Skip to content

Platform

One governed model, from OT architecture to an issued report.

OTReady is not a questionnaire with a dashboard attached. Every judgement it records (a risk scenario, a requirement conclusion, a Finding, a remediation task, a line in a report) points back at a real part of the plant, and stays pointed at it.

  • Architecture first, so an assessment result can name what it applies to
  • Assessment-first: connectivity is optional enrichment, never a prerequisite
  • Findings, Evidence and remediation share one canonical identity
  • Reports are issued as versions and stay readable as documents
Illustration, not a screenshot. The projects shown are fictional demo estates. It shows how OTReady presents several OT estates under one governed platform. Every product image further down this page is a real capture.

The model

Each stage inherits the context of the one before it.

The order is not a marketing device. It is the dependency chain the product enforces: a target needs a scope to belong to, an assessment needs a target to filter against, a Finding needs something to be about, and a report needs all of it to be true at once.

  1. Context

    Sector context and OT Domains describe what the plant does, in the operator's own vocabulary rather than a fixed taxonomy.

  2. Architecture

    Sites, Zones, Subzones, Conduits and the Communication Channels inside them: canonical objects with stable identity that everything later refers to.

  3. Risk

    An initial cyber risk orientation, and the detailed IEC 62443-3-2 assessment that reasons scenario by scenario over zones and conduits.

  4. Targets

    Target Security Levels are proposed by the detailed risk work and then explicitly confirmed by a person. A proposal is not a target.

  5. Assessments

    IEC 62443-3-3 requirements filtered by the confirmed target, plus the NIS2 Quick Scan and the evidence-gated NIS2 Full Readiness assessment.

  6. Findings & Evidence

    Gaps become governed Findings with one canonical identity, each carrying its provenance, its affected architecture and the evidence behind it.

  7. Remediation

    A treatment decision turns a Finding into tracked work on one board, reviewed before it can close.

  8. Reports

    Readable reports, issued as immutable versions, assembled from the same canonical state everything else used.

Architecture

The part most assessment tools skip.

Most OT security tooling begins at the questionnaire, which means its output can describe a finding but not the thing the finding is about. OTReady begins one step earlier.

Sites, Zones and Subzones carry their own canonical identity. Conduits are the security relationships between them, and the Communication Channels inside a Conduit carry the protocol, direction and encryption facts. Assets, interfaces and locators live in the same model without being required to describe every relationship.

  • Purdue level is an architecture classification, never a Security Level
  • Approval state is separate from where an object came from
  • Multi-site estates, with contextual drill-down from estate to channel
The OTReady architecture explorer showing zones and subzones with the conduits recorded between them.
Zone & Conduit lens: the same canonical objects, viewed by relationship.
The OTReady assurance cockpit listing dimensions with a status band and a written explanation for each.
Each dimension names its reason, and links to the affected objects.

Assurance

A derived reading, assembled fresh, never stored.

The Assessment & Assurance cockpit reports the weakest single dimension rather than an average, and deliberately produces no score. One number would let a well-modelled architecture compensate for a risk posture nobody has assessed.

Every dimension states why it reads the way it does and links to the objects behind it. There is no opaque score to take on trust.

What is in the platform

The parts, and what each one is responsible for.

Architecture
Sites, Zones, Subzones, Conduits, Communication Channels, Assets and interfaces.
OT Domains
Customer-defined functional context, assigned many-to-many across the model.
Risk & Targets
Initial orientation, detailed IEC 62443-3-2 risk, and confirmed Target Security Levels.
Assessments
IEC 62443-3-3, NIS2 Quick Scan and NIS2 Full Readiness.
Assurance
A derived reading across dimensions, each explainable and linked to its sources.
Findings & Evidence
One canonical Finding model, and evidence artifacts linked to the contexts they support.
Remediation
One board, treatment decisions, review before closure, and full task context.
Reports
Three report kinds, issued as immutable versions with their history preserved.
Governance
People and access, project-scoped roles and grants, and audit history.

Connected Assurance enriches the model. It is never a prerequisite.

OTReady works assessment-first. A project with no connected source is complete and correct, not degraded. Where an operator does connect an NDR/IDS, SIEM, CMDB or their own API, observations can raise detected conditions and Operational Alerts: evidence that a source reported something, never approved architecture and never a Finding on its own.

Go deeper

  • Architecture

    The canonical model, and why a Conduit is not a Communication Channel.

  • Assurance

    How a derived reading is produced, and what UNKNOWN does and does not mean.

  • Remediation

    From a governed Finding to reviewed, accountable work on one board.

  • Reports

    Readable records, issued as versions that stay what they were.

See the model against your own plant.

The fastest way to judge whether this fits is to look at it with your sites, your zones and the assessments you are actually being asked for.