OTRISK
Asset owners Integrators & service providers Product suppliers Consultancies & auditors
Solutions · Asset owners

You own the risk, even where suppliers run the systems.

You lead OT security or compliance at plants, networks or installations. The law made your management liable, a customer wrote IEC 62443 into the contract, and the current proof is a spreadsheet. Set targets, collect evidence, prove it: that's the whole job, and it needs a system.

The situation, named

Dates you didn't choose.
Cbw enforcement, a customer audit, a certification window. The calendar is set by others; the readiness has to be yours.
Two worlds, no bridge.
The IT GRC tool doesn't know what a PLC is. The OT monitoring platform doesn't know what evidence is. You own the gap between them.
Audit dread.
Not fear of failing: fear of not being able to show. The work happened; the proof is scattered across mailboxes and shared drives.

The parts that apply to you

IEC 62443-3-2The risk assessment. The demonstrable, per-installation risk analysis nearly every regime starts with, and the piece the zorgplicht asks for first.
IEC 62443-3-3System requirements. What "appropriate measures" concretely means for the installed system, trimmed to the security-level target your risk set.
IEC 62443-2-1Your security program. Policies, roles, incident handling, supplier management: the organisational half the board approves.
IEC 62443-2-4Your service providers. The yardstick you hold integrators and maintainers to: your NIS2 supply-chain duty, made assessable.

What you run in OTRISK

1

The risk assessment workspace. Seven gated steps from scoping to sign-off, on your own matrix, generating the IRA and CRS your management and auditor accept. See the workflow →

2

Requirement assessments. 3-3, 2-1, ISO 27001, NIST SP 800-82: every requirement owned, deadlined and independently reviewed. Nobody accepts their own work.

3

Suppliers in your environment. Integrators evidence 2-4 where you can see it, with two-stage review keeping their verdicts and yours separate. The questionnaire pile becomes a standing assessment.

4

Reports on demand. Change a score Tuesday; the board pack is current Wednesday. Re-assessment is a review pass, not a rebuild.

Launching customer: a Dutch grid operator. The risk-matrix approach developed with them ships as a template. No sensors, no hardware: your first assessment starts from a network drawing and a workshop.

Bring one installation in mind. Leave with concrete next steps and pricing.

Thirty minutes with an OT security expert. No slideware, no salespeople. We show you which parts of OTRISK fit your situation and how the way of working looks.