ICS Threat Assessment

ICS security grounded in the MITRE ATT&CK framework.

When you need it

  • Nobody can say which adversary techniques are realistic against your control systems
  • The board or a regulator has asked what the actual threats to operations are
  • You are planning security spend and want it aimed at the threats that matter

We uncover the threats to your ICS environment with a comprehensive evaluation built on the MITRE ATT&CK framework. We identify the risks, assess their impact and deliver strategies you can act on. Our experts work closely with your organisation to protect critical assets, reduce risk and harden the environment against evolving threats.

By analysing the tactics, techniques and procedures adversaries use, we give you a clear view of current and emerging threats. Recommendations are prioritised and paired with an implementation plan customised to your operations, so the overall security posture improves in the right order.

How it runs

  1. 1

    Scope the environment

    Sites, systems, the processes they run and what a disruption would mean to each.

  2. 2

    Map the threats

    The tactics, techniques and procedures relevant to your ICS, using the MITRE ATT&CK framework.

  3. 3

    Assess impact

    What each realistic threat could do to safety, production and the business.

  4. 4

    Prioritise

    A ranked view of the risks and the controls that close them.

  5. 5

    Plan

    An implementation plan customised to your operations, sequenced so the important things happen first.

What you get

  • Threats mapped to MITRE ATT&CK tactics, techniques and procedures
  • Risks identified with their impact assessed
  • Prioritised recommendations
  • A customised implementation plan

Where it is used most

Questions we get asked

How is this different from a risk assessment?

A threat assessment starts from the adversary: which techniques are realistic against your systems and what they could do. A risk assessment starts from the standard or the process. Most clients benefit from both, and we scope them together.

Do you need access to the control network?

Not for a first pass. We work from architecture, documentation and interviews, and add on-network evidence where it is available and safe to collect.

How long does it take?

It scales with the estate. We agree the scope and the timeline before we start.

Talk to us about threat assessment.

Tell us about the site, the systems and what you are trying to achieve. A consultant will reply.