Is this the right starting point?
When to use it
Leadership teams that need OT cybersecurity direction, and organizations whose people need the skills to carry it.
What you receive
Agreed advisory support for decisions and accountability, and role-based training with a capability plan.
What we start with
The decisions your leadership has to take, how OT risk is reported today, and the roles whose skills need to grow.
Working within your operation. Advisory responsibilities are scoped. Asset-owner obligations and operational authority do not transfer.

Cybersecurity is never a one-off project. It is a lifecycle, and it needs an independent, honest and skilled partner working with the operator through every stage.
Then back to Assess, as the operation, the threat and the standards change.
Watch
Build the capability to direct it yourselves.
Decision rights that close the gaps between IT, OT and leadership, and training built around the decisions each role actually takes.
From the operator side
Engineers who have run the plants.
We are experts in the key cybersecurity and OT cybersecurity standards. Our team has more than 20 years of experience, with careers spanning automation and process control systems engineering and IT/OT cybersecurity. We have worked as operators with major global companies across oil and gas, power and utilities, chemicals, energy, manufacturing and petrochemicals, as well as in OEM leadership and consulting.
We know how the process runs, what a maintenance window costs, why a controller cannot simply be taken offline, and what a trip does to the unit downstream.
The advisory role is held by InnovAKT's executive leadership: control systems engineering, asset-owner operations and the leadership of OT cybersecurity managed services, in the same people.
- Engineering
- Industrial control systems background spanning DCS and SCADA
- Asset owner
- Control systems engineering and operations in oil and gas
- Business builder
- Engineering, product, sales and general-management leadership
- Executive
- Former General Manager for global OT cybersecurity managed services
- Global experience
- Led multidisciplinary teams supporting critical-infrastructure sectors and regions
- Advisory
- OT cybersecurity, Industrial AI, digital transformation and operating-model design
Two services
Two ways to strengthen the people who own the risk.
- Service 01Available on its own
OT CISO Advisory
Executive OT leadership on demand
An experienced partner for the decisions that need both authority and industrial context: board reporting, IT/OT governance, program sequencing, vendor challenge, regulatory posture and Industrial AI.
- Service 02Available on its own
InnovAKT Academy
Role-based OT cybersecurity training
Training for control engineers, IT and security teams entering OT, shift teams, and executives and boards, with tabletop exercises and a capability plan.
Service 01 · OT CISO Advisory · executive leadership on demand
Seven decisions that require both authority and industrial context.
Each area crosses organizational boundaries. The work is to create a shared view of consequence, make ownership explicit and turn the decision into a sequence the operation can execute.
Decision rights
Commonly
| Decision | Operations | Engineering | IT & Security | Executive |
|---|---|---|---|---|
| Accepting cyber risk to a production process | C | C | C | |
| Approving a firewall change between L3 and L3.5 | C | A | ||
| Granting and revoking vendor remote access | C | A | ||
| Taking a controller offline during an incident | C | C | C | |
| Funding the OT security program | C | A | ||
| Setting the OT security architecture standard | C | C | ||
| Declaring an OT cybersecurity incident | C | A |
Three of the seven decisions have no single accountable owner. They are not unmanaged — they are managed by whoever escalates hardest on the day, which produces a different answer each time and no record of why.
With shared governance
| Decision | Operations | Engineering | IT & Security | Executive |
|---|---|---|---|---|
| Accepting cyber risk to a production process | C | C | C | A |
| Approving a firewall change between L3 and L3.5 | C | A | C | |
| Granting and revoking vendor remote access | A | C | C | |
| Taking a controller offline during an incident | A | C | C | |
| Funding the OT security program | C | C | C | A |
| Setting the OT security architecture standard | C | A | C | |
| Declaring an OT cybersecurity incident | A | C |
Every decision has one accountable owner and named consultation. Note what did not happen: nothing moved wholesale to IT, and nothing moved away from operations. The rows that were empty are the work.
A reference model. A is accountable — one per row, never more. C is consulted before the decision is made. Convergence does not fail on technology. It fails on rows with no A in them.
Board and executive reporting
Cyber-physical risk in the terms a board governs by: production, safety, environment, regulation and capital, comparable quarter to quarter.
IT/OT governance design
Decision rights, accountability and joint risk ownership written down, including who declares an OT incident and who holds stop authority.
Program sequencing and budget defense
A funded, sequenced multi-year program, and its defense in the rooms where capital is allocated.
Vendor, integrator and OEM challenge
Technical scrutiny of what is proposed, sold or written into a contract, with no commercial interest on our side.
Regulatory posture and audit readiness
What actually governs you, what evidence will be expected, what you can produce today and what the gap costs to close.
Support to the person who owns the risk
A confidential peer for the CISO, COO, engineering director or plant leader who holds the accountability.
Industrial AI and digital transformation governance
Use cases, data and decision authority, and the controls required before automation influences a consequential process.
A risk that two capable teams each believe the other owns is a risk nobody is managing.
The mandate options, the five-step method and each decision area in full are on the OT CISO Advisory page.
OT CISO Advisory service detailsService 02 · InnovAKT Academy · role-based training
Four audiences, two mechanics that make them work.
Our goal is to raise ICS and OT cybersecurity knowledge and bring more people into OT security. Tracks are selected against the gap that actually exists. Most organizations need two or three of them, not all four, and scoping establishes which before anything is built.
Control engineers and automation staff
Security concepts expressed in the terms this audience already works in: PLC, DCS and SCADA configuration practice, engineering workstation handling, portable media and project file transfer, vendor and OEM access, change control, and what to do with an observation that looks wrong. The emphasis is on the decisions they take every week, not on threat taxonomy.
IT and security teams entering OT
Process context, safety concepts, availability expectations, asset lifecycles measured in decades, and why a practice that is routine on the enterprise estate can be consequential on a process network. IT brings enterprise governance, identity, scale and operating discipline. OT brings process knowledge, engineering context, safety awareness and an understanding of consequence. This track is built so each side can use what the other holds, not so one absorbs the other.
Operations supervisors and shift teams
Short, practical sessions for the people on shift when something looks unusual: what is worth escalating, who to call, what information to capture, what not to change while it is being assessed, and how a cyber-related event differs from the process upsets they already handle well. Built to fit around shift patterns rather than assume classroom availability.
Executives and boards
What cyber-physical risk means for safety, production continuity and regulatory position, what the organization is currently accountable for, what a credible program looks like, and which decisions only leadership can take. Delivered as a working session, sized for a board agenda, with the organization's own exposure as the worked example.
Incident-response tabletop exercises
Scenarios written from your architecture, your vendor arrangements and your escalation routes, run with the people who would actually be involved. The value is rarely the scenario itself. It is discovering which decision has no owner, which contact list is out of date, and which assumption about a recovery path has never been tested. Where a scenario's decisions need proving, it continues as a cyber drill under AKTSecure™ GRC.
Competency assessment and capability plan
Where each role stands against the competencies it needs, recorded so it can be tracked, and a written capability plan setting out what the organization can now run without external support, what it should bring in-house next, and where retaining a supplier is the deliberate choice rather than the default one.
People do not act on what they were shown. They act on what they have practiced.
Each track in detail, formats and what each leaves people able to do are on the InnovAKT Academy page.
InnovAKT Academy service detailsHow we work
Accountability stays with you, and gets stronger.
Asset-owner obligations do not transfer
We advise, challenge and support; decisions and accountability remain with the people who hold them.
Vendor-neutral
No resale margin and no referral position in anything we recommend.
Your own exposure as the worked example
Briefings and training use your architecture and procedures, not generic material.
Hands-on where it is safe
Practical work on bench, spare or simulated equipment, or on your own equipment while it is out of service and isolated from the running process; safety systems are covered conceptually only.
Confidential by default
Leadership support is a working relationship, not a report to the board.
Fit
Where AKTElevate™ fits, and where to start instead.
Use AKTElevate™ when
- Accountability for cyber-physical risk is either unassigned or assigned to someone without the industrial context to exercise it.
- A board or audit committee is asking questions nobody can currently answer in business terms.
- A program is funded and running, but sequencing and decisions are contested every quarter.
- A capable leader owns the risk and needs a peer with industrial experience to test judgments against.
- Controls have been deployed and the people expected to operate them were never trained on them.
- An IT or security team is taking on OT responsibility and needs process and safety context before it does.
- A response plan exists on paper and has never been exercised by the people named in it.
Start with another service when
- What you need is delivery capacity and hands on the work. Our engineers deliver it through AKTSecure™, and AKTElevate™ can lead it alongside.
- You have no view of operational exposure yet. Start with GoSecure™, so governance is built on a known environment.
- What you need is round-the-clock operation of your security controls — see InnovAKT Shield™.
Framework alignment
Grounded in the language your board and your engineers already use.
Board reporting follows NIST CSF 2.0, including its Govern function, because that is the vocabulary directors and insurers recognize. Technical judgment is anchored in ISA/IEC 62443 and NIST SP 800-82 Rev. 3: establishing the charter and business case for an OT cybersecurity program (§3.1, §3.2), governance and risk management strategy (§6.1.2, §6.1.4), managing OT security risk (§4.1), and awareness and training (§6.2.2). Its comparison of OT and IT security (§2.4) is the backbone of the IT-to-OT track.
Outcomes
What is different in the organization afterwards.
Decisions with an owner
Every row that matters has exactly one accountable person, written down.
Reporting a board can govern by
Cyber-physical risk expressed in production, safety, environmental and regulatory terms, comparable quarter to quarter.
Capability that stays
Competencies recorded by role, and a plan for what the organization now runs without outside support.
A leader with a peer
The person who owns the risk has someone with industrial experience to test a judgment against before it is taken.
Deliverables
What you receive, in writing.
OT CISO Advisory
- Executive risk narrative and reporting packCyber-physical risk stated in operational and business terms, with the small set of measures leadership will actually track, the decisions required of them, and a structure that repeats reliably each cycle so movement is visible.
- IT/OT governance and decision-rights charterAccountability model across engineering, operations, IT and security: who decides what, who is consulted, what escalates and to whom, where enterprise standards apply and where a documented industrial exception applies instead.
- Sequenced program and investment caseMulti-year sequence with dependencies, operational impact, ownership and the cost of delay per item, written to be taken into a capital discussion without translation and tendered without rewriting.
- Regulatory and audit position statementWhat governs you, what evidence is expected, what exists today, what the gaps are, who owns closing each one, and the honest answer to give when an auditor asks about a gap that is still open.
InnovAKT Academy
- Role and competency mapWhich roles need which competencies, where each currently stands, and which tracks close the gap. The basis for track selection, and reusable as new staff join.
- Tailored training materialSession content, exercises and reference material built against your architecture and procedures where access allows, handed over in editable form for you to re-run.
- Tabletop exercise pack and findingsScenarios written from your environment, the facilitation material to re-run them, and a written record of ownership, communication and recovery gaps identified during the exercise.
- Capability planWhat the organization can now run without external support, what should move in-house next, what to retain externally by choice, and the refresh cadence required to hold the position.
Engagement process
Five steps, from orientation to a role you no longer need filled.
Orientation
The decisions, people and reporting cycles that matter, and the training gaps behind them.
Decision rights and priorities
The ownership model agreed; the tracks selected against the real gap.
Working cadence
Advisory sessions on the reporting cycle; training delivered in blocks around plant commitments.
Exercise
A tabletop with operations in the room, using your architecture and your escalation routes.
Hand over
A role you no longer need filled: capability plan, reporting format and governance your people now run.
Questions we are actually asked
What leaders, training managers and shift leads ask first.
Is this going to undermine our existing CISO?
It should not, and in most engagements the CISO is the person who asked for it. The role being filled is industrial context and the standing to arbitrate between engineering, IT and the business, alongside an accountable leader rather than over one. Reporting lines and the limits of the mandate are agreed in writing at the outset for exactly this reason.
Where it does become a problem is when an organization wants accountability transferred rather than strengthened. Risk ownership stays with the asset owner. If the intention is to move it to a supplier, this is the wrong engagement and no contract wording would make it the right one.
How many days a month is this, really?
It ranges from a standing cadence built around a reporting cycle and a steering forum, to an interim mandate during a transition or a major program. Intensity is agreed before commitment and reviewed at each cycle rather than assumed to continue at the level it started.
The engagement is designed to get smaller. If the same intensity is still required in year three, either the transfer is not working or the organization has a resourcing problem that an advisory arrangement is quietly masking. Both are worth naming rather than renewing around.
You are going to tell us to buy things.
There is no resale margin, no referral fee and no product line behind any recommendation. Frequently the advice redirects planned spend rather than adding to it, because sequence and configuration turn out to matter more than additional capability.
The structural safeguard matters more than the statement. Advisory is scoped and staffed separately from delivery, so the person advising on a priority is never the person whose utilization depends on that priority being funded. Where an engagement needs both, you contract them separately and you can put the delivery work out to someone else entirely.
Our engineering team will not accept an outsider setting security rules.
They are right not to, and a governance model designed without them will not be followed regardless of who signs it. Decision rights are designed in a room with engineering, operations, IT and security present, and both sides give something up. That is what makes the result durable.
The role arbitrates between positions; it does not impose one. Where engineering has a well-founded operational objection to an enterprise standard, the output is a documented industrial exception with a named signer, not a quiet deviation that nobody has accepted in writing.
What if your advice conflicts with our corporate security standard?
Sometimes it will, and the conflict is usually real rather than a misunderstanding. An enterprise patching cadence, an agent deployment requirement or an automated containment policy can each be correct on the corporate estate and consequential on a process network.
The answer is never to ignore the standard on site. It is to raise the exception formally, state the operational reasoning, define the compensating control, and have it accepted by whoever owns the standard. Undocumented deviation is how organizations discover during an audit that half the estate has been out of policy for years.
Our people have already done awareness training.
Then awareness is probably not the gap. Awareness training tells people that a category of risk exists. It rarely changes what an engineer does with a project file on a Tuesday, or what a supervisor does at two in the morning with a screen behaving oddly.
These tracks are built around the decisions a role actually takes. Where your organization needs awareness coverage only, we deliver that too, as a shorter and lighter engagement.
Will you train people on our live systems?
On your own systems and procedures, yes, but never on equipment controlling a running process. Your architecture, procedures and vendor arrangements are the worked examples, within the data-handling rules agreed in scoping. Hands-on practice runs on bench or spare equipment, in a simulated environment built to mirror your systems, or on your own equipment while it is out of service and isolated from the running process, in a window operations schedules and supervises.
Safety instrumented systems are covered conceptually and never used as a teaching environment. Everything else is planned with operations, so each session is as practical as the plant can safely support.
We cannot release operators for a full day.
The supervisor and shift material is built for exactly that constraint: short sessions, repeated across crews, scheduled around the roster rather than assuming classroom availability. Engineering tracks can be split into blocks across a shutdown or a quiet period.
What does not work is booking training against a roster that cannot support it. It gets deferred twice, then delivered to whoever happened to be available, which is how training ends up recorded as complete and absent from practice. We agree the schedule with the person who owns the roster before anything is built.
Do people get a certificate at the end?
Competency is assessed against the requirements of the role and recorded per person, and that record is yours to hold, reuse and show to a regulator, insurer or customer asking for evidence of role-based competency. It is a competency record rather than an accredited qualification, and we describe it that way.
Attendance is recorded too, for the audit trail. The competency record is what holds when someone checks, and it is what the program is built to produce.
Can you train our IT security team to run OT?
Yes, as a program rather than a single course. The track transfers process context, safety concepts and the judgment to know when an enterprise practice needs adapting, so a capable team can start working in an industrial environment without doing harm while it learns.
The rest comes from supervised time on plant alongside engineers who have it, which our engineers and OT CISO Advisory can provide while your team builds experience. Training shortens the period in which a well-intentioned enterprise practice produces an operational surprise, and engineering accountability and judgment stay in the room.
Next step
Start with one reporting cycle, or one track and one exercise.
One board or executive reporting cycle, or one track and one exercise, is enough to establish whether the work adds something your organization does not already have. It commits nothing beyond it.
- Accountability stays with you — the role strengthens ownership, it does not assume it
- Vendor-neutral — no resale margin and no referral position in anything we recommend
- Your exposure as the worked example — briefings and training use your architecture and procedures, not generic material
- Never on a running process — hands-on work uses bench, spare, simulated or isolated equipment
Or discuss one component on its own: OT CISO Advisory · InnovAKT Academy
Questions buyers ask
What we are asked before we start.
What is AKTElevate™?
AKTElevate™ is InnovAKT's leadership and capability offer. It combines OT CISO Advisory, executive OT cybersecurity leadership on demand, with InnovAKT Academy, role-based training for engineers, operators, IT teams and boards. Both are designed to strengthen the people who own the risk rather than replace them.
What is a fractional OT CISO?
A senior OT cybersecurity leader who carries the leadership work part-time under a written mandate: setting strategy, running the program, preparing and presenting board and regulatory reporting alongside your accountable executive, and directing internal teams and vendors. Accountability for the risk stays with that executive, and the organization does not have to hire a full-time executive it may not yet need or be able to recruit.
Why would an organization use OT CISO Advisory rather than hire?
Because the role is hard to fill and expensive to fill badly. Industrial organizations often need the judgment immediately and the headcount later. InnovAKT's OT CISO Advisory supplies the judgment now, builds the function while it is in place, and is designed to hand over to a permanent hire rather than to become permanent itself.
What does an OT CISO Advisory engagement actually cover?
Strategy and roadmap, governance and policy, risk reporting to executives and the board, program and vendor direction, regulatory and audit response, incident readiness and escalation design, and the development of the internal people who will eventually hold the role.
What is InnovAKT Academy?
InnovAKT Academy is the training arm of the firm: OT cybersecurity education for control engineers, IT and security teams, operations staff and executives, taught by consultants who deliver the work rather than by career trainers, and built around the client's own environment where that is possible.
Who should attend OT cybersecurity training?
Training is tailored to four audiences: control and automation engineers; IT and security professionals working with OT; operations supervisors and shift teams; and executives and boards. The selected tracks depend on the capability gaps and responsibilities in your organization. Not every engagement needs all four.
Is InnovAKT Academy training based on IEC 62443?
IEC 62443 and the NIST Cybersecurity Framework provide the structure, because those are the frameworks clients are measured against. The teaching itself is built on field cases, because a standard tells you what to achieve and a case tells you what it looks like when it goes wrong.