OT Cybersecurity Services
Protecting industry. Enabling tomorrow.
OT Cybersecurity built around the realities of your operations. From the control room to connected assets, NineTenths Company brings security, safety and continuity into one clear plan.
A clear focus. The whole OT picture.
NineTenths Company is focused on securing industrial operations across Saudi Arabia and the GCC.
Our primary objective: Localize advanced technology and protect critical and sensitive infrastructure across the region.
Our approach brings cybersecurity and industrial engineering into the same conversation: what must keep running, what could interrupt it, and which controls will reduce that risk.
Engineering-led thinking
Controls that respect production, safety systems and maintenance constraints.
Technology-neutral design
Recommendations shaped by your environment, priorities and lifecycle needs.
Practical accountability
Clear deliverables, agreed responsibilities and evidence you can use.
Complete lifecycle. Connected protection.
From the first assessment to ongoing assurance, our service portfolio addresses the full OT security lifecycle. Open a service area to see its scope and deliverables.
10 Service disciplines. One coordinated approach.
01 — Strategy, governance & compliance
- OT cybersecurity strategy, maturity baseline and investment roadmap
- Cybersecurity management system (CSMS), policies and operating procedures
- NCA ECC / OTCC gap assessment and control mapping
- ISA/IEC 62443 program alignment and certification-readiness support
- Risk ownership, RACI, third-party governance and management reporting
- Cybersecurity requirements for procurement, RFPs, EPC contracts
Typical deliverables: A prioritized roadmap, compliance register, governance model and evidence plan.
02 — Asset discovery & risk assessment
Build a reliable picture of assets, dependencies and risk without treating a running plant like an office network.
- Passive-first OT asset discovery and inventory reconciliation
- PLC, DCS, SCADA, SIS, HMI, IED and engineering workstation inventories
- Network topology, communication baselines and data-flow mapping
- Criticality, consequence-based risk and threat assessments
- Vulnerability identification, configuration reviews and exposure prioritization
- Authorized penetration testing in a lab or approved maintenance window; agreed stop conditions
- Supplier, remote-site and legacy-system risk reviews
Typical deliverables: An asset register, risk register, network maps and a sequenced remediation backlog.
03 — Secure architecture & engineering
Translate risk decisions into implementable controls across the plant, industrial DMZ and enterprise boundary.
- High-level design (HLD), low-level design (LLD) and technical specifications
- ISA/IEC 62443 zones and conduits; security-level target definition
- Industrial DMZs, firewall rules, microsegmentation and secure routing
- Unidirectional gateways where justified by consequence and data-flow needs
- Secure historian, MES, ERP, cloud and third-party integrations
- Resilient network design, time services, logging and architecture reviews
- Security requirements for greenfield facilities and brownfield upgrades
Typical deliverables: Approved designs, communication matrices, bills of materials and acceptance criteria.
04 — Implementation & commissioning
Introduce controls through controlled change, staged validation and an agreed operational handover.
- Industrial firewall, IDS, asset-visibility and monitoring deployment
- OT endpoint protection, application allowlisting and device control
- System hardening and secure baseline configuration
- Directory services, secure administration and infrastructure integration
- Proof of concept, factory acceptance tests and site acceptance tests
- Management of change, rollback procedures and maintenance-window coordination
- As-built documentation, operating procedures and knowledge transfer
Typical deliverables: Validated controls, test evidence, as-built records and a signed handover package.
05 — Identity & secure remote access
Give personnel and suppliers the access they need, with approval, traceability and limits.
- Privileged access management and least-privilege role design
- Multi-factor authentication at supported access boundaries
- Managed jump hosts, time-bound vendor access and session recording
- Account lifecycle, periodic access reviews and emergency access procedures
- Service-account and secrets management; certificate lifecycle planning
- Secure engineering laptops and removable-media workflows
Typical deliverables: An access model, approved remote-access paths and auditable access records.
06 — OT SOC & threat monitoring
Connect industrial telemetry to security operations while preserving engineering context.
- OT SOC design, operating model and managed or co-managed monitoring
- Passive network detection, protocol-aware alerts and anomaly investigation
- SIEM integration, detection engineering and MITRE ATT&CK for ICS mapping
- Threat intelligence enrichment and threat hunting under approved scope
- Severity matrices, escalation paths, incident triage and plant liaison
- SLAs, OLAs, use-case tuning and operational reporting
- Coverage and staffing, including any 24/7 service, agreed contractually
Typical deliverables: Detection use cases, escalation playbooks, coverage definitions and reporting dashboards.
07 — Vulnerability, patch & asset lifecycle
Prioritize changes by operational consequence, compatibility and real exposure.
- Continuous vulnerability tracking and risk-based remediation planning
- OEM advisory monitoring and patch applicability assessment
- Offline validation, backups, staged deployment and rollback testing
- Compensating controls for unsupported or unpatchable systems
- Configuration drift, firmware and certificate lifecycle management
- SCADA, PLC, IED and infrastructure obsolescence planning
- Periodic health checks and evidence refresh
Typical deliverables: A maintained remediation register, patch calendar and lifecycle replacement plan.
08 — Incident response & recovery
Coordinate cyber response with plant operations, process safety and business continuity.
- OT incident readiness assessments and scenario-specific response plans
- Tabletop exercises, communications trees and crisis coordination
- Forensic readiness, log retention and evidence preservation
- Authorized containment with operations and safety approval
- Recovery from trusted controller logic, configurations and system images
- Offline or immutable backups and restoration validation
- Business impact analysis, recovery priorities and lessons learned
Typical deliverables: Tested response playbooks, recovery procedures and exercise improvement actions.
09 — Assurance, training & program support
Coordinate cyber response with plant operations, process safety and business continuity.
- OT incident readiness assessments and scenario-specific response plans
- Tabletop exercises, communications trees and crisis coordination
- Forensic readiness, log retention and evidence preservation
- Authorized containment with operations and safety approval
Build lasting capability
10 — Connected industry & emerging security
Evaluate new technologies through bounded pilots, with safety and measurable acceptance criteria.
- Industrial drone and robotic inspection ecosystem security
- IIoT, edge-computing and private wireless security assessments
- Digital-twin and predictive-maintenance data integrity
- AI model, dataset and inference-pipeline security with human oversight
- Software supply-chain assurance, SBOM review and supplier risk
- Crypto-agility and post-quantum migration readiness for long-lived assets
- Continuous compliance evidence automation and cyber-range validation
Typical deliverables: A feasibility assessment, threat model, pilot design and operational acceptance criteria.

🔍
ASSESSMENT
Identify risks. Understand your environment. Build a secure foundation
- Asses Inventory and Mapping
- Risk & Vulnerability Assesment
- Security Gap Analysis
- Compliance (NERC, IEC 62443, NCA)
- Roadmap & Recommendations

⚙️
IMPLEMENTATION
Deploy the right controls. Integrate security into your operations.
- Secure Architecture Deign
- Network Segmentation & Access Control
- OT Security Solutions Deployment
- Patch & Configuration Management
- Testing & Comissioning
- Knowledge Transfer & Training

🛡️
MANAGED SERVICES
Continuous monitoring. Rapid response. Operational resilience.
- 24/7 OT SOC Monitoring
- Threat Detection & Incident Response
- Managed Patch & Vulnerability Management
- Asset Configuration Monitoring
- Reporting & Compliance Support
- Expert Advisory & Continuous Improvment
Different environments. The same responsibility.
Security decisions begin with the process being protected. We tailor scope to each sector’s equipment, operating model and consequences of disruption.
Oil, gas & petrochemicals
DCS, SIS, pipelines, terminals and remote production assets.
Power & substations
Generation, transmission, distribution, IEDs and substation automation.
Water & desalination
Treatment plants, pumping stations, telemetry and distributed SCADA.
Manufacturing
Production lines, process control, MES and industrial connectivity.
Mining & minerals
Processing plants, remote operations and industrial fleet interfaces.
Renewables & infrastructure
Solar, wind, BESS, transport, ports and building automation.
PROPOSED SOLUTION – PILOT-LED DELIVERY
A new perspective. A protected ecosystem.
NineTenths SkyGuard
Bring thermal, visual and LiDAR inspection to industrial assets, while securing the aircraft, ground station, communications and data behind every mission.
Built on NineTenths Company’s established drone services and ISO-certified management systems, this concept extends those capabilities into secure OT environments through feasibility assessments and controlled pilots.
01
Substation inspection
Inspect accessible equipment for thermal anomalies and visible defects, respecting electrical clearances and approved flight envelopes.
02
Plant & pipeline surveys
Support visual condition surveys and authorized leak-detection workflows using suitable sensors and engineering validation.
03
Renewable asset health
Support solar thermal surveys and wind-asset inspections, connecting validated observations with maintenance work orders.
Secure from mission to maintenance.
REFERENCE ARCHITECTURE
Aircraft & payload
Device identity · signed firmware
Encrypted storage · approved sensors
→
Ground station
Hardened devices · MFA
Protected command & telemetry links
→
Inspection DMZ
Isolated ingress · malware screening
Data validation · controlled APIs
→
Analytics & OT SOC
Asset-linked findings · audit trails · Human-reviewed maintenance actions
No direct drone-to-PLC or SIS control path. Inspection data crosses approved boundaries only.
How we protect the complete ecosystem
Before takeoff
Threat-model the mission; review vendor and software supply chains; inventory aircraft, batteries, payloads and docking stations; verify firmware, keys and operator access. Define flight approvals, site permits and data ownership.
After landing
Screen and validate uploaded data in an isolated inspection environment. Apply retention, access, residency and privacy requirements; protect APIs and AI models. Correlate security events with the SOC without exposing production controllers.
During the mission
Use authenticated and encrypted links where supported. Define loss-of-link and navigation-anomaly procedures, geofences and safe landing behavior. Monitor telemetry and preserve human control; encryption alone does not prevent RF interference or GNSS spoofing.
Throughout the lifecycle
Rotate credentials, patch through approved testing, inspect docks for tampering and revoke lost devices. Rehearse compromised-aircraft, lost-link and data-leak scenarios. No jamming or active counter-drone actions are included.
From concept to an approved operational pilot
- “Define the problem.” Choose one asset class, inspection objective and baseline workflow.
- “Assess feasibility.” Review aviation authorization, industrial hazards, radio constraints, data handling and cybersecurity.
- “Validate in isolation.” Test the aircraft, communications, data pipeline and failure scenarios outside production.
- “Run a controlled pilot.” Use approved missions and human validation of inspection findings.
- “Measure and decide.” Evaluate inspection coverage, finding quality, operator exposure, security events and maintenance usefulness before scaling.
Operations are subject to GACA and other applicable aviation rules, site-owner permission, airspace restrictions, qualified operators and safety assessment. Hazardous-area suitability and any BVLOS approval must be established separately. Benefits are evaluated in the pilot.
Global principles. Local requirements.
NineTenths Company’s approach follows applicable OT cybersecurity frameworks in Saudi Arabia and internationally. We identify the requirements relevant to each facility, map controls and support implementation with evidence.
Saudi Arabia
NCA OTCC & ECC
OTCC-1:2022 extends the Essential Cybersecurity Controls for industrial environments. Map applicable ECC 2-2024 and OTCC requirements to accountable implementation and evidence.
International OT
ISA/IEC 62443
Program governance, risk assessment, zones and conduits, system requirements, service-provider practices and secure product development. Security levels are scoped to systems and requirements.
Practical guidance
NIST SP 800-82 & CSF
Use SP 800-82 Rev. 3 for OT security guidance and CSF 2.0 for governance and outcome mapping. Supplement with SP 800-53 and SP 800-61 where relevant.
Management & continuity
ISO/IEC & ISO standards
Apply ISO/IEC 27001, 27002 and 27005 to management and risk; 27019 for energy utilities; ISO 22301 for business continuity, as required by the engagement.
Sector-specific references
Power, safety & industrial systems
Select IEC 62351, IEEE 1686 and IEC 61850 security considerations for power systems. Consider NERC CIP only where applicable or contractually adopted; coordinate with IEC 61508/61511 safety processes.
Threat-informed practice
MITRE, CISA & CIS
Use ATT&CK for ICS to structure detection scenarios, CISA guidance for operational practices and appropriately tailored CIS Controls. Purdue and ISA-95 support architecture understanding; they are not certifications.
Saudi and GCC applicability
Assess additional NCA controls, including CSCC, CCC and DCC, where critical systems, cloud or data scope makes them relevant. For GCC engagements, confirm the applicable national, sector and customer requirements in the UAE, Qatar, Oman, Bahrain or Kuwait before agreeing the compliance baseline.
Maintain a project-specific standards register covering applicable global, regional and customer requirements. Confirm current editions, jurisdiction, system boundaries and contractual obligations at kickoff and review them as the program evolves.
Separate the layers.
Control every conduit.
NineTenths Company maps every security control to the Purdue Reference Model — ensuring the right protection at every layer, from physical process to enterprise network.
Each layer below maps to a defined security zone. Controls are selected by consequence, not convention — what must never stop defines what must always be protected.
Enterprise network & external services
Corporate identity, finance, enterprise analytics, collaboration, approved cloud services.
Identity governance, endpoint security, internet controls, supplier assurance.
Plant business planning & logistics
ERP interfaces, production planning, maintenance management, quality and reporting consumers.
Segmentation, application allowlisting, controlled historian consumption.
Brokered exchange between IT and OT
Jump hosts, remote-access broker, patch and AV relays, historian replication, secure file transfer, update repositories.
MFA, session recording, dual firewalls, malware screening, proxy services.
Operations management systems
Plant historian, OT application servers, engineering support, domain services, backup, OT monitoring and management.
Dedicated OT identity, backup validation, passive monitoring, administrative separation.
Area and unit supervision
HMI, SCADA servers, operator stations, batch and alarm servers, local engineering workstations.
Hardened baselines, least privilege, application control, controlled engineering access.
Control and protection devices
PLC, DCS controllers, RTU, IED, protection relays, SIS/ESD logic solvers.
Logic integrity, signed firmware where supported, configuration backup, physical access.
The process being protected
Sensors, analyzers, actuators, valves, drives, motors, production machinery and physical conditions.
Safe state, tamper protection, calibration integrity, operational and safety procedures.
Remote & cloud access
Terminate through approved access services and the industrial DMZ, with time-bound authorisation and MFA. No direct IT-to-controller paths.
Modern architectures
IIoT, edge, wireless and cloud can cross traditional levels. Engineer real zones and conduits from data flows — not from assumed layer boundaries.
Safety systems
SIS and ESD functions require independent assessment. Safety integrity must not be compromised by security controls or shared network paths.
From one facility to a stronger portfolio.
Start with a defined scope. Prove the controls in the operating environment. Then repeat what works across substations, plants and remote assets.
01
Discover
Agree critical assets, site constraints, regulatory scope and success measures.
02
Engineer
Develop the risk treatment plan, HLD / LLD and implementation sequence.
03
Validate
Test, commission and hand over with operations approval and evidence.
04
Sustain
Monitor, maintain, exercise recovery and expand through reusable site standards.
Partner with OEMs & Vendors.
NineTenths Company’s partnership approach connects industrial equipment manufacturers, security vendors, EPCs and asset owners.
Industrial Control Systems — OEMs & automation platforms







OT Cybersecurity — Security technology vendors








How we work with technology partners
01 — Align the scope
Agree system boundaries and responsibilities.
02 — Validate together
Confirm interoperability and acceptance criteria.
03 — Sustain the solution
Define support ownership and lifecycle maintenance.
Frequently Asked Questions About OT Cybersecurity
OT (Operational Technology) cybersecurity protects the industrial systems that run physical processes — PLCs, DCS, SCADA, SIS and similar control equipment — from cyber threats that could disrupt operations, safety or production continuity. Unlike IT security, it prioritizes availability and safety over confidentiality.
IT security focuses on protecting data confidentiality across enterprise networks, while OT security focuses on keeping physical processes running safely and reliably. OT environments often involve legacy equipment, real-time constraints and safety systems that require specialized, engineering-aware approaches rather than standard IT tools.
Yes. NineTenths maps applicable NCA ECC 2-2024 and OTCC-1:2022 requirements to each facility, conducts gap assessments, and supports accountable implementation with the evidence needed for compliance reporting.
Timelines vary by facility size, asset count and site access constraints, but a typical asset discovery and risk assessment engagement is scoped after an initial discovery phase that defines critical assets, site limitations and regulatory requirements.
Yes, through its OT SOC & threat monitoring service. Coverage models — including any 24/7 monitoring — are agreed contractually based on the facility’s risk profile and operational requirements.
NineTenths secures oil, gas & petrochemicals, power & substations, water & desalination, manufacturing, mining & minerals, renewables & infrastructure, and military & security facilities, tailoring scope to each sector’s equipment and operating model.
