OT / ICS Security — Netherlands

We secure
the floor,
not just
the office.

Industrial control systems, SCADA, and OT networks are your most critical — and most exposed — assets. Sec4OT provides hands-on security for production environments, built around your uptime, not around IT frameworks.

IEC
62443 aligned
OT
Native methodology
22
Years experience
NL
Nationwide onsite
V-101 REACTOR 62 bar S7-1500 CPU 1516 P ● UNIT 3 RUNNING T: 94°C P: 6.2bar STOP PANEL B-04 VFD-01 48.5Hz VFD-02 36.1Hz MANAGED SW P-201 RUN P-202 STBY PT FT E-301 HEAT EXCH. TT PT FT SEC4OT OT ENVIRONMENT SCAN LIVE
Triton/TRISIS targets Safety Instrumented Systems — energy sector
IEC 62443 — the international standard for industrial cybersecurity
CISA: 70% of ICS vulnerabilities are remotely exploitable
NIST CSF 2.0 — updated framework now explicitly covers OT environments
Legacy PLC firmware: average 8+ years without a security patch
MITRE ATT&CK for ICS — adversary tactics mapped to production environments
IT/OT convergence expanding attack surface in manufacturing and utilities
Passive OT discovery: visibility without production risk
Triton/TRISIS targets Safety Instrumented Systems — energy sector
IEC 62443 — the international standard for industrial cybersecurity
CISA: 70% of ICS vulnerabilities are remotely exploitable
NIST CSF 2.0 — updated framework now explicitly covers OT environments
Legacy PLC firmware: average 8+ years without a security patch
MITRE ATT&CK for ICS — adversary tactics mapped to production environments
IT/OT convergence expanding attack surface in manufacturing and utilities
Passive OT discovery: visibility without production risk

OT security
built for the floor

Three core service lines designed for production environments where downtime is not an option and legacy systems are the norm.

01 / Asset Management
Asset visibility
You cannot protect what you cannot see. We build a complete, verified inventory of every ICS/SCADA asset — PLCs, HMIs, historians, engineering workstations — including firmware, network exposure, and communication patterns.
Passive discoveryOT-safe scanCMDB export
02 / Vulnerability Management
Risk reduction
OT vulnerability management is not the same as IT. We assess what can be patched, what requires compensating controls, and what must be isolated — without a single minute of unplanned downtime. Output is a prioritised risk register, not a raw CVE dump.
CVE prioritisationCompensating controlsRisk register
03 / Professional Services
Expert services
Live-hack simulations on a digital twin, security awareness training for operators and engineers, and OT-SOC advisory. We work onsite, speak industrial, and understand that the SCADA operator has different needs than the CISO upstairs.
Live hack simulationDigital twinOperator training
Frameworks & standards
IEC 62443
NIST CSF 2.0
CISA ICS-CERT
MITRE ATT&CK for ICS
NIST SP 800-82

From intake to
secured production

A structured four-phase approach that keeps production running throughout.

01
Intake & scope
Free 30-minute call to understand your environment, obligations, and risk priorities. No commitment, no pitch deck.
02
Onsite discovery
We deploy passive monitoring and walk the floor with your engineers. Nothing changes, nothing goes offline.
03
Risk assessment
Findings mapped to IEC 62443. Delivered as a prioritised risk register with compensating control options per finding.
04
Remediation support
We stay alongside your team through implementation — patching, segmentation, hardening, and documentation.

Industrial
security
from the
inside out

Sec4OT was founded to address a gap that most IT security firms don't understand: the floor is not the office. Production environments run on protocols IT doesn't speak, hardware IT won't patch, and uptime requirements IT doesn't face.

We operate from the Netherlands, work on-site across industrial sectors, and bring OT-native expertise to every engagement — not an IT security methodology adapted for OT as an afterthought.

Sec4OT is deliberately small. When you engage with us, you work directly with Marc — a senior security engineer with a background in both production floor automation and offensive security. No junior consultants, no generic checklists.

M
Marc
Founder & OT Security Engineer

Over a decade of hands-on experience spanning industrial automation and OT cybersecurity. Fluent in both Modbus and MITRE ATT&CK for ICS — which means findings are grounded in production reality, not theoretical risk frameworks.

Backgrounds in PLC/SCADA engineering and penetration testing. Regularly engaged for asset discovery, vulnerability assessments, live-hack demonstrations, and OT-SOC design across manufacturing, water, and energy sectors.

PI Certified — Process Industry
IEC 62443 — Industrial cybersecurity standard
NIST SP 800-82 — OT security guidance
MITRE ATT&CK for ICS — adversary emulation
CISA ICS-CERT advisory alignment
Sectors served
Energy & utilities
🏭
Manufacturing
💧
Water treatment
Oil & gas
🚂
Transport
🧪
Chemicals

Four principles that
guide every engagement

Hard-earned convictions about what actually works in industrial environments.

Uptime first
Every recommendation accounts for production schedules, maintenance windows, and the reality that a PLC running 24/7 for eight years cannot simply be patched on a Tuesday afternoon. We plan around your operations, not our methodology.
OT-native, not IT-adapted
We use passive discovery tools designed for OT networks — not Nessus against a Siemens S7. We understand Modbus, Profinet, DNP3, and EtherNet/IP. We know the difference between a PLC and a DCS, and why it matters for your security posture.
Evidence-based risk
No vendor fear-mongering. Every finding is tied to a specific asset, a specific risk, and a specific compensating control option. If we cannot quantify it, we do not report it as critical. Your risk register should be actionable, not alarming.
Built for operators
Security awareness training designed for the person running the SCADA screen, not the CISO. Incident response procedures that account for the fact that your most important safety system is also potentially your most vulnerable network node.

OT security that
speaks industrial

Three service lines built specifically for production environments. Every engagement is scoped around your uptime requirements, your risk exposure, and your actual environment — not a standard IT security template.

Service 01
Asset visibility
OT asset management & inventory

You cannot defend what you haven't discovered. Most OT environments have grown organically over years — PLCs added, HMIs upgraded, historian servers never decommissioned. The result is a network nobody fully understands.

We deploy OT-safe passive and selective active discovery to build a complete, verified inventory of every device on your production network. No guessing. No spreadsheets from 2019.

Complete asset register: device type, vendor, firmware version, IP/MAC, and communication patterns
Network topology map showing OT/IT boundaries and internet-exposed assets
Identification of legacy devices, unmanaged endpoints, and rogue connections
CMDB-ready export compatible with your existing asset management tooling
Onsite deliveryZero production impact1–5 days typical
Protocols & platforms covered
  • Modbus, Profinet, EtherNet/IP, DNP3, OPC-UA
  • Siemens S7, Allen-Bradley, Schneider, ABB, Honeywell
  • Historians: OSIsoft PI, Ignition, Wonderware
  • HMI/SCADA: WinCC, FactoryTalk, iFIX
  • Safety instrumented systems (SIS/SIL-rated)
Frameworks aligned
  • IEC 62443-2-1 (IACS security management)
  • NIST SP 800-82 (OT security guide)
  • CISA ICS-CERT asset visibility guidance
Service 02
Vulnerability management
OT risk assessment & remediation planning

OT vulnerability management is fundamentally different from IT. You cannot simply patch a PLC running 15-year-old firmware because a scanner flagged a CVE. The risk of a failed update often exceeds the risk of the vulnerability itself.

We assess every finding in the context of your production environment — what can be patched, what requires compensating controls, what needs network isolation, and what requires a documented risk acceptance decision.

Prioritised risk register: each finding scored by exploitability, production impact, and proximity to safety systems
Remediation options per finding: patch, compensating control, isolation, or risk acceptance — with tradeoffs
Quick-win list: findings addressable in under one day with zero production impact
Technical report for your OT team plus executive summary for management
Onsite + remote optionsNo active scanning by default2–10 days typical
Assessment scope
  • CVE cross-reference for all discovered assets
  • Configuration review: hardening gaps, default credentials
  • Network segmentation: OT/IT boundary analysis
  • Remote access: VPN, jump servers, vendor connections
  • Patch status across all patchable devices
Deliverable format
  • Executive summary (1 page) for management
  • Technical report with full findings for OT team
  • Remediation tracker (Excel/CSV) for follow-up
Service 03
Professional services
Security testing, training & OT-SOC advisory

Beyond assessment, Sec4OT provides hands-on services for organisations that need to test their defences, train their people, and build detection capability in OT environments.

Live-hack simulation — Controlled attack demonstration on a digital twin. Shows your team exactly what an attacker could do and how it would appear in your monitoring tooling
Digital twin security lab — Mirror your production environment for testing without production risk. Ideal for patch testing, change validation, and red team exercises
OT security testing — Structured pen testing aligned to IEC 62443 zone/conduit model, with explicit scope agreed with your production manager before any test begins
Security awareness training — Operator-focused training in Dutch or English, built for SCADA operators, field engineers, and maintenance technicians — not the IT helpdesk
OT-SOC advisory — Design and implementation guidance for an Operational SOC — detection use cases, playbook development, and OT-specific incident response procedures
Dutch & EnglishOnsite deliveryScoped per engagement
Training audiences
  • SCADA operators & control room staff
  • Field engineers & maintenance technicians
  • OT/IT convergence teams
  • Plant managers & HSE officers
  • Executive & board level (tabletop exercises)
MITRE ATT&CK for ICS
  • All testing mapped to ATT&CK for ICS matrix
  • Findings linked to real-world threat actors
  • Detection gap analysis included

OT security
in the field

Practical insights from production environments — not theoretical frameworks. Written for engineers and security professionals working in or around industrial control systems.

OT-SOC
Featured
Building an operational security operations center: what it actually takes

OT environments have become aware of the need for security in production — making an operational SOC a possibility. But an OT-SOC is not an IT-SOC with different data sources. It requires different detection logic, different playbooks, different tooling, and a fundamentally different relationship with production.

This post covers what makes an OT-SOC distinct, what the minimum viable capability looks like, and the common mistakes organisations make when adapting IT security operations for industrial environments.

Read full article →
Passive OT asset discovery: methods, tools, and what to do with the results

A walkthrough of passive discovery approaches for ICS networks — and why the inventory is only the first step.

Coming soon
CVE triage in OT: why CVSS scores alone will mislead you

A critical CVE on a PLC that controls safety interlocks is not the same as the same CVE on an IT server. Here's how to contextualise risk properly.

Coming soon
What a live-hack simulation actually teaches your operators

Controlled attack demonstrations on digital twins — what they reveal about detection gaps and operator response.

Coming soon
Asset management
OT asset inventory in practice

Discovery methods, tooling, and what to do when you find devices nobody remembers installing.

Coming soon
Vulnerability management
Patching PLCs without breaking production

Risk-based patch management for OT — when to patch, when to compensate, and when to accept.

Coming soon
Threat intelligence
MITRE ATT&CK for ICS explained

How adversary tactics map to production environments — and what it means for your detection strategy.

Coming soon

Get new posts in your inbox

Practical OT security content, published when there's something worth saying — not on a content calendar. No spam, unsubscribe anytime.

Start with a
free intake

Tell us about your environment. We’ll come back with an honest assessment of your risk exposure and what it would take to address it — no sales pressure, no generic report.

info@sec4ot.nl
KvK: 89266692
Netherlands-based, on-site available nationwide