Home / Services

How Red Tiger works

Three steps, from the live plant to 24x7 MSP + Metrics and Reports.

The assessment gets the team onto the plant safely. Then Red Tiger fixes the immediate need and presents the options to your board. If you want the team to stay, it watches those assets 24x7 and reports on them.

Rotating equipment on a bright plant floor
Step 1
1

Assessment

Plant-safe and passive on live OT. Level 3.5 and down. Only OT, not IT. For water and wastewater this is the infrastructure security assessment under AWIA and EPA §1433. The team runs REDCAT on one computer first so operations can see it does not change the console. You get a prioritized report and a board briefing.

The plant-safe assessment →
Step 2
2

Fix the immediate need

A plan with real-world fixes for the gap that fails AWIA, the open remote-access path, or the missing protection and detection at the plant. The IoTSecure.io mini is the team's usual device for protect and detect at the plant. A multi-year roadmap comes later if you want one.

Start with the assessment →
Step 3
3

24x7 MSP + Metrics and Reports

The team installs, maintains, and monitors the assets it just assessed. The mini at the plant connects back to Red Tiger so the team can watch it. Metrics and reports go to the people who need them, on the cadence you set.

24x7 MSP + Metrics and Reports →

NERC CIP and other services

  • NERC CIP CVACIP-aligned assessment for electric utilities: ESP access points, BES Cyber Systems, generation, EMS, and control centers. Evidence the auditor can use.
  • OT / ICS CVAThe live-plant assessment. Six layers. Level 3.5 and down.
  • OT / ICS penetration testingUsually after a passive assessment. Active work stays off live control paths unless there is a staging system.
  • External and internal IT penetration testingPaths from the Internet and from inside the business network toward the plant. The IT to OT boundary is the point.
  • OT cybersecurity roadmapHigh, medium, and low findings mapped to capital projects in a multi-year plan, highest risk in year one. People and policy, not only technology.
  • Architecture reviewZones, the SCADA DMZ, and remote and vendor access. For pipelines, TSA VADR with Red Tiger's partner UTSI. See Oil & Gas.
  • Compliance and frameworksISA/IEC 62443, NERC CIP, NIST SP 800-82, and the NIST CSF, applied on the industry pages where they matter.
  • ICS / OT incident responseA plan before an event, and help when something looks wrong.
  • Red teamTime-boxed cyber, physical, wireless, and social engineering testing, when you need the full picture.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.