ISA/IEC 62443 Expert-Certified · tony@port254.com

Services

Six services covering the operational-technology layer and the regulatory obligations built on top of it. Each is engineering work first, compliance evidence second, not the other way around.

Service 01

OT/ICS Security Assessment

A structured assessment of your operational-technology environment against IEC 62443: asset identification, zone and conduit modelling, and a target security level (SL-T) assessment for SCADA, DCS, and industrial control system environments. This is the foundation every other engagement builds on: you can't secure, segment, or defend an environment you haven't first modelled correctly.

  • Asset identification and classification across the CII environment
  • Zone and conduit modelling
  • Target Security Level (SL-T) assessment
  • Gap report against the seven IEC 62443 foundational requirements
Service 02

IEC 62443 Advisory & Gap Programme

Regulation 71(3) permits Kenyan CII owners to adopt global best practices on their own initiative. IEC 62443 is the only international standard purpose-built for the SCADA and industrial-control environments running energy grids, water treatment plants, and transport networks. We hold all four ISA/IEC 62443 Expert certificates and turn the standard into a prioritised, resourced remediation programme, not a certificate on a wall.

  • Current (SL-A) versus target (SL-T) security level gap analysis
  • Prioritised remediation roadmap, sequenced around operational constraints
  • Vendor and system-integrator security requirement development
  • Ongoing advisory through implementation
Service 03

CII Regulatory & Audit Readiness

Designated CII owners are subject to formal compliance audits by the Director of NC4 under Regulations 44–50, worked from Form CMCA 6. Auditors can enter your premises with 30 days' notice. We run pre-audit readiness assessments against that exact template (network, system, data, application and physical security) so gaps are found and closed before the auditors arrive, and we draft the compliance documentation your CISO needs to present.

  • Pre-audit gap assessment against the CMCA 6 structure
  • Annual cybersecurity risk assessment and risk register (Reg 17)
  • Compliance report drafting (Reg 46) and audit-day support
  • CISO designation support and mandatory policy development (Reg 32–34)
  • Broader governance, risk and compliance advisory (ISO 27001 alignment, policy and risk frameworks) where it sits alongside a CII engagement
Service 04

OT Network Architecture & Segmentation

Two decades of networking and infrastructure work underneath the security layer: IT/OT boundary design, zone-and-conduit network architecture, DMZ design for IT/OT convergence, and remote and vendor access path review. Most CII breaches don't start in the control room. They start at a flat network boundary or an unmanaged remote-access path into it.

  • IT/OT boundary design and DMZ architecture
  • Zone and conduit network segmentation
  • Remote and third-party vendor access path review (Reg 39)
  • Active Directory and IT/OT identity boundary assessment
Service 05

Offensive Assurance for OT/IT Boundary

Regulation 39(d) explicitly requires regular security audits and penetration testing for critical information infrastructure. We hold OSCP and OSEP certifications, and testing is scoped for operational environments, identifying real vulnerabilities in SCADA, ICS, and IT/OT boundary systems without disrupting a live process. This is assurance work performed by the same person who did the architecture and standards work, not handed to a separate generalist pentest team.

  • IT/OT boundary and Active Directory penetration testing
  • Operations-safe testing of SCADA-adjacent and boundary systems
  • Remote and virtual access path testing (Reg 39)
  • Remediation guidance and re-test
  • General IT network and application penetration testing, scoped alongside an OT/CI engagement
Service 06

AI System Security Assessment

AI models and agents are entering operational and critical-infrastructure environments faster than most security programmes account for: predictive maintenance models on OT networks, AI-assisted SCADA anomaly detection, agentic tools with access to operational data. OffSec AI Red Teamer (OSAI) certified, we assess these systems the way we assess any other component entering a CII environment: for the specific risk they introduce to it.

  • Security assessment of AI models and pipelines operating on or near OT networks
  • Adversarial testing: prompt injection, model extraction, data leakage
  • Multi-agent and orchestration security review
  • Risk-prioritised hardening guidance

Start With an OT/ICS Security Assessment

Not sure where your operational-technology environment stands, or how far behind the CII Regulations you are? We start with a structured assessment: what you're running, what the standard requires, and where the gaps sit.

Get in Touch View All Expertise