Skip to content

Process Industries

The plant does not stop so that you can assess it.

Refining, petrochemical, chemical and continuous process plants run for years between turnarounds, on control systems installed across three decades and maintained by vendors who need a way in. The assurance question is not whether the plant could be rebuilt securely. It is what can be written down, defended and improved while it keeps running.

Configurable
A process plant environment: process vessels, structural steel and piping around a process unit.
  • Process units, offsites and the control building as canonical Sites, Zones and Subzones
  • The boundary around safety-related systems modelled as architecture, never assessed as a safety function
  • Package units and vendor remote access recorded as the conduits they actually are
  • IEC 62443 and NIS2 answered plant-wide and per unit from one model

Understand the environment

Continuous operation is the constraint that shapes everything else.

A process plant is not a set of machines that can be taken down one at a time. It is a single continuous or batch operation in which the units are coupled, and the window in which anything can be touched is a turnaround scheduled years ahead. That single fact decides what a security programme can realistically be: not a remediation campaign, but a defensible written position that improves at the pace the plant allows.

The control estate reflects it. A distributed control system supervises the process, programmable controllers run the units around it, and a long tail of package units arrives with its own controller, its own engineering laptop and its own support contract. Remote I/O and field infrastructure reach out into areas people enter under permit. Much of it predates the network it now sits on, and replacing it is a capital project rather than a patch.

Alongside it sits equipment whose purpose is to bring the process to a safe state, and in many plants a fire and gas system beside it. Those have their own lifecycle, their own regime and their own people. What a cybersecurity model can honestly do is record where the boundary runs and what crosses it. What it must never do is pretend to evaluate whether the safety function works.

  • Continuous coupled operation with maintenance windows measured in years
  • DCS supervision, PLC unit control, and package units nobody specified centrally
  • Safety-related and fire and gas systems adjacent to the control estate
  • Long-lived brownfield equipment and standing vendor dependencies

Terminology

What OTReady calls things here.

OTReady ships no process taxonomy. These are the objects; the names inside them are the plant's own, taken from the plot plan and the unit numbering that already exist.

Site
A process complex, a tank farm, an offsites and utilities area, the control building. Physical grouping only, and it inherits nothing.
Zone and Subzone
The process control layer, a unit's control zone, the safety-related boundary, a package unit, the field layer. A unit with its own target becomes its own Subzone rather than a note on a bigger one.
Conduit
The relationship between the control layer and a unit, between the plant DMZ and a vendor path, or between a package unit and the system that supervises it.
Communication Channel
What that relationship actually carries: a control protocol, a historian feed, an alarm path, an engineering session. Encryption is recorded per channel, and "not recorded" stays not recorded.
OT Domain
Process control, safety systems, package units, utilities and offsites, remote operations. The plant's own functional vocabulary, not a fixed list.

Architecture

The complex as the plant already describes it.

The OTReady architecture view for an illustrative process-industry configuration, showing process units, package units, the safety-related boundary and offsites as canonical zones.
Real OTReady product screenshot using illustrative configuration data. Built to render the application for this page; not a demo estate and not a customer.

Conduit and channel

A package unit is where the tidy diagram stops being true.

The plant-wide drawing shows a supervised process with a controlled boundary. The package units are where that drawing and the plant diverge: a compressor skid, an analyser house or a boiler package arrives complete, with a controller nobody in the plant specified, a maintenance path the vendor expects to keep, and a data feed into the historian.

Written down as separate Channels, one relationship usually turns out to carry several different things behaving several different ways: the supervisory link, the trend data, and a session somebody uses from outside. Some are protected, some are not, and some nobody has established either way. That third state is kept as its own answer, because recording an unknown as "fine" is how a plant acquires a position it cannot defend at the next audit.

An OTReady conduit detail view for an illustrative process-industry configuration, listing the communication channels a package unit conduit carries.
Real OTReady product screenshot using illustrative configuration data.

How OTReady applies

The same chain, on a process complex.

  1. OT context
  2. Architecture
  3. Risk
  4. Targets
  5. Assessments
  6. Findings & Evidence
  7. Remediation
  8. Reports

Nothing in the chain is sector-specific. What differs is the shape of the answer: a plant-wide baseline that governs the complex, and unit-level targets that may legitimately be stricter or looser, each recorded as a deliberate decision rather than reconciled into one number.

Assurance

Plant-wide and unit-specific, read side by side.

The OTReady assurance cockpit for an illustrative process-industry configuration, showing each dimension with its band and the reason for it.
Real OTReady product screenshot using illustrative configuration data. A derived reading of assurance inputs, never a compliance verdict.
The OTReady governed findings list for an illustrative process-industry configuration, each finding attributed to the architecture object it concerns.
Real OTReady product screenshot using illustrative configuration data.

Findings

A finding that names a unit can be scheduled against a turnaround.

When a finding is attributed to the zone, conduit or channel it concerns, it can be matched to the only window in which that unit is actually reachable. A finding written against "the plant" cannot be, and quietly becomes the item that moves from one report to the next without ever being scheduled.

Representative use cases

What process operators bring to it.

A process unit
Its control zone, its field layer and its relationship to the plant-wide control system, with a target confirmed for the unit rather than inherited from the site.
The safety-related boundary
Recorded as architecture: which zone it is, what crosses it and under what conditions. OTReady documents the boundary; it does not assess, test or certify the safety function, and it is not a safety system.
Package units
The skids and vendor-supplied systems that arrived with their own controller and their own support path, modelled as real objects instead of a footnote.
Vendor and remote access
The paths that exist because the plant depends on the people who built it, enumerated as conduits and channels with their actual protection state.
Turnaround planning
Findings attributed to specific units, so that remediation can be planned against the window in which the unit is down rather than against a calendar.

Configurable today, and said plainly.

Process Industries is CONFIGURABLE with the standard OTReady objects. There is no process accelerator, no oil and gas accelerator, no process template and no accepted process demo estate. The screenshots on this page come from an illustrative configuration built to render the application for this page: it is not a customer, not a demonstrated use case and not a delivered solution. OTReady is not a DCS, a control system or a safety system, and it is not tied to any control system vendor.

Where the detail lives

  • OT architecture

    Sites, Zones, Conduits and the Channels inside them.

  • Risk and targets

    A plant-wide baseline and unit-level targets, each confirmed deliberately.

  • Assurance

    Nine dimensions, each with its reason, and no score.

See OTReady against your own process complex.

A working session on your units, your package systems and the paths your vendors use.