OTRISK
Asset owners Integrators & service providers Product suppliers Consultancies & auditors
Solutions · Consultancies & auditors

Deliver assessments your clients keep.

You deliver OT security engagements for asset owners. OTRISK gives you a delivery workspace inside the client's tenant, with your own roles and your own team. When the engagement ends, the client keeps the assessment, the evidence and the process log. No handover project, no lock-in.

The work lives in the client's tenant

Consultancy deliverables usually leave the building as documents: a report, a spreadsheet, a PDF that starts aging the day it is handed over. In OTRISK you deliver inside the client's environment instead. Same method, same rigour, but the result is a living assessment the client can maintain after you leave.

Your own roles and team.
The client invites your organisation into their tenant. Your lead runs your own people and assigns the work; role-based access keeps everyone scoped to the engagement, and custom roles are supported.
One shared truth.
Your consultants and the client's engineers work on the same requirements and the same evidence, with verdicts kept separate. No email attachments, no version confusion, one permanent process log.
Nothing to migrate at the end.
Assessments, evidence and the process log live in the client's environment from day one. When the engagement ends, the client keeps all of it. That is the design, not a concession.

This matches how we run our own services: onboarding and enablement until the team is self-sufficient, and no delivery practice of our own to protect. Sector depth and delivery capacity come from partners; the platform stays the system of record. Our services stance →

SP.03 · Backup & restore evidence
Awaiting client verdict
IEC 62443-2-4 · third party: Vermeer OT Advies · tenant: Pumping station Zuid
2026-07-22 09:14 · e.visser (consultant) · submitted · "restore test report, line B"
2026-07-22 16:40 · s.jansen (consultancy lead) · stage 1 accepted
2026-07-23 08:05 · entered client Review Queue
stage 2 · final verdict · m.dekker (client lead) · pending
two-stage review · nobody accepts their own submission

Two-stage review: your verdicts, then theirs

In third-party mode, on IEC 62443-3-3, 2-4, 4-1, 4-2 and NIST SP 800-82, your organisation answers inside the client's tenant. Your lead reviews your team's work first, inside your own organisation. Only then does it reach the client's queue, where their lead or auditor gives the final verdict. Nobody ever accepts their own submission, and every verdict carries a name, a timestamp and a comment, permanently.

The IEC 62443-3-2 risk assessment stays the client's own. There is no third-party flow on 3-2, by design. Your consultants work in it as part of the client's team: every ZCR step is submitted by one person and accepted by another, and the asset owner signs the approval. You steer the method; the client owns the decisions.

How assessments & evidence work →

For auditors and certification bodies

An audit does not need another export. With the client's agreement, you review where the work lives.

Read access instead of an export

The auditor role gives review rights on the assessment itself: every requirement linked to its evidence and its verdict, the process log open for inspection. Reports still generate on demand as PDF when a file must leave the system.

Formal audit records

Audits exist as records in the tenant, attached to the assessments they cover. Requirement, evidence and verdict stay linked for years, so a finding is traceable long after the engagement that produced it.

Certification bodies

An IECEE NCB can be attached to an assessment, so the certification body reviews in the same system the team works in. OTRISK supports that process; the certification decision stays where it belongs, with the body.

Before the client's security review asks. OTRISK runs as a dedicated application instance and database per client, EU-hosted, with MFA and role-based access, and evidence downloads are policy-checked. Send the reviewer to the Security & architecture page.

How partnering with OTRISK works

We build and run the platform, and our own services stop at onboarding and enablement. We do not sell delivery capacity or sector expertise; that is partner territory, deliberately. If you deliver OT security engagements, OTRISK is built to be your delivery workspace, not your competitor.

Book a demo and mention you come as a consultancy; the first call is then about partnering, not procurement.

1

Start with a working session. Thirty minutes with an OT security expert. We walk the delivery flow in a demo tenant against the engagements you actually sell: a 2-4 supplier audit, a 3-3 system assessment, a 3-2 risk assessment with the client's team.

2

Deliver a first engagement through the platform. The client runs OTRISK; you deliver inside it with your own roles and your two-stage review. We stay close for product questions while your team finds its routine.

3

Formalise the partnership. Commercial terms are agreed together in that first conversation.

Deliver through the platform. Keep the client relationship.

Thirty minutes with an OT security expert, no slideware. Bring one client engagement in mind. We show you which parts of OTRISK fit the work you deliver and how the way of working looks inside a client tenant. You leave with concrete next steps and pricing.