Company Partners Our Teams Contact Blog
Services
Industries
Talk to an expert
Industry and OT

Cybersecurity for industry and critical infrastructure, without stopping operations.

In manufacturing, energy and sanitation, an incident is not limited to data: it stops the line, interrupts supply and puts people at risk. We help manufacturers, utilities and critical infrastructure operators protect the convergence of IT and OT with controls that respect the production process.

Why the sector is a target

Availability is the asset attackers want to hold hostage

In OT, the priority is keeping the process running safely. Attackers know this: the higher the cost of an hour of downtime, the greater the pressure to pay.

IT/OT convergenceNetworks that were once isolated now exchange data with ERP, the cloud and IoT devices. A phishing attack on the corporate network can become a path to plant supervisory systems.
Legacy ICS and SCADAEquipment from different generations and vendors, systems that cannot be rebooted, and protocols such as Modbus and DNP3, designed without authentication or encryption.
Ransomware and production downtimeEven when the attack stays in IT, companies often shut down operations as a precaution. The impact is then measured in lost production and interrupted service.
Vendor remote accessIntegrators and manufacturers need to access PLCs and engineering workstations. Permanent connections, shared passwords, and uncontrolled tools become entry points.
What regulation requires

Standards that say what to do and how to do it

In the electricity sector, ANEEL Normative Resolution No. 964/2021 requires concession holders, permit holders and authorized agents, as well as ONS and CCEE, to maintain a cybersecurity policy and report the highest-impact incidents, with analysis of cause, impact and mitigation actions. ONS adds an operational routine with minimum controls for the environment that connects to system operations.

For the “how”, the reference is the series ISA/IEC 62443, focused on industrial automation and control systems: requirements for the security program of plant operators, service providers, and manufacturers, plus risk assessment that divides the environment into zones and conduits. The NIST SP 800-82 Rev. 3, an OT security guide published in 2023, covers ICS, SCADA, DCS, and PLCs. And MITRE ATT&CK for ICS catalogs the techniques used against industrial environments, from access through remote services to inhibiting response functions.

In sanitation and industry in general there is no cybersecurity regulation this specific, but the LGPD covers customer and employee data, and 62443 is the recognized path for structuring the program.

Where we help

Each risk in the industrial environment and the service that addresses it

Network detection

Visibility into traffic between IT and OT and detection of anomalous communications, without installing agents on sensitive equipment.

Identities and access

Vendor remote access through PAM, MFA, recorded sessions, and time-limited approval instead of permanent connections.

24×7 SOC and MDR

Continuous monitoring of the corporate network and its touchpoints with OT, to contain an attack before it reaches the plant.

Vulnerability Management

Asset inventory and prioritization of fixes by risk to the process, with compensating controls where patching is not possible.

Incident Response

A plan and crisis support to contain the attack, decide what to shut down and resume operations safely.

GRC

Cybersecurity policy, risk assessment and alignment with IEC 62443 and ANEEL Resolution 964, with organized evidence.

Segmentation and testing

Zones, conduits and testing that respect the process

Segmentation is not just separating the corporate network from the industrial one. It means grouping assets by function and criticality, defining how each zone can communicate and controlling those paths. That way, an IT incident does not spread to supervisory systems, and a compromised device cannot reach the rest of the plant.

Segmentation has to be tested. Our pentest verifies whether the barriers work, with scope defined together with engineering. CEDAE, the water and sanitation company of Rio de Janeiro, hired NTS for vulnerability assessment and pentesting. In the words of Paulo Pompei, of CEDAE: “Network Secure is our Information Security partner. With the vulnerability assessment and Pentest project, we were impressed by the information provided — it has become an ongoing and essential partner.”

NTS clients also include companies in the beverage industry, such as Coca-Cola.

Frequently asked questions

Common questions about OT security

Not always. Many OT assets can only be updated during downtime windows and with vendor validation. That is why remediation comes with compensating controls: segmentation, access restriction and traffic monitoring until the maintenance window.

No. The series has parts for those who operate the plant (the asset owner's security program), for service providers and integrators, and for component manufacturers. Part 3-2 covers risk assessment and the division of the system into zones and conduits.

Poorly planned active testing can affect sensitive equipment. In OT, the scope is defined with engineering, the most intrusive techniques are restricted to test environments or agreed windows, and inventory can be done passively.

Yes. ANEEL Normative Resolution No. 964/2021 requires sector agents to have a cybersecurity policy and to report the highest-impact incidents, with an analysis of cause and impact and of the mitigation actions taken.

How long can your operation stay down?

Talk to a specialist and see where your industrial network is exposed, from its connection to IT to vendor access.

Talk to an expert →