Services

OT and control-system security architecture.

Zone and conduit design for SCADA and DCS: segmentation that is enforced rather than asserted, vendor remote access, and recoverable control systems.

Why people call

  • The network grew for twenty years without a plan, and the only diagram anyone trusts is the one in someone’s head.
  • There is a firewall between IT and OT, and a list of exceptions through it that nobody has reviewed since it was written.
  • An OEM has a VPN into level 2 and the access was granted before anyone asked what it could reach.
  • A regulator or an insurer has asked a question the current documentation cannot answer.

What we design

Zone and conduit model
The system under consideration defined, partitioned into zones and conduits, with a target security level set per zone and per conduit. This is the method in IEC 62443-3-2, which defines the process rather than prescribing a single named risk-assessment technique.
The boundary itself
What crosses between the operational estate and the enterprise, by what mechanism, in which direction, and what happens when that mechanism fails. Brokered or unidirectional patterns where inbound sessions cannot be justified.
Vendor and remote access
Who reaches the plant from outside it, through what, with which credentials, and what they can reach once inside. Usually the shortest path between a vendor’s convenience and a reportable incident.
Legacy and unpatchable equipment
Controllers that cannot be patched are an architecture problem, not a policy problem. Placement and mediation carry the risk that patching cannot.
Recovery
What it takes to rebuild a control system, tested rather than assumed, on the understanding that downtime here is a public-safety event rather than a revenue dip.

How it maps to your obligations

Stated from the instruments. Position as at August 2026; each row links to the detail.

A zone and conduit model showing what is segregated from what, and by what enforcing mechanism.
A compensating-controls position for equipment that cannot be patched, expressed as placement and mediation.
A remote-access inventory and the conduit design that governs it.
Architecture evidence behind whichever of the five named frameworks you have adopted.

What you are left holding

The work survives the consultant leaving, or it was not architecture.

  • Zone and conduit diagram, with target security levels per zone
  • Data-flow diagram across the IT/OT boundary
  • Asset and communications inventory, as known
  • Remote access register
  • Architecture decision records — what was chosen, what was rejected, and why
  • Prioritised roadmap in dependency order

Start with the drawings you already have.

Even an out-of-date drawing tells us more in thirty minutes than a questionnaire does in a week.

Or email info@radconsulting.au.