You deliver OT security engagements for asset owners. OTRISK gives you a delivery workspace inside the client's tenant, with your own roles and your own team. When the engagement ends, the client keeps the assessment, the evidence and the process log. No handover project, no lock-in.
Consultancy deliverables usually leave the building as documents: a report, a spreadsheet, a PDF that starts aging the day it is handed over. In OTRISK you deliver inside the client's environment instead. Same method, same rigour, but the result is a living assessment the client can maintain after you leave.
This matches how we run our own services: onboarding and enablement until the team is self-sufficient, and no delivery practice of our own to protect. Sector depth and delivery capacity come from partners; the platform stays the system of record. Our services stance →
In third-party mode, on IEC 62443-3-3, 2-4, 4-1, 4-2 and NIST SP 800-82, your organisation answers inside the client's tenant. Your lead reviews your team's work first, inside your own organisation. Only then does it reach the client's queue, where their lead or auditor gives the final verdict. Nobody ever accepts their own submission, and every verdict carries a name, a timestamp and a comment, permanently.
The IEC 62443-3-2 risk assessment stays the client's own. There is no third-party flow on 3-2, by design. Your consultants work in it as part of the client's team: every ZCR step is submitted by one person and accepted by another, and the asset owner signs the approval. You steer the method; the client owns the decisions.
An audit does not need another export. With the client's agreement, you review where the work lives.
The auditor role gives review rights on the assessment itself: every requirement linked to its evidence and its verdict, the process log open for inspection. Reports still generate on demand as PDF when a file must leave the system.
Audits exist as records in the tenant, attached to the assessments they cover. Requirement, evidence and verdict stay linked for years, so a finding is traceable long after the engagement that produced it.
An IECEE NCB can be attached to an assessment, so the certification body reviews in the same system the team works in. OTRISK supports that process; the certification decision stays where it belongs, with the body.
We build and run the platform, and our own services stop at onboarding and enablement. We do not sell delivery capacity or sector expertise; that is partner territory, deliberately. If you deliver OT security engagements, OTRISK is built to be your delivery workspace, not your competitor.
Book a demo and mention you come as a consultancy; the first call is then about partnering, not procurement.
Start with a working session. Thirty minutes with an OT security expert. We walk the delivery flow in a demo tenant against the engagements you actually sell: a 2-4 supplier audit, a 3-3 system assessment, a 3-2 risk assessment with the client's team.
Deliver a first engagement through the platform. The client runs OTRISK; you deliver inside it with your own roles and your two-stage review. We stay close for product questions while your team finds its routine.
Formalise the partnership. Commercial terms are agreed together in that first conversation.
Thirty minutes with an OT security expert, no slideware. Bring one client engagement in mind. We show you which parts of OTRISK fit the work you deliver and how the way of working looks inside a client tenant. You leave with concrete next steps and pricing.