ciso.diy
Critical Infrastructure Complete preview
Bundles critical infrastructureNERC CIPTSA pipelineOT security

Critical Infrastructure Complete

The plant, the regulators above it, the federal reporting duty, the drill and the board layer — five products covering an operator end to end, from the vendor VPN that should already be off to the evidence log a director keeps. 25% off buying separately.

What this actually gives you

  • Five jobs, usually five different people — the plant, the regulators above it, the federal reporting duty, the drill, and what the board asks and records while you do all of it.
  • Build once to the strictest formulation and present each regulator its own view — twenty control families mapped across NERC CIP, the TSA directives, EPA/AWIA and state rules, NIS2, IEC 62443, CSF 2.0 and the CISA CPGs.
  • Every row of the regime kit points at the plant file that produces its evidence — the two are designed as a pair, and the other three turn them into a programme rather than a binder.
  • Safety first, throughout. Where a compliance deadline and a safe operating state disagree, the safe state wins and the deviation gets documented.

An operator's cyber programme has five jobs, usually held by five different people, and they are normally bought one crisis at a time.

OT Security Program Kit for the Plant — the plant itself: asset inventory with automatic risk scoring, zones and conduits with SL-T derived from consequence and exposure, the vendor remote-access broker and the six-step VPN retirement, patch and EOL strategy for equipment that cannot simply be patched, and the safety-first incident playbook built on loss of view versus loss of control.

Critical Infrastructure Regime Kit — the regulators above it: which regimes bind each asset, the NERC CIP 2026-to-2030 calendar, the TSA directive crosswalk with its 12-hour clock, the water regime sheet, twenty control families mapped across every regime with the strictest formulation named, the multi-regime incident clock, and the assessment programme planner. Every row points at the OT-01 file that produces its evidence.

CIRCIA 72/24 Reporting Readiness Pack — the federal duty: whether you are covered, whether an incident is reportable at 2 a.m., and the report drafted inside the first day.

Executive Tabletop Exercise Kit — the drill, with scenario 6 written for exactly this estate.

Director's Cyber Oversight Kit — the board layer: twelve questions with good and weak answer patterns, the oversight evidence log, the charter and expertise statement, and the annual calendar.

Why the whole set. The plant kit tells you what to build and in what order; the regime kit tells you which regulator asks for it and by when; the reporting pack is what happens in the twelve or seventy-two hours after; the tabletop is where you find out whether any of it works; and the oversight kit is what the board asks and records while you do. Build once to the strictest formulation and present each regulator its own view — that is the argument for owning the pair at the centre of this, and the other three are what turn it into a programme rather than a binder.

Safety first, throughout. These kits sit above live processes. Nothing here should be applied without plant engineering in the room, and where a compliance deadline and a safe operating state disagree, the safe state wins and the deviation gets documented.

Sold as a Standard licence at the entry tier because two of the five components are not sold as organisation licences; the vCISO / MSSP tier is available for firms running this across client estates.

What's in this bundle

Governance 8 pages

OT Security Program Kit for the Plant

Segment the plant, fence vendor remote access, survive the outage. For the plant with a flat network, a vendor VPN, SCADA on an ageing hypervisor and a safety PLC on the same VLAN — the IEC 62443 zones-and-conduits programme, sequenced for a plant that cannot stop.

Compliance 9 pages

Critical Infrastructure Regime Kit

One baseline, every regulator. Power, pipelines, water, rail and nuclear — which regimes bind each asset, what changed in 2026 and what lands by 2030, twenty control families mapped across all of them, and the incident clocks that run in hours.

Incident Response 8 pages

CIRCIA 72/24 Reporting Readiness Pack

Know in ten minutes whether CIRCIA covers you, decide in one call whether an incident is reportable, and have the report drafted inside the first day — the two-gate covered-entity worksheet, the four-prong decision tree, the 72/24 clock runbook, and a report pre-fill with a JSON Schema twin for your SOAR. Built on the NPRM, with a free update when the final rule publishes.

Governance 8 pages

Executive Tabletop Exercise Kit

Eight board-ready scenarios, ninety minutes each — 64 injects that each name the decision they force and the question to ask the room, a decision log that pre-fills and scores itself on time-to-decide, and an after-action report carrying the regulatory evidence statement for NYDFS 500.16(d), DORA Art. 11 and NIS2 Art. 20. A billable engagement in a box.

Governance 6 pages

Director's Cyber Oversight Kit

What a director should ask, and what a good answer looks like. Twelve questions with the good-answer and weak-answer patterns, the evidence log that proves oversight happened, and the charter, calendar and self-assessment regulators, plaintiffs and insurers now expect. No technical background assumed.

What's included

  • Complete Library (.zip) — all formats included — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-08