OTSEC playbook

The pattern you take home

Nine field steps, ten obligation families, one deterministic referee. Reusable on Monday inside your own estate.

Register free

01 / Field workflow

Scope to assurance in nine steps

  1. 1. Scope

    Confirm room, water system and safety boundary.

    Quick presents context; CLEO flags missing documents.

  2. 2. Discover

    Locate PLC, HMI, gateway, switch, radio, modem and trace visible connections.

    Meta expert coaches visual identification.

  3. 3. Identify

    Capture label, model, serial, firmware screen, ports, enclosure and network indicators.

    CLEO structures cited records — no guessing.

  4. 4. Explain

    Ask why it is connected, who owns it, who accesses it, when and from where.

    MAX flags unsupported operational claims.

  5. 5. Match

    Compare to KEV, CISA ICS advisory and vendor bulletin.

    Rules match exact product/version; a human confirms applicability.

  6. 6. Decide

    Remove, restrict, monitor, patch, replace or accept with compensation.

    AI drafts; the human safety and security authority decides.

  7. 7. Remediate

    Call the expert; perform preapproved containment or configuration work.

    Remote expert leads; operator controls the action.

  8. 8. Recover

    Validate process, alarms, local/manual control and rollback.

    Verifier checks required states and hashes.

  9. 9. Assure

    Submit the final record.

    MAX judges; verifier gates; the graph records.

02 / Obligation framework

Ten questions a finding must answer

An obligation is not paperwork. It is the required evidence set that lets a claim become a fact.

Asset inventory

Do we know what exists and who owns it?

Required evidence: Identity, location, function, criticality, owner, version, photo.

Connectivity

Why is it online and what can reach it?

Required evidence: Ports/path, zone/conduit, business purpose, remote-access owner, expiry.

Vulnerability

Is a known issue applicable?

Required evidence: Exact product, version and config plus advisory or KEV citation.

Access control

Who may connect, how and when?

Required evidence: Named identity, MFA, role, approval, window, revocation.

Change control

Was controller logic changed properly?

Required evidence: Request, approver, baseline hash, window, rollback and outcome.

Monitoring

Would we know if access or a write occurred?

Required evidence: Log source, expected events, detection rule, test result, owner.

Incident response

Can the team contain without unsafe effects?

Required evidence: Classification, contacts, decision authority, isolation SOP, comms.

Continuity / recovery

Can the building operate and restore trusted state?

Required evidence: Manual procedure, gold copy, backup location, restore test.

Competency

Is the field person qualified and supported?

Required evidence: Training, task scope, expert session, attestation and escalation.

Evidence assurance

Is closure supportable?

Required evidence: Provenance, relevance, completeness, MAX judgment, verifier result.

03 / The stack

Six systems and one referee

If the AI and the rules disagree, the deterministic verifier wins.

SystemEvent jobWhat you see
CriticalAssetOperational Infrastructure Graph, obligations, missions, evidence chain and authoritative factsThe building, assets, dependencies, vulnerabilities, SOPs, evidence and judgments in one graph
OTSECThreat-surface discovery plus expert-led field remediationField surveys, connected-asset questions, known-issue checks, approved containment and recovery
Amazon QuickCommand and collaboration work surfaceIncident view, task queue, evidence status, team progress and scoreboard
CLEOPlan-room and obligation specialistCited extraction from drawings, O&M manuals, SOPs and records; explicit gaps and no-assumption findings
MAXChief Inspector / mission assuranceAccepts or rejects evidence and professional conclusions; requests resubmission
Deterministic verifierRecomputes rules, scores and state transitionsA visible verified / not-verified result — it wins if AI and rules disagree

04 / Range architecture

Eight zones, zero venue routes

The deliberately bad firewall rule exists only inside the synthetic range.

Participant / Quick

No direct route to the controller zone; API-only access to event services.

CriticalAsset control plane

Signed service identity, least privilege, immutable event log.

AI assurance plane

Read, draft and judge only — no actuator, switch, PLC or dispatch permission.

Expert assistance plane

Session bound to mission and team; consent required; no production credentials.

OTSEC management

Exercise Director and Range Lead only; all actions preauthored and logged.

Synthetic OT DMZ

Only allowlisted conduits; the deliberately bad rule exists only inside the range.

Synthetic control zone

No venue route, safe dummy registers, resettable state.

Process simulation

Safe envelope enforced locally; no potable or live building connection.

05 / Standards mapping

Everything maps to something auditable

ISO/IEC 27001
Risk ownership, documented controls, competence, suppliers, incidents, continuity, corrective action.
ISO/IEC 27002
Inventory, acceptable use, identity and access, logging, configuration, vulnerabilities, remote access.
IEC 62443
Zones and conduits, system risk assessment, security levels, secure integration, service-provider process.
ISO 55001
Connects cyber treatment to asset lifecycle, criticality, maintenance, evidence and operational value.
NIST SP 800-82 Rev. 3
OT-specific security that preserves safety, reliability and performance, including BAS.

Definition of done

The event succeeds when a participant can move from an unknown connected pump control to a verified asset, applicable obligation, approved treatment, expert-assisted recovery and auditable fact — without ever placing the real building at risk.

Your privacy choices. We use only essential cookies by default. With your consent we may also use analytics or marketing tools. You can change your choice anytime. See our Privacy Notice.