Six services covering the operational-technology layer and the regulatory obligations built on top of it. Each is engineering work first, compliance evidence second, not the other way around.
A structured assessment of your operational-technology environment against IEC 62443: asset identification, zone and conduit modelling, and a target security level (SL-T) assessment for SCADA, DCS, and industrial control system environments. This is the foundation every other engagement builds on: you can't secure, segment, or defend an environment you haven't first modelled correctly.
Regulation 71(3) permits Kenyan CII owners to adopt global best practices on their own initiative. IEC 62443 is the only international standard purpose-built for the SCADA and industrial-control environments running energy grids, water treatment plants, and transport networks. We hold all four ISA/IEC 62443 Expert certificates and turn the standard into a prioritised, resourced remediation programme, not a certificate on a wall.
Designated CII owners are subject to formal compliance audits by the Director of NC4 under Regulations 44–50, worked from Form CMCA 6. Auditors can enter your premises with 30 days' notice. We run pre-audit readiness assessments against that exact template (network, system, data, application and physical security) so gaps are found and closed before the auditors arrive, and we draft the compliance documentation your CISO needs to present.
Two decades of networking and infrastructure work underneath the security layer: IT/OT boundary design, zone-and-conduit network architecture, DMZ design for IT/OT convergence, and remote and vendor access path review. Most CII breaches don't start in the control room. They start at a flat network boundary or an unmanaged remote-access path into it.
Regulation 39(d) explicitly requires regular security audits and penetration testing for critical information infrastructure. We hold OSCP and OSEP certifications, and testing is scoped for operational environments, identifying real vulnerabilities in SCADA, ICS, and IT/OT boundary systems without disrupting a live process. This is assurance work performed by the same person who did the architecture and standards work, not handed to a separate generalist pentest team.
AI models and agents are entering operational and critical-infrastructure environments faster than most security programmes account for: predictive maintenance models on OT networks, AI-assisted SCADA anomaly detection, agentic tools with access to operational data. OffSec AI Red Teamer (OSAI) certified, we assess these systems the way we assess any other component entering a CII environment: for the specific risk they introduce to it.
Not sure where your operational-technology environment stands, or how far behind the CII Regulations you are? We start with a structured assessment: what you're running, what the standard requires, and where the gaps sit.