The OT Security Starter Kit | PrOTect IT All
// Free field guide

The OT Security Starter Kit

Ten things to do before you spend a dollar on a tool. Most plants I walk into already bought a product before they did the basics. The tool sits half deployed because the foundation under it was never poured. This is the foundation.

15+ years in critical infrastructure
Asset owner over 40+ power plants
Helped build the OT cyber practice at a Big Four firm and at Arcova
Former CTO at an OT security vendor

Send me the kit

The PDF lands in your inbox. No cost, no sales call.

We send the kit, new episodes, and the occasional field note. Unsubscribe any time.
Part One

The Five Controls

These map to the SANS Five ICS Cybersecurity Critical Controls, because that list is written by people who have defended real control systems, and it gets you ninety percent of the way there. Each one opens with the attacker's side, so you know what you are actually defending against, then the steps, then the tell that says you have the problem.

001

Write the plan for the plant, not the office

Isolating the box can trip a turbine or start an eight hour restart. You need a plan written for the physics of your facility, not the IT binder nobody opens.

002

Draw the line between IT and OT

A flat network is one phished clerk away from the whole plant. Most sites already own the hardware. The rules on it have not been reviewed in three years.

003

Watch your own network

Attackers stopped needing zero-days in OT years ago. They speak Modbus, DNP3, and OPC exactly the way your engineering workstation does.

004

Count every door in

Remote access is the front door in most OT incidents, and most plants have more doors than they know about. Start with the ones the vendors left open.

005

Patch what matters, mitigate the rest

You cannot patch like IT, and chasing every CVSS 10 will bury you. Rank by what is reachable and what it controls, then mitigate the rest on purpose.

Part Two

Zero Budget, This Week

Five moves that need an old computer, a maintenance window, and an afternoon. No purchase order, no procurement cycle, no vendor. If you do nothing else in this guide, do these.

006

Turn an old machine into a sensor

Real visibility on the control network for the cost of a spare PC and an afternoon. Attackers count on nobody watching.

007

Read your firewall

It has been logging every crossing for years and nobody has opened it. The evidence of a foothold is sitting in a log that is about to roll over.

008

Prove the asset inventory

The integrator's spreadsheet is dated startup and missing everything added since. Every other control depends on fixing that.

009

Test the backup

Ransomware in a plant is not about your files. It is about the only copy of the PLC logic and the HMI images that took three months to build.

010

Run the tabletop

Attackers rehearse. They have done this to plants before. Your team has never practiced. Fix that in one afternoon.

Read it, mark it up, hand it to the plant manager

The kit is free. Put your email in and it comes straight to your inbox. If you get to the end and want a second set of eyes on your site, the last page tells you how to reach me.

Send me the kit