OT Security Program Kit for the Plant
Segment the plant, fence vendor remote access, survive the outage. For the plant with a flat network, a vendor VPN, SCADA on an ageing hypervisor and a safety PLC on the same VLAN — the IEC 62443 zones-and-conduits programme, sequenced for a plant that cannot stop.
What this actually gives you
- Safety first, and that is not a disclaimer. In IT you contain by isolating; in OT, isolating the wrong thing takes the operator’s view of a running process away. Every task carries a safety gate.
- The playbook opens on loss of view versus loss of control, and on the SCADA-on-Windows and ESXi misclassification that sends responders down an IT path on an OT event.
- Task 2 is “turn inbound VPN off”, and it is meant to be done today — the one change that removes the most exposure for the least engineering, sequenced before any architecture work.
- Zones carry an SL-T derived automatically from consequence and exposure; the conduit sheet with protocol, direction, enforcement and logging is your rulebase, plus deny-all.
- The TSA pipeline reporting clock is 12 hours under the SD-02 series, not 24 — rail differs. Eleven regimes, with every deadline computed from a single T0.
Safety first, and that is not a disclaimer. In IT you contain by isolating. In OT, isolating the wrong thing takes away the operator's view of a running process, and the failure mode is not data loss. Every task in this kit carries a safety gate, the incident playbook opens on the distinction between loss of view and loss of control, and recovery is safety-validated before it is complete. Nothing here should be applied without plant engineering in the room.
Written for the plant you actually have. A flat network. A vendor VPN that has been there for years. SCADA running on a hypervisor nobody wants to touch. A safety PLC sharing a VLAN with everything else. Dragos's 2026 review puts OT visibility below 10% at most operators, and no amount of architecture advice helps a site that cannot stop to implement it. The sequence here is built for a plant that runs continuously.
What you get
01 OT Asset Inventory (XLSX) — per asset: type, vendor, firmware, end of life, Purdue level, zone, protocols, exposure, vendor access, virtualisation, safety relevance, criticality, backup state and default credentials, resolving automatically to CRITICAL / HIGH / MEDIUM / LOW, with a flat-network indicator that tells you plainly what you are dealing with.
02 Zones & Conduits Plan + Design Narrative (XLSX + DOCX) — zones with SL-T derived automatically from consequence and exposure; conduits with protocol, direction, enforcement, logging and status — which is your rulebase — plus deny-all. The narrative carries the reference architecture, the DMZ pattern, per-zone rules, a cut-over approach that does not require an outage, and the evidence list an auditor will ask for.
03 Vendor Remote-Access Standard (DOCX) — broker-only architecture, named identities with phishing-resistant MFA, approval classes, logging, a vendor contract addendum, and a six-step VPN retirement. This is the control that regulators moved on first, and the one most plants still owe.
04 Patch & EOL Strategy (XLSX) — a decision matrix per asset class covering source, cadence, vendor approval, pre-conditions, compensating controls and rollback, with an EOL register that names the options and the dates. Written for equipment that cannot simply be patched on Tuesday.
05 OT Incident & Safety-First Playbook (DOCX) — incident classification including the SCADA-on-Windows and ESXi misclassification that sends responders down an IT path on an OT event, the first thirty minutes, containment at boundaries, hours 1 to 24, safety-validated recovery, roles and the record.
06 Regulatory Clocks (XLSX) — eleven regimes with applicability: CIRCIA, EPA and AWIA plus state water rules, the TSA directives, NERC CIP including CIP-015, NIS2, the CRA, PSM/RMP, insurance, the SEC and your contracts — and an incident clock computing every deadline from a single T0.
07 90-Day Plan (XLSX) — twelve sequenced tasks, each with its own safety gate, a status roll-up and a stated day-90 position.
08 Practitioner Guide (PDF) — what 2025–26 taught, the target plant, the inventory method, zones and conduits, the broker, patch and EOL, the hypervisor, backups and manual operations, monitoring, incidents, the regulatory map, what insurers, buyers and roll-ups ask, ninety days, failure patterns and an FAQ.
ot01.json — risk rules, the SL-T heuristic, the conduit schema, clocks and plan tasks.
Task 2 is "turn inbound VPN off", and it is meant to be done today. The ordering is deliberate: inventory, then the one change that removes the most exposure for the least engineering, then backups, then the DMZ and broker, then zones and conduits. A plant that follows it in order is materially safer before the architecture work starts.
Pairs with the Executive Tabletop Kit, whose scenario 6 is the drill for this, the CIRCIA 72/24 Reporting Readiness Pack for the federal reporting clock, I've Been Breached if it becomes an enterprise incident, the Vendor Risk Operations Kit for the vendors reaching into the plant, and the Data Center Assessment Kit where the estate extends into colocation.
Regulatory clocks are marked for verification against your own directives and permits — the TSA pipeline reporting clock in particular is 12 hours under the SD-02 series, not 24, and rail differs. A practitioner's toolset, not legal or engineering advice: adapt it with plant engineering, and let safety govern.
Also available in a bundle
This product is sold on its own and as part of a set. If you need more than this one, the set is cheaper than buying the parts.
What's included
- Complete Library (.zip) — all formats included — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
- Practitioner License: unlimited client use (vCISO / MSP)
More from the CISO Marketplace ecosystem
Choose your license:
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee
Version history ›
- v1.0.1 2026-09-04
Corrected the TSA pipeline incident-reporting clock to 12 hours — it was 24, which would have made you late.
- 06 Regulatory Clocks: TSA pipeline reporting is 12 hours under the SD-02 series (rail remains 24)
- Earliest-clock formula updated so the multi-regime deadline now resolves correctly
- v1.0.0 2026-09-04
First release.
Already bought this? Every update is free — sign in to My Library for the current version.