Engineer in a hard hat and hearing protection checking a protection relay on a switchgear panel
Two orders of the same list

An illustrative finding set, not a customer’s. The same eight items, ranked two ways. Severity scores rank the first list. Reachability and operational consequence rank the second. Nothing on the network is critical until the process says it is.

Watch

The same eight findings, re-ranked in front of you.

Thirty-one seconds on what changes when a list is ordered by consequence and reach instead of by score.

Scope

Six areas of work, in this order.

The order is deliberate. Consequence has to be understood before exposure means anything, and exposure has to be proven before a priority can be defended.

01

Operational consequence analysis

We begin with the process, not the network. Which functions must keep running, what a safe state looks like, what the operational and safety consequence is if each is lost or manipulated, and how long the operation can tolerate that loss. This is done with engineering and operations, not derived from documentation.

02

Architecture and zone review

Current network and system architecture assessed against ISA/IEC 62443 zone and conduit principles and Purdue-model separation. We document what the architecture is, not what the drawing says it is — the difference between the two is frequently the most useful finding of the engagement.

03

Asset and dependency visibility

Control systems, engineering workstations, historians, network infrastructure and safety-adjacent equipment identified through passive collection and configuration review. Assets are ordered by the operational function they support, because an inventory not ranked by consequence cannot drive a priority.

04

Exposure and reachability

Firewall rule sets, routing, remote access paths, wireless, portable media practice and IT/OT interconnection analyzed to establish what can actually reach what. Reachability is proven from configuration and observation. We do not assert a path we have not evidenced, and we do not scan a production network to find one.

05

Third-party and remote access

Vendor, integrator and OEM access reviewed end to end: who holds it, through what route, with what privilege, under whose approval, and whether it is revoked when an engagement ends. In multi-site estates this is consistently among the highest-consequence and lowest-visibility exposures we find.

06

Prioritized remediation sequence

Findings converted into an ordered plan: what to do first, why that order, what each item depends on, what it will disrupt, who owns it, and what level of effort it represents. Written so it can be taken to a budget conversation without translation, and tendered competitively without rewriting.

Nothing on the network is critical until the process says it is.

How we work on site

Nothing we do changes the state of your process.

These constraints are contractual, not aspirational. They are written into scope before work begins.

  • Passive collection only — no active scanning of production networks at any point
  • Safety systems out of scope — SIS is reviewed on paper, never interrogated live
  • Read-only access — configuration exports and observation, no changes made by us
  • Your escort, your rules — site access under your permit and supervision processes
  • Findings shown before they are written — no surprises in the final report

Fit

When this is the right engagement — and when it is not.

Use GoSecure™ when

  • You are being asked for an OT cybersecurity budget and cannot yet defend a number.
  • You have an asset inventory but no way to rank what it contains by operational consequence.
  • A regulator, insurer, auditor or customer has asked for evidence of operational risk assessment.
  • IT and OT disagree about exposure, and nobody has evidence rather than opinion.
  • You are about to spend on technology and want the priority established first.
  • You have acquired or inherited sites whose architecture nobody currently understands.

Do not use GoSecure™ when

  • You already hold a credible, current assessment. Start at execution instead — see AKTSecure™.
  • Your question is whether existing controls work, not what your risks are — that is ControlPulse™.
  • An incident is in progress. Assessment is not an incident-response activity.
  • There is no intention or funding to act on the output. An unfunded assessment becomes a filed report.
  • What you actually need is decision authority and ownership — see OT CISO Advisory.

Framework alignment

Mapped once. Reported against whatever governs you.

GoSecure™ is structured primarily around ISA/IEC 62443 — zones, conduits, security levels and capability requirements — because that is the vocabulary industrial engineering and industrial vendors already share.

Findings are then expressed against whichever additional frameworks actually apply to you: NIST CSF 2.0 where leadership reports in that language, NIST SP 800-82 for ICS-specific guidance, NERC CIP where you are a registered entity, and NIS2 or Saudi NCA ECC and OTCC where the obligation is real.

No customer is assessed against all of them. Mapping to frameworks that do not govern you adds pages and removes clarity. Compliance alignment is a reporting output of this engagement — it is not its objective.

Outcomes

What is different in the organization afterwards.

A defensible priority

A remediation order tied to operational consequence, so investment decisions can be justified to a board, a regulator or an insurer with reasoning rather than assertion.

One shared picture

Engineering, IT, security and leadership working from the same view of exposure. Most IT/OT disagreement is an evidence problem before it is a governance problem.

Spend directed, not increased

Frequently the output redirects planned spend rather than adding to it, because sequence and configuration turn out to matter more than additional capability.

A program, not a report

Owners, dependencies and effort attached to every item, so the work can start the week after delivery instead of waiting for a separate planning exercise.

Deliverables

What you receive, in writing.

Exact contents are agreed in scoping. These four are present in every engagement.

01

Operational risk register

Critical functions, credible disruption scenarios, consequence rating and current exposure — expressed in operational terms an engineering manager recognizes.

02

Architecture and exposure findings

Current-state architecture as observed, zone and conduit assessment, reachability analysis, and remote and third-party access paths with evidence attached.

03

Prioritized roadmap

Sequenced remediation with owner, dependency, effort, operational impact and framework reference per item. Structured for budgeting and for competitive tender.

04

Executive briefing

A leadership-level presentation of exposure, priority and required decisions — delivered live to your executive team, not left as a document to interpret.

Engagement process

Five steps, agreed before the first one begins.

Duration depends on estate size, site count and access. Scoping establishes it before any commitment is made.

Step 01

Scoping and rules of engagement

Sites, systems and boundaries defined in writing. Access method, escort requirements, data-handling rules and explicit exclusions agreed. Nothing proceeds until this document is signed by both sides.

Step 02

Consequence workshops

Structured sessions with operations, engineering and maintenance to establish critical functions, safe states and tolerance for loss. This is the step that most assessments skip, and it determines the value of everything after it.

Step 03

Technical review and observation

Configuration collection, passive network observation, documentation review and site walkdowns. Conducted under your permit-to-work and supervision arrangements, within agreed windows.

Step 04

Analysis and findings validation

Findings assembled, then walked through with your technical team before the report is written. Errors get corrected here, and your team is not seeing the content for the first time in front of leadership.

Step 05

Delivery and roadmap handover

Executive briefing, technical handover, and a working session to assign owners and confirm sequence. You leave with a plan that has names against it.

Questions we are actually asked

What gets asked before anyone agrees to site access.

Will any of this touch our production network?

No. Collection is passive throughout: span or tap-based network observation, configuration exports, documentation review and walkdowns under your escort. We make no change, we place nothing in line with a control path, and we do not scan a production network to confirm a route we suspect exists.

That constraint has a cost, and it is worth stating. Passive work establishes what a configuration permits and what traffic is observed. It does not establish what an active test would reveal. Where you need that second answer, it belongs in a ControlPulse™ engagement with written rules of engagement, an agreed window and a named abort authority.

We already have an assessment from someone else.

Then you may not need this one. Send it to us before the scoping call. If it establishes operational consequence, evidences reachability and gives you a defensible order of work, we will tell you to start at execution rather than repeat an assessment you have already paid for.

What we look for is specific: does it rank anything by what happens to the process, or is it an asset list with vulnerability severities attached? The second is common, and it is not a priority. It is a length.

How is this different from what our IT security team does?

Your IT security team almost certainly assesses against enterprise controls, patch position and known vulnerability exposure. That work is necessary and this does not replace it. The starting point is different: we begin from the physical process and what its loss or manipulation would mean, then work outward to the systems and paths that could cause it.

The practical difference shows up in the output. A vulnerability with no reachable path to a consequential function ranks below a documented vendor route into a control zone that nobody reviews. That ordering is difficult to produce from an enterprise toolset, because the toolset has no view of the process.

Our OEM says we cannot change that configuration.

That is frequently true, and we do not treat it as an opening position to be argued down. What we do is establish what the support agreement actually says in writing, because the verbal answer on site and the contractual position are often different documents.

Where the constraint genuinely holds, it is recorded as a constraint and the roadmap works around it with compensating controls rather than pretending it will be resolved. A plan that depends on a vendor changing its support position is not a plan you can fund.

What happens if you find something serious mid-engagement?

You hear it the day we find it, through a contact route agreed in scoping, not in a report six weeks later. The scoping document names who we call and who they may escalate to before any site work begins.

We will not act on it. We do not contain, disconnect, disable an account or change a rule, because we are not inside your operational authority and a well-intentioned action during production is how assessments cause incidents. You get the observation, the evidence and the options with their operational impact attached. The decision is yours.

We do not have budget this year.

There are two honest answers, and which applies depends on what the money is for. If there is no funding to assess and no funding to act, wait. An assessment delivered into an organization with no capacity to act on it becomes a filed report, and that outcome damages the next attempt more than doing nothing would.

If the problem is that you cannot defend a number for next year, a single representative site is usually the cheaper route. It produces a defensible figure, a sequence and an evidence base for the budget conversation, and it commits nothing at estate scale.

Next step

Start with one site, not the whole estate.

A single representative facility establishes method, effort and value before anything is committed at scale. Most multi-site programs we run began exactly that way.

  • Scope and exclusions in writing — before any site access is arranged
  • No active scanning — passive collection and configuration review only
  • Vendor-neutral output — nothing we recommend earns us a margin
  • Findings validated with your team — before they reach your executives

Questions buyers ask

The three things we are asked before we start.

What is GoSecure™?

GoSecure™ is InnovAKT's OT cybersecurity assessment. It establishes what is actually installed and connected, how it is exposed, and what a cyber event would do to the physical process — and turns that into a ranked, costed, sequenced program a plant can execute. It is an assessment written to be implemented, not filed.

Is a GoSecure™ assessment safe to run on a live plant?

Yes. Discovery is passive by default: network capture, configuration review, engineering documentation and interviews. Anything that would touch a live controller is proposed, agreed, coordinated with the vendor and scheduled — never run because a tool offered to run it.

How is GoSecure™ different from a standard vulnerability assessment?

A vulnerability assessment tells you which software is out of date. GoSecure™ tells you which of those facts can change the behaviour of the process, in what order they should be addressed, what each will cost, and who should own it. It is graded against IEC 62443 and the NIST Cybersecurity Framework, but the ranking is operational.