In manufacturing, energy and sanitation, an incident is not limited to data: it stops the line, interrupts supply and puts people at risk. We help manufacturers, utilities and critical infrastructure operators protect the convergence of IT and OT with controls that respect the production process.
In OT, the priority is keeping the process running safely. Attackers know this: the higher the cost of an hour of downtime, the greater the pressure to pay.
In the electricity sector, ANEEL Normative Resolution No. 964/2021 requires concession holders, permit holders and authorized agents, as well as ONS and CCEE, to maintain a cybersecurity policy and report the highest-impact incidents, with analysis of cause, impact and mitigation actions. ONS adds an operational routine with minimum controls for the environment that connects to system operations.
For the “how”, the reference is the series ISA/IEC 62443, focused on industrial automation and control systems: requirements for the security program of plant operators, service providers, and manufacturers, plus risk assessment that divides the environment into zones and conduits. The NIST SP 800-82 Rev. 3, an OT security guide published in 2023, covers ICS, SCADA, DCS, and PLCs. And MITRE ATT&CK for ICS catalogs the techniques used against industrial environments, from access through remote services to inhibiting response functions.
In sanitation and industry in general there is no cybersecurity regulation this specific, but the LGPD covers customer and employee data, and 62443 is the recognized path for structuring the program.
Visibility into traffic between IT and OT and detection of anomalous communications, without installing agents on sensitive equipment.
Vendor remote access through PAM, MFA, recorded sessions, and time-limited approval instead of permanent connections.
Continuous monitoring of the corporate network and its touchpoints with OT, to contain an attack before it reaches the plant.
Asset inventory and prioritization of fixes by risk to the process, with compensating controls where patching is not possible.
A plan and crisis support to contain the attack, decide what to shut down and resume operations safely.
Cybersecurity policy, risk assessment and alignment with IEC 62443 and ANEEL Resolution 964, with organized evidence.
Segmentation is not just separating the corporate network from the industrial one. It means grouping assets by function and criticality, defining how each zone can communicate and controlling those paths. That way, an IT incident does not spread to supervisory systems, and a compromised device cannot reach the rest of the plant.
Segmentation has to be tested. Our pentest verifies whether the barriers work, with scope defined together with engineering. CEDAE, the water and sanitation company of Rio de Janeiro, hired NTS for vulnerability assessment and pentesting. In the words of Paulo Pompei, of CEDAE: “Network Secure is our Information Security partner. With the vulnerability assessment and Pentest project, we were impressed by the information provided — it has become an ongoing and essential partner.”
NTS clients also include companies in the beverage industry, such as Coca-Cola.
Not always. Many OT assets can only be updated during downtime windows and with vendor validation. That is why remediation comes with compensating controls: segmentation, access restriction and traffic monitoring until the maintenance window.
No. The series has parts for those who operate the plant (the asset owner's security program), for service providers and integrators, and for component manufacturers. Part 3-2 covers risk assessment and the division of the system into zones and conduits.
Poorly planned active testing can affect sensitive equipment. In OT, the scope is defined with engineering, the most intrusive techniques are restricted to test environments or agreed windows, and inventory can be done passively.
Yes. ANEEL Normative Resolution No. 964/2021 requires sector agents to have a cybersecurity policy and to report the highest-impact incidents, with an analysis of cause and impact and of the mitigation actions taken.
Talk to a specialist and see where your industrial network is exposed, from its connection to IT to vendor access.