Monitoring, triage, and a person who picks up the phone.
Security and availability from the same desk, because at 3am nobody cares which one it was. On the corporate side that means identity and endpoint telemetry: a sign-in from somewhere the user has never been, a new mailbox forwarding rule, a service account logging on interactively, a privileged group that changed. On a control network it usually means alerting on change: a device that was not there yesterday, a conversation that has never happened before, a controller dropped into program mode. Detections are tuned for the estate we are actually watching.
Why it matters
The failure a buyer fears from a SOC is alert noise: a queue of generic IT signatures firing on an OT network, and a call centre that cannot tell a booked maintenance window from an attack. So we learn your maintenance calendar, and we alert on the plant becoming interesting, because the plant is supposed to be boring.
What it covers
- Identity, endpoint and network telemetry
- Endpoint, firewall, identity and cloud-tenant logs into a SIEM, with detections for credential abuse, privilege changes and lateral movement, correlated with the OT side rather than kept in a separate silo. Coverage mapped against MITRE ATT&CK.
- OT-aware detection
- New asset, new conversation, PLC mode change to program, firmware or logic download, unexpected function codes, for example a Modbus write from a host that is not the engineering workstation. Coverage mapped against MITRE ATT&CK for ICS.
- Escalation that reaches a person
- Runbooks agreed with your site, an escalation path, and a person who picks up the phone, not only a dashboard.
How it runs
Map the coverage
A detection coverage map against ATT&CK for ICS, so you can see what is watched and what is not, rather than trusting that everything is.
Learn the site
Your maintenance calendar and your normal, so a booked firmware download is not a 3am phone call and a genuinely new behaviour is.
Triage and escalate
Alerts triaged against that baseline and escalated on the runbook you agreed, with the reasoning attached.
Report
A monthly report and incident notes you can hand to an auditor or an insurer.
What you are left holding
- Detection coverage map against MITRE ATT&CK for ICS.
- Escalation runbook agreed with the site.
- Monthly report.
- Incident notes.
Worked to
- MITRE ATT&CK for ICS
- NIST CSF 2.0 (Detect, Respond)
Questions we are asked first
Will we drown in false alerts?
The detections are tuned to the estate we watch and to your maintenance calendar, so a booked change does not page anyone and a genuinely new behaviour does. Alerting on change means the quiet plant stays quiet.
Do you understand OT alerts, or just forward IT ones?
OT-aware detection is the point: mode changes, logic downloads, unexpected function codes and new conversations, mapped to ATT&CK for ICS, not a Windows signature set pointed at a PLC.
Related work
Tell us what is bothering you.
An email is enough to start with. A scoping call is free and there is nothing to commit to, and where we are not the right people we will say so and point you at someone who is.
A first call about one site. No charge, and nothing to commit to.
Our named next step: we come to one site and hand you an assessment you can act on.