, detects against industrial protocols rather than generic IT signatures, and is measured on availability and safety first.

Where we start

A false positive that stops a line
is worse than most alerts.

That sentence is the whole difference between IT security and OT security, and most vendors will not say it out loud.

You are measured on uptime, safety and output. Not on breach counts. A control system that halts because a security tool did something unexpected is a real cost today, on your shift, with your name on it. A breach is a risk you carry but cannot see.

So the question is not how much security we can add. It is how much visibility you can gain without changing the risk profile of a plant, a building or a production line that is already running.

Everything below follows from that. If a control has a plausible route to causing an outage, it does not go near your environment until you have agreed it.

How it works

Four steps, and none of them
touch your equipment.

Nothing is installed on a controller, nothing is scanned, and nothing changes on the process network.

  1. 01

    Deploy the sensor

    A passive sensor connects to a network tap or SPAN port and observes a copy of the traffic. No agent on any controller, no packets injected, and no configuration changed on anything that is already running.

  2. 02

    Build the real inventory

    The sensor identifies devices, protocols and communication patterns to produce an asset inventory that reflects the network as it is, rather than the spreadsheet. In most estates those two parted company years ago.

  3. 03

    Correlate against IT

    OT telemetry joins the IT signal in the same pipeline, so lateral movement from the corporate network into the plant reads as one chain of events instead of two unrelated alerts in two consoles.

  4. 04

    Analyst response

    Investigations run through the same agent roster and the same completeness gate as everything else, and a senior analyst signs the verdict before it reaches you. One escalation path, one set of named contacts.

Why OT is different

The six questions you will ask
before you let anyone near it.

Answered with the mechanism rather than the reassurance, because a promise that monitoring is "safe" is not something you can take to a plant manager.

No agents on your controllers

Monitoring is passive and agentless. We watch a copy of the traffic from the side. Your SCADA and control systems keep running exactly as designed, with no change to process timing and no new software on anything that matters.

Industrial protocols, natively

Detection is tuned to the protocols that actually run on a plant network — BACnet, Modbus, DNP3 and EtherNet/IP — so normal control traffic is recognised as normal. Generic IT signatures applied to operational traffic read the same packets as an anomaly and bury you in noise.

Segmentation-aware

Deployment respects the Purdue Model rather than working around it. Sensors sit where the architecture says they should, and the segmentation you built stays intact instead of being quietly bridged to make a security tool work.

The platform you already have

We monitor Armis, Claroty, Forescout, Microsoft Defender for IoT and Nozomi Networks, and we treat them as equals: the expertise that makes monitoring useful sits with our analysts rather than with any one platform. If you already have a sensor, we work with it. If you do not, the assessment comes first and the platform decision second.

One SOC, not a second console

Most OT products hand you another dashboard and another queue. OT alerts land in the same 24/7 SOC as your IT alerts, worked by the same analysts against the same pipeline, so nothing falls between the two.

Compliance you can evidence

IEC 62443 for industrial control systems, NIS2 for operators in scope, and the UK Cyber Assessment Framework for critical national infrastructure. The reporting is built to produce what an assessor asks for.

Three estates, three problems

Not one thing called
operational technology.

A plant, a device estate and a building share the same underlying problem — equipment never designed to be monitored, on a network that grew around it — but almost nothing else.

Industrial OT

Manufacturing, energy, utilities, transport.

Control systems and plant networks where equipment predates the threat model, cannot take an agent, and in some cases cannot be rebooted without a planning process. The work is understanding what is on the network and what normal looks like, before anything else.

  • IEC 62443
  • NIS2
  • UK CAF

IoT estates

Connected devices across sites, at scale.

Devices deployed in volume, often by a team that is not IT, frequently without a patch route and rarely in an asset register. The first job is an inventory that reflects reality rather than the one on the spreadsheet.

  • NIS2
  • ISO 27001

Smart buildings & BMS

Property, facilities and building management.

Building management, access control, HVAC and lifts, usually procured through facilities rather than IT, often reachable from a network nobody has audited. A distinct buyer with a distinct risk: the building is the operation.

  • NIS2
  • Cyber Essentials Plus
Not a separate dashboard

OT alerts land in the same SOC
as everything else.

Most OT security products hand you another console and another queue. That is a monitoring tool, not a service.

  • The same 24/7 manned SOC works OT signals and IT signals, so an attack that crosses from the corporate network into the plant is one investigation, not two.
  • The same agent roster, the same nine-stage pipeline, and the same completeness gate that audits an investigation for evidence gaps before it closes.
  • Senior analyst sign-off before anything reaches you, which matters more here than anywhere: the cost of acting on a wrong verdict is measured in downtime.
  • One escalation path, one set of named contacts, one report.
Live deployment

What an OT rollout
actually looks like.

Rather than a case study written three years after the fact, here is an engagement we are in the middle of right now.

In deployment

Industrial manufacturer, multi-site

A large industrial manufacturer running production across multiple sites, with an IT security programme that stopped at the office boundary. The plant networks sat outside it: no monitoring, no asset inventory, and no way to tell whether anything on them had changed.

We are deploying passive monitoring across those sites now, feeding the same 24/7 SOC that already works their IT estate, so an attack that crosses from the corporate network into production is one investigation rather than two.

Service levels, measured across our SOC

3m 30sAverage L1 verdict
7m 50sAverage L2 verdict
24/7Manned, one queue for IT and OT

Microsoft Solutions Partner for Security

All four security specialisms, and Microsoft Sentinel as the correlation engine underneath whichever OT platform you run.

Running Microsoft Sentinel since 2019

Seven years of production SIEM engineering behind the detection content, not a recent pivot into the category.

IEC 62443 and NIS2 mapped

Reporting is built to produce the evidence an assessor asks for, rather than a report you then have to translate.

Senior analyst sign-off as standard

Nothing reaches you on an automated verdict alone. In OT the cost of acting on a wrong call is measured in downtime.

Under this pillar

Where it goes
from here.

Managed OT/IoT SOC

The managed service for operational technology: continuous monitoring, investigation and escalation, run by our SOC.

See the service

Smart Building Security

Building management, access control and the systems that keep a property operating.

See the service
Questions

OT security, answered.

What is an OT SOC?

An OT SOC is a security operations centre that monitors operational technology — the control systems, sensors and devices that run physical processes — rather than only the corporate IT estate. It differs from an IT SOC in what it watches, how it watches it and what it optimises for: monitoring is passive and agentless so it cannot disturb a running process, detection is tuned to industrial protocols instead of generic IT signatures, and the analysts working it are measured on protecting availability and safety rather than confidentiality.

How is OT security different from IT security?

The risk model is inverted. In IT, the worst outcome is usually data loss. In OT, the worst outcome is a process stopping or behaving unsafely, so a security control that causes an outage has itself become the incident. Tooling, change windows and escalation all have to account for that, and a control that is routine in IT can be unacceptable in OT.

Will monitoring disrupt our control systems?

That is the first question worth asking any vendor, and the answer should be specific to your environment rather than general. We scope it with you before anything is deployed, and no control goes near your environment until you have agreed what it does and what it touches.

Which frameworks does this map to?

IEC 62443 for industrial control systems, NIS2 for operators in scope across the EU, and the UK Cyber Assessment Framework for critical national infrastructure. Buyers in this space tend to search around the compliance obligation before they search around the threat, so the framework is usually where the conversation starts.

Do you cover IoT and building systems as well as industrial OT?

Yes. Industrial OT, IoT estates and smart building systems are three different buyers with three different vocabularies, but they share the same underlying problem: equipment that was never designed to be monitored, connected to a network that has grown around it.

Where does an engagement start?

With a visibility assessment rather than a platform purchase. You cannot protect what you have not identified, and in most estates the asset register and reality have drifted apart. The assessment establishes what is actually there and what normal looks like before anything else is proposed.

Where to start

Start with what is
actually on the network.

You cannot protect what you have not identified, and in most estates the asset register and reality parted company years ago. The assessment establishes what is there before anything is proposed.

A Wizard Cyber security analyst