
Keep the lights on when an adversary comes for your control systems
Infrastructure hardening
Overview
Assessment and hardening of the control systems behind power, energy, finance and national infrastructure. OT-native defence engineered for SCADA and industrial control systems that cannot be rebooted, reducing the attack surface of the infrastructure that nations depend on.
OT-native assessment and hardening for the SCADA and industrial control systems behind power, water, energy and transport, reducing the attack surface of infrastructure that cannot simply be rebooted or patched on an IT schedule, for the ministries and operators who must keep essential services running, delivered by an independent team that keeps the map of your control estate inside your own borders.
Key capabilities
- OT-native assessment and hardening of SCADA and industrial control systems, rather than IT security patterns misapplied to control networks.
- Prioritised reduction of exposure across the control estate, sequenced so the highest-consequence risk is closed first.
- Segmentation between control and corporate networks to stop a breach traversing from the office side into the plant.
- Assessment tailored to ageing, poorly documented estates that were never built for a hostile network.
- Verification that fixes hold, so hardening is measured rather than assumed.
- The map of the control estate kept with the buyer, with no foreign disclosure line.
- Applied methodically alongside the operators who run the systems, so the plant keeps running throughout.
Performance envelope
| Protocol coverage | Configuration-dependent, matched to the estate |
| Estate assessment scope | Subject to mission profile |
| Segmentation model | Configuration-dependent |
| Sector classes | Multiple sector classes available |
| Verification approach | Tested against the hardened state |
| Integration surface | Integrated to existing systems on assessment |
| Estate knowledge | Retained by the buyer, no foreign disclosure line |
| Detailed methods | Available under controlled briefing, not published |
Qualitative envelope only. Exact figures are configuration-dependent and shared under a controlled briefing against your requirement: never published.
In depth
Infrastructure hardening is not a product but a methodical programme executed alongside the operators who run the systems. The work is unglamorous. Assess the estate as it actually is, reduce exposure in priority order, segment control from corporate, and verify the fixes hold. It is what decides whether essential services survive a determined attack, delivered and sustained through one accountable team.
Estate assessment
A structured survey of the operational-technology estate as it really is, often ageing, poorly documented and never designed for a hostile network, establishing what is actually running before anything is changed.
Exposure reduction
Prioritised hardening of the control systems and protocols carrying the most risk, sequenced so the highest-consequence exposure is closed first without disrupting the process the plant is running.
Segmentation
Separation between control and corporate networks so a compromise on the enterprise side cannot traverse into the systems that operate generation, water or transport.
Verification
Confirmation that each fix actually holds under test, so the programme reports a measured reduction in attack surface rather than an assumption of one.
Operators
The engineers who run the systems are part of the programme throughout. Their knowledge shapes the assessment, and training leaves them able to sustain the hardened state rather than watch it erode.
Integrations
Interfaces to the existing control, monitoring and site-security systems already in place, so hardening works with the installed base rather than forcing a rip-and-replace of infrastructure that cannot be taken offline.
Operational problems it addresses
- Reducing the attack surface of the SCADA and industrial control systems behind power, water, energy and transport before an incident exposes them.
- Segmenting control networks from corporate networks so a breach on the office side cannot reach the systems that run the plant.
- Assessing an ageing operational-technology estate that was never designed for a hostile network and is documented, if at all, only by the foreign vendors who built it.
- Hardening control systems that cannot tolerate downtime, where a careless fix can be as disruptive as an attack.
- Bringing the knowledge of a nation's control-system map back inside its own borders rather than leaving it with foreign vendors.
- Verifying that fixes hold, so hardening is a measured reduction in exposure rather than an assumption.
Deployment configurations
Why Unstrat: the difference
Unstrat is the authorised global representative and distributor for this capability. It is already in service with a track record behind it, so you are buying something that has done the job elsewhere, not funding a first attempt. You are not the test bed.
Versus IT security patterns applied to OT
Industrial control systems cannot be rebooted or patched on an IT schedule, and a careless fix can be as disruptive as an attack. Hardening here is OT-native and methodical, working with the constraints of live control systems rather than treating them as ordinary corporate endpoints.
Versus leaving the estate map with foreign vendors
When the control-system map sits with the foreign vendors who built the estate, so does a blueprint of national vulnerability. Independent assessment and hardening keep that knowledge with the buyer, with no foreign disclosure line, so the understanding of the infrastructure stays sovereign.
Versus a one-off audit or compliance tick
A point-in-time audit produces a report, not a hardened estate. This is a programme: assessment, prioritised exposure reduction, segmentation and verification that fixes hold, a measured reduction in attack surface rather than a checklist that flatters the current state.
Versus a single-vendor closed platform
One-vendor OT-security platforms lock a buyer into a fixed toolset and often into the vendor that built the vulnerability. Working with the installed base, and keeping the estate knowledge with the operator, avoids a rip-and-replace of infrastructure that cannot be taken offline.
Versus waiting for the incident that forces the issue
Much of the installed OT base was never designed for a hostile network, and attacks on utilities have moved from theory to precedent. Hardening reduces the attack surface before the incident that would otherwise expose it, when the cost is a programme rather than a national emergency.
How it reaches you
Sovereignty & localisation
- Buyer ownership of the estate assessment, control-system map and all findings the programme produces.
- Local control of the hardening roadmap, segmentation policy and configuration.
- Options for local execution and integration alongside the buyer's own operators.
- In-region maintenance and sustainment of the hardened state rather than remote, supplier-gated support.
- Operator training and train-the-trainer programmes so the national team can sustain hardening independently.
- Progressive technology transfer and component localisation, scoped per programme.
- A path towards independent sustainment so the estate stays hardened long after delivery.
Integration
- Existing SCADA and industrial control systems, hardened in place rather than replaced.
- In-service monitoring and site-security systems, augmenting current coverage of the OT estate.
- Corporate and enterprise networks, through controlled segmentation between control and business systems.
- Existing operator procedures and change-control processes, keeping the operators who run the plant in the loop.
- Government and regulatory databases where reporting on critical-infrastructure resilience is required.
- National and site infrastructure, including power, siting and process constraints, assessed as part of the programme.
Procurement & delivery
- Programmes begin with an estate assessment and a prioritised hardening roadmap, executed with the operators who run the systems.
- Export-control position and end-user-certificate chain are confirmed before any configuration is represented.
- Assessment, hardening, segmentation, verification and acceptance follow the standard programme path.
- Operator training, sustainment of the hardened state and in-region support are part of the same accountable engagement.
Infrastructure hardening: questions
Can you harden control systems that we cannot take offline?
Yes, and that constraint is the starting point. Industrial control systems cannot be rebooted or patched on an IT schedule, so hardening is OT-native and methodical, sequenced with the operators who run the plant so the process keeps running while exposure is reduced. A careless fix can be as disruptive as an attack, and the programme is built to avoid exactly that.
Our OT estate is old and barely documented. Where do you start?
With an assessment of the estate as it actually is. Much of the installed base is decades old, was never designed for a hostile network, and is documented only by the foreign vendors who built it, so the first work is establishing what is truly running before anything is changed, then reducing exposure in priority order.
Who ends up holding the map of our control systems?
You do. When a control-system map sits with foreign vendors, so does a blueprint of national vulnerability. Independent assessment and hardening keep that knowledge with the buyer, with no foreign disclosure line, so the understanding of your infrastructure stays sovereign.
How is this different from IT security applied to our plant?
IT patterns misapplied to control systems can break the process they are meant to protect. Hardening here is OT-native: assessment, prioritised exposure reduction, segmentation between control and corporate networks, and verification, all shaped by how the control estate actually behaves rather than by an office-network template.
How do we know the hardening actually worked?
Verification is part of the programme, not an afterthought. Each fix is confirmed to hold under test, so the programme reports a measured reduction in attack surface rather than an assumption of one. That distinguishes a hardened estate from a report that merely lists intended changes.
Will hardening force us to rip out and replace equipment?
The intent is to work with the installed base, not replace it. Infrastructure that cannot be taken offline is hardened in place and segmented, and the capability integrates with the existing control, monitoring and site-security systems. Any replacement is a scoped decision, not a precondition.
What can you tell us about protocols and specific methods?
Protocol coverage and scope are configuration-dependent and matched to your estate, and multiple sector classes are supported. The detailed methods are shared under a controlled briefing against your specific environment rather than published, so the discussion fits your systems, sector and constraints.
Next step on this capability
Related capability
View all →Applications it supports
Capability comparisons
Questions buyers ask
What is critical infrastructure hardening?
Hardening is the work of shrinking the attack surface of the control systems behind power, water, transport and finance, rather than only watching them. It runs as an assessment of the estate as it actually is, prioritised reduction of exposure, segmentation between control and corporate networks, and verification that the fixes held. Monitoring platforms tell you what is on the network and what looks wrong; hardening changes the thing that was wrong. Our teams do that work on live grids and payment networks, with 3 GW or more of generation defended and 7.5 billion financial accounts secured.
See: What infrastructure hardening coversOT security as a capability
Best OT security vendor for SCADA and industrial control systems
The market is dominated by monitoring platforms, and two of them are genuinely good: Dragos publishes a protocol coverage list detailed enough to check against your own substations, and Claroty xDome offers passive monitoring, Edge querying and CMDB integration in one modular platform. Neither document promises to change the configuration of a relay. The Cybersecurity Group works from the same protocol depth into the control systems themselves, on estates where a reboot is not available, with substation-security technology validated by a government laboratory and deployed in the field.
See: Dragos, Claroty and the cyber group comparedIT security patterns versus OT reality
Dragos alternatives for government infrastructure
Dragos is a strong platform with deep published protocol coverage, including IEC 61850 GOOSE, IEC 60870-5-101 and 104, DNP3 and Modbus. Governments look elsewhere for two reasons: a US-headquartered platform vendor sitting inside grid telemetry, and the fact that monitoring on its own does not reduce exposure. Our hardening work covers the same protocol families, is performed on the control systems themselves, and comes from an independent, non-aligned supplier. Plenty of operators sensibly run a monitoring platform and a hardening programme together.
Which industrial protocols does the hardening work cover?
IEC 61850, Modbus and DNP3, including air-gapped networks where a false positive is treated as unacceptable rather than tolerable. Dragos publishes a longer list in public, taking in IEC 60870-5-101 and 104, OPC UA and DA and a set of vendor-specific protocols from ABB, OMRON and others, and we say so on the comparison page. Claroty's data sheet claims the broadest coverage without naming protocols. Give every bidder your own protocol inventory and make them answer against it line by line.
OT security for air-gapped networks that cannot be rebooted
Passive monitoring works anywhere you can span a switch, which is why every credible vendor leads with it. What breaks in isolated environments is the cloud dependency: xDome is described as a SaaS platform, and the Dragos brochure describes sensors and virtual appliances without stating air-gap operation. Our brief specifically covers air-gapped networks with zero tolerance for false positives, because in a substation or a payments switch acting on a bad alert can trip generation or stop settlement. Make air-gap operation and the signature update path written requirements.
See: Air-gapped and connected estates comparedHow each vendor handles isolation
Substation cyber security for IEC 61850 environments
Substations are where the IT-security playbook fails most visibly, because the protocols are real-time and the equipment predates the threat model. The Cybersecurity Group has substation-security technology built for IEC 61850 environments, validated by a government laboratory and live-deployed rather than piloted. That sits alongside zero-day discovery work credited on the US NIST register with two CVEs. Ask any bidder which of your protocols its researchers have personally broken.
See: Substation-security technology and validationResearch record compared
How is infrastructure hardening priced against an OT monitoring subscription?
Nobody in this comparison publishes prices, so compare the shape of the spend rather than a headline. xDome is a modular SaaS subscription, so cost recurs and scales with sites and assets. Hardening is scoped engineering work with a defined end state, plus whatever monitoring you choose to run afterwards. A SaaS platform in a nationally sensitive or isolated estate also carries a hosting and data-residency conversation that has to be priced, and the honest comparison is total programme cost over five years.
Does hardening replace a security operations centre?
No. Hardening reduces what an attacker can reach; monitoring and response deal with what still gets through. The two are complements, which is why many operators run a detection platform alongside a hardening programme rather than choosing between them. Our defensive practice runs alongside the hardening work, with security operations blocking more than 100,000 threats a day across grids, regulated finance and fleets at sea.
See: Defensive cybersecurity and incident responseCritical infrastructure resilience
Cyber security for power generation and payment networks from one supplier
Grids and payment systems fail differently, and the discipline underneath them is closer than most buyers expect: both are real-time, both are unforgiving of downtime, and both are defended by too few people. Our practice covers power and energy, financial infrastructure, industrial control systems and national infrastructure from one team, with 3 GW or more of generation defended and 7.5 billion accounts secured. That breadth is worth checking rather than assuming, so ask which named engineers work across both.
See: Sectors covered by the hardening practiceCyber defence for financial institutions
Our grid control systems were installed by a foreign vendor and we have no reliable documentation. Where does a hardening programme even start?
It starts with the estate as it actually is, not as the drawings claim, and that assessment is most of the value in the first phase. From there the work is prioritised reduction of exposure, segmentation between control and corporate networks, and verification that the fixes held. The knowledge produced belongs to you rather than staying with the vendor who built the plant. Our teams do this on running infrastructure, including 3 GW or more of generation, so the sequencing assumes you cannot take the system down to suit a consultant's plan.
See: How a hardening programme is runThe infrastructure hardening brief
Can a ministry use a United States OT security platform without exposing grid topology to a foreign government?
It is a procurement question rather than paranoia, and the vendor documents raise it themselves. Dragos is US-headquartered and offers Neighborhood Keeper for anonymous threat-intelligence sharing across the OT community; Claroty is headquartered in New York and pushes automatic detection updates. For a private manufacturer those are benefits. For a state whose grid topology and vulnerability register are classified, the vendor's legal home and the direction of telemetry flow belong in the risk assessment. A non-aligned supplier removes that clause from the argument, and we still recommend writing the data-residency terms into any contract you sign.
What is the difference between OT security and normal enterprise IT security, and why can we not use our existing tooling?
In an office network a noisy alert costs an analyst an hour. In a substation or a payments switch, acting on a bad alert can trip generation or stop settlement, and missing a real one can do worse. Enterprise tools also assume you can patch, reboot and agent everything, none of which is true of control systems that were commissioned before the threat existed. That is why our work is OT-native and why air-gapped coverage is stated with zero tolerance for false positives rather than treating detection breadth as the goal.
How do we know a cyber supplier can actually read our protocols rather than reselling someone else's signatures?
Ask for original research and check where it was published. Claroty publishes its Team82 group, Dragos publishes its own OT threat intelligence feeding the platform, and the cyber group has two CVEs credited on the US NIST register plus substation-security technology validated by a government laboratory. All three are real credentials that mean slightly different things: a register entry proves original discovery, a threat-intelligence feed proves sustained coverage. Ask for both, and ask which of your protocols each supplier has actually broken.
Is this live work on production infrastructure or a pilot programme dressed up in case studies?
It is live work on running systems: 3 GW or more of generation defended, 7.5 billion financial accounts secured, and substation-security technology validated by a government laboratory and deployed in the field. The teams work in places where a false positive has an operational cost, which shapes how alerts are tuned and who carries the risk when one is wrong. Ask us, and every other bidder, what the false-positive rate looks like on your protocols and who is accountable when an alert stops a process.
See: Published operational scaleScale and validation compared
Can our own engineers be trained to sustain the hardening after the programme finishes, rather than renewing a contract forever?
That should be the stated end state of any national programme, and it is how ours is framed: a path to a sovereign security-operations capability rather than perpetual outsourcing. Hardening is executed with the operators who run the systems, so the estate knowledge stays with your people instead of leaving with a consultant. Live-fire training environments, including a maritime range built around bridge, navigation and OT systems, let defenders practise on realistic replicas of what they actually run.





