You lead OT security or compliance at plants, networks or installations. The law made your management liable, a customer wrote IEC 62443 into the contract, and the current proof is a spreadsheet. Set targets, collect evidence, prove it: that's the whole job, and it needs a system.
The risk assessment workspace. Seven gated steps from scoping to sign-off, on your own matrix, generating the IRA and CRS your management and auditor accept. See the workflow →
Requirement assessments. 3-3, 2-1, ISO 27001, NIST SP 800-82: every requirement owned, deadlined and independently reviewed. Nobody accepts their own work.
Suppliers in your environment. Integrators evidence 2-4 where you can see it, with two-stage review keeping their verdicts and yours separate. The questionnaire pile becomes a standing assessment.
Reports on demand. Change a score Tuesday; the board pack is current Wednesday. Re-assessment is a review pass, not a rebuild.
Launching customer: a Dutch grid operator. The risk-matrix approach developed with them ships as a template. No sensors, no hardware: your first assessment starts from a network drawing and a workshop.
Thirty minutes with an OT security expert. No slideware, no salespeople. We show you which parts of OTRISK fit your situation and how the way of working looks.