Protecting industry. Enabling tomorrow.

A clear focus. The whole OT picture.

NineTenths Company is focused on securing industrial operations across Saudi Arabia and the GCC.

Our primary objective: Localize advanced technology and protect critical and sensitive infrastructure across the region.

Our approach brings cybersecurity and industrial engineering into the same conversation: what must keep running, what could interrupt it, and which controls will reduce that risk.

Engineering-led thinking

Controls that respect production, safety systems and maintenance constraints.

Technology-neutral design

Recommendations shaped by your environment, priorities and lifecycle needs.

Practical accountability

Clear deliverables, agreed responsibilities and evidence you can use.

Complete lifecycle. Connected protection.

From the first assessment to ongoing assurance, our service portfolio addresses the full OT security lifecycle. Open a service area to see its scope and deliverables.

10 Service disciplines. One coordinated approach.

01 — Strategy, governance & compliance
  • OT cybersecurity strategy, maturity baseline and investment roadmap
  • Cybersecurity management system (CSMS), policies and operating procedures
  • NCA ECC / OTCC gap assessment and control mapping
  • ISA/IEC 62443 program alignment and certification-readiness support
  • Risk ownership, RACI, third-party governance and management reporting
  • Cybersecurity requirements for procurement, RFPs, EPC contracts

Typical deliverables: A prioritized roadmap, compliance register, governance model and evidence plan.

02 — Asset discovery & risk assessment

Build a reliable picture of assets, dependencies and risk without treating a running plant like an office network.

  • Passive-first OT asset discovery and inventory reconciliation
  • PLC, DCS, SCADA, SIS, HMI, IED and engineering workstation inventories
  • Network topology, communication baselines and data-flow mapping
  • Criticality, consequence-based risk and threat assessments
  • Vulnerability identification, configuration reviews and exposure prioritization
  • Authorized penetration testing in a lab or approved maintenance window; agreed stop conditions
  • Supplier, remote-site and legacy-system risk reviews

Typical deliverables: An asset register, risk register, network maps and a sequenced remediation backlog.

03 — Secure architecture & engineering

Translate risk decisions into implementable controls across the plant, industrial DMZ and enterprise boundary.

  • High-level design (HLD), low-level design (LLD) and technical specifications
  • ISA/IEC 62443 zones and conduits; security-level target definition
  • Industrial DMZs, firewall rules, microsegmentation and secure routing
  • Unidirectional gateways where justified by consequence and data-flow needs
  • Secure historian, MES, ERP, cloud and third-party integrations
  • Resilient network design, time services, logging and architecture reviews
  • Security requirements for greenfield facilities and brownfield upgrades

Typical deliverables: Approved designs, communication matrices, bills of materials and acceptance criteria.

04 — Implementation & commissioning

Introduce controls through controlled change, staged validation and an agreed operational handover.

  • Industrial firewall, IDS, asset-visibility and monitoring deployment
  • OT endpoint protection, application allowlisting and device control
  • System hardening and secure baseline configuration
  • Directory services, secure administration and infrastructure integration
  • Proof of concept, factory acceptance tests and site acceptance tests
  • Management of change, rollback procedures and maintenance-window coordination
  • As-built documentation, operating procedures and knowledge transfer

Typical deliverables: Validated controls, test evidence, as-built records and a signed handover package.

05 — Identity & secure remote access

Give personnel and suppliers the access they need, with approval, traceability and limits.

  • Privileged access management and least-privilege role design
  • Multi-factor authentication at supported access boundaries
  • Managed jump hosts, time-bound vendor access and session recording
  • Account lifecycle, periodic access reviews and emergency access procedures
  • Service-account and secrets management; certificate lifecycle planning
  • Secure engineering laptops and removable-media workflows

Typical deliverables: An access model, approved remote-access paths and auditable access records.

06 — OT SOC & threat monitoring

Connect industrial telemetry to security operations while preserving engineering context.

  • OT SOC design, operating model and managed or co-managed monitoring
  • Passive network detection, protocol-aware alerts and anomaly investigation
  • SIEM integration, detection engineering and MITRE ATT&CK for ICS mapping
  • Threat intelligence enrichment and threat hunting under approved scope
  • Severity matrices, escalation paths, incident triage and plant liaison
  • SLAs, OLAs, use-case tuning and operational reporting
  • Coverage and staffing, including any 24/7 service, agreed contractually

Typical deliverables: Detection use cases, escalation playbooks, coverage definitions and reporting dashboards.

07 — Vulnerability, patch & asset lifecycle

Prioritize changes by operational consequence, compatibility and real exposure.

  • Continuous vulnerability tracking and risk-based remediation planning
  • OEM advisory monitoring and patch applicability assessment
  • Offline validation, backups, staged deployment and rollback testing
  • Compensating controls for unsupported or unpatchable systems
  • Configuration drift, firmware and certificate lifecycle management
  • SCADA, PLC, IED and infrastructure obsolescence planning
  • Periodic health checks and evidence refresh

Typical deliverables: A maintained remediation register, patch calendar and lifecycle replacement plan.

08 — Incident response & recovery

Coordinate cyber response with plant operations, process safety and business continuity.

  • OT incident readiness assessments and scenario-specific response plans
  • Tabletop exercises, communications trees and crisis coordination
  • Forensic readiness, log retention and evidence preservation
  • Authorized containment with operations and safety approval
  • Recovery from trusted controller logic, configurations and system images
  • Offline or immutable backups and restoration validation
  • Business impact analysis, recovery priorities and lessons learned

Typical deliverables: Tested response playbooks, recovery procedures and exercise improvement actions.

09 — Assurance, training & program support

Coordinate cyber response with plant operations, process safety and business continuity.

  • OT incident readiness assessments and scenario-specific response plans
  • Tabletop exercises, communications trees and crisis coordination
  • Forensic readiness, log retention and evidence preservation
  • Authorized containment with operations and safety approval

Build lasting capability

10 — Connected industry & emerging security

Evaluate new technologies through bounded pilots, with safety and measurable acceptance criteria.

  • Industrial drone and robotic inspection ecosystem security
  • IIoT, edge-computing and private wireless security assessments
  • Digital-twin and predictive-maintenance data integrity
  • AI model, dataset and inference-pipeline security with human oversight
  • Software supply-chain assurance, SBOM review and supplier risk
  • Crypto-agility and post-quantum migration readiness for long-lived assets
  • Continuous compliance evidence automation and cyber-range validation

Typical deliverables: A feasibility assessment, threat model, pilot design and operational acceptance criteria.

Assesment

🔍

ASSESSMENT

Identify risks. Understand your environment. Build a secure foundation

  • Asses Inventory and Mapping
  • Risk & Vulnerability Assesment
  • Security Gap Analysis
  • Compliance (NERC, IEC 62443, NCA)
  • Roadmap & Recommendations
Implementation

⚙️

IMPLEMENTATION

Deploy the right controls. Integrate security into your operations.

  • Secure Architecture Deign
  • Network Segmentation & Access Control
  • OT Security Solutions Deployment
  • Patch & Configuration Management
  • Testing & Comissioning
  • Knowledge Transfer & Training
Managed Services

🛡️

MANAGED SERVICES

Continuous monitoring. Rapid response. Operational resilience.

  • 24/7 OT SOC Monitoring
  • Threat Detection & Incident Response
  • Managed Patch & Vulnerability Management
  • Asset Configuration Monitoring
  • Reporting & Compliance Support
  • Expert Advisory & Continuous Improvment

Different environments. The same responsibility.

Security decisions begin with the process being protected. We tailor scope to each sector’s equipment, operating model and consequences of disruption.

Oil, gas and petrochemicals icon

Oil, gas & petrochemicals

DCS, SIS, pipelines, terminals and remote production assets.

Power and substations icon

Power & substations

Generation, transmission, distribution, IEDs and substation automation.

Water and desalination icon

Water & desalination

Treatment plants, pumping stations, telemetry and distributed SCADA.

Manufacturing icon

Manufacturing

Production lines, process control, MES and industrial connectivity.

Mining and minerals icon

Mining & minerals

Processing plants, remote operations and industrial fleet interfaces.

Renewables and infrastructure icon

Renewables & infrastructure

Solar, wind, BESS, transport, ports and building automation.

Military & security

Defense facilities, security operations, mission-critical platforms and sensitive communications, protected through confidentiality, operational resilience and alignment with applicable national requirements.

PROPOSED SOLUTION – PILOT-LED DELIVERY

A new perspective. A protected ecosystem.

NineTenths SkyGuard

Bring thermal, visual and LiDAR inspection to industrial assets, while securing the aircraft, ground station, communications and data behind every mission.

Built on NineTenths Company’s established drone services and ISO-certified management systems, this concept extends those capabilities into secure OT environments through feasibility assessments and controlled pilots.


01

Substation inspection

Inspect accessible equipment for thermal anomalies and visible defects, respecting electrical clearances and approved flight envelopes.


02

Plant & pipeline surveys

Support visual condition surveys and authorized leak-detection workflows using suitable sensors and engineering validation.


03

Renewable asset health

Support solar thermal surveys and wind-asset inspections, connecting validated observations with maintenance work orders.

Secure from mission to maintenance.

REFERENCE ARCHITECTURE

Aircraft & payload

Device identity · signed firmware

Encrypted storage · approved sensors

→

Ground station

Hardened devices · MFA

Protected command & telemetry links

→

Inspection DMZ

Isolated ingress · malware screening
Data validation · controlled APIs

→

Analytics & OT SOC

Asset-linked findings · audit trails · Human-reviewed maintenance actions


No direct drone-to-PLC or SIS control path. Inspection data crosses approved boundaries only.

How we protect the complete ecosystem

Before takeoff

Threat-model the mission; review vendor and software supply chains; inventory aircraft, batteries, payloads and docking stations; verify firmware, keys and operator access. Define flight approvals, site permits and data ownership.

After landing

Screen and validate uploaded data in an isolated inspection environment. Apply retention, access, residency and privacy requirements; protect APIs and AI models. Correlate security events with the SOC without exposing production controllers.

During the mission

Use authenticated and encrypted links where supported. Define loss-of-link and navigation-anomaly procedures, geofences and safe landing behavior. Monitor telemetry and preserve human control; encryption alone does not prevent RF interference or GNSS spoofing.

Throughout the lifecycle

Rotate credentials, patch through approved testing, inspect docks for tampering and revoke lost devices. Rehearse compromised-aircraft, lost-link and data-leak scenarios. No jamming or active counter-drone actions are included.

From concept to an approved operational pilot
  1. “Define the problem.” Choose one asset class, inspection objective and baseline workflow.
  2. “Assess feasibility.” Review aviation authorization, industrial hazards, radio constraints, data handling and cybersecurity.
  3. “Validate in isolation.” Test the aircraft, communications, data pipeline and failure scenarios outside production.
  4. “Run a controlled pilot.” Use approved missions and human validation of inspection findings.
  5. “Measure and decide.” Evaluate inspection coverage, finding quality, operator exposure, security events and maintenance usefulness before scaling.

Operations are subject to GACA and other applicable aviation rules, site-owner permission, airspace restrictions, qualified operators and safety assessment. Hazardous-area suitability and any BVLOS approval must be established separately. Benefits are evaluated in the pilot.

Global principles. Local requirements.

NineTenths Company’s approach follows applicable OT cybersecurity frameworks in Saudi Arabia and internationally. We identify the requirements relevant to each facility, map controls and support implementation with evidence.

Saudi Arabia

NCA OTCC & ECC

OTCC-1:2022 extends the Essential Cybersecurity Controls for industrial environments. Map applicable ECC 2-2024 and OTCC requirements to accountable implementation and evidence.

Official reference ↗

International OT

ISA/IEC 62443

Program governance, risk assessment, zones and conduits, system requirements, service-provider practices and secure product development. Security levels are scoped to systems and requirements.

Official reference ↗

Practical guidance

NIST SP 800-82 & CSF

Use SP 800-82 Rev. 3 for OT security guidance and CSF 2.0 for governance and outcome mapping. Supplement with SP 800-53 and SP 800-61 where relevant.

Official reference ↗

Management & continuity

ISO/IEC & ISO standards

Apply ISO/IEC 27001, 27002 and 27005 to management and risk; 27019 for energy utilities; ISO 22301 for business continuity, as required by the engagement.

Official reference ↗

Sector-specific references

Power, safety & industrial systems

Select IEC 62351, IEEE 1686 and IEC 61850 security considerations for power systems. Consider NERC CIP only where applicable or contractually adopted; coordinate with IEC 61508/61511 safety processes.

Official reference ↗

Threat-informed practice

MITRE, CISA & CIS

Use ATT&CK for ICS to structure detection scenarios, CISA guidance for operational practices and appropriately tailored CIS Controls. Purdue and ISA-95 support architecture understanding; they are not certifications.

Official reference ↗

Saudi and GCC applicability

Assess additional NCA controls, including CSCC, CCC and DCC, where critical systems, cloud or data scope makes them relevant. For GCC engagements, confirm the applicable national, sector and customer requirements in the UAE, Qatar, Oman, Bahrain or Kuwait before agreeing the compliance baseline.
Maintain a project-specific standards register covering applicable global, regional and customer requirements. Confirm current editions, jurisdiction, system boundaries and contractual obligations at kickoff and review them as the program evolves.

Separate the layers.
Control every conduit.

NineTenths Company maps every security control to the Purdue Reference Model — ensuring the right protection at every layer, from physical process to enterprise network.

Each layer below maps to a defined security zone. Controls are selected by consequence, not convention — what must never stop defines what must always be protected.

Enterprise IT
Industrial DMZ
Operations & control
Physical process
L5 ENTERPRISE

Enterprise network & external services

Corporate identity, finance, enterprise analytics, collaboration, approved cloud services.

SECURITY FOCUS

Identity governance, endpoint security, internet controls, supplier assurance.

Approved business data  ↓  No direct enterprise-to-controller path
L4 SITE BUSINESS

Plant business planning & logistics

ERP interfaces, production planning, maintenance management, quality and reporting consumers.

SECURITY FOCUS

Segmentation, application allowlisting, controlled historian consumption.

North firewall  ↓  Explicit allowlist, inspected flows
L3.5 INDUSTRIAL DMZ

Brokered exchange between IT and OT

Jump hosts, remote-access broker, patch and AV relays, historian replication, secure file transfer, update repositories.

SECURITY FOCUS

MFA, session recording, dual firewalls, malware screening, proxy services.

South firewall  ↓  Default deny, protocol and destination control
L3 SITE OPERATIONS

Operations management systems

Plant historian, OT application servers, engineering support, domain services, backup, OT monitoring and management.

SECURITY FOCUS

Dedicated OT identity, backup validation, passive monitoring, administrative separation.

Area conduits  ↓  Only required industrial protocols
L2 SUPERVISORY

Area and unit supervision

HMI, SCADA servers, operator stations, batch and alarm servers, local engineering workstations.

SECURITY FOCUS

Hardened baselines, least privilege, application control, controlled engineering access.

Control networks  ↓  Deterministic communication, strict change control
L1 BASIC CONTROL

Control and protection devices

PLC, DCS controllers, RTU, IED, protection relays, SIS/ESD logic solvers.

SECURITY FOCUS

Logic integrity, signed firmware where supported, configuration backup, physical access.

I/O and field buses  ↓  Safety and process signals
L0 PHYSICAL PROCESS

The process being protected

Sensors, analyzers, actuators, valves, drives, motors, production machinery and physical conditions.

SECURITY FOCUS

Safe state, tamper protection, calibration integrity, operational and safety procedures.

⚡

Remote & cloud access

Terminate through approved access services and the industrial DMZ, with time-bound authorisation and MFA. No direct IT-to-controller paths.

◈

Modern architectures

IIoT, edge, wireless and cloud can cross traditional levels. Engineer real zones and conduits from data flows — not from assumed layer boundaries.

⊛

Safety systems

SIS and ESD functions require independent assessment. Safety integrity must not be compromised by security controls or shared network paths.

From one facility to a stronger portfolio.

Start with a defined scope. Prove the controls in the operating environment. Then repeat what works across substations, plants and remote assets.


01

Discover

Agree critical assets, site constraints, regulatory scope and success measures.


02

Engineer

Develop the risk treatment plan, HLD / LLD and implementation sequence.


03

Validate

Test, commission and hand over with operations approval and evidence.


04

Sustain

Monitor, maintain, exercise recovery and expand through reusable site standards.

Partner with OEMs & Vendors.

NineTenths Company’s partnership approach connects industrial equipment manufacturers, security vendors, EPCs and asset owners.

Industrial Control Systems — OEMs & automation platforms

Siemens
Yokogawa-Logo
Schneider Electric Logo
Honeywell-Logo
ABB logo
Rockwell Automation Logo
Aveva logo

OT Cybersecurity — Security technology vendors

Nozomi Networks Logo
Drago
Fortinet-Logo
Xage Security
Phosphorus
forescout
Industrial Defender
XONA

How we work with technology partners

01 — Align the scope

Agree system boundaries and responsibilities.

02 — Validate together

Confirm interoperability and acceptance criteria.

03 — Sustain the solution

Define support ownership and lifecycle maintenance.

What is OT cybersecurity?

OT (Operational Technology) cybersecurity protects the industrial systems that run physical processes — PLCs, DCS, SCADA, SIS and similar control equipment — from cyber threats that could disrupt operations, safety or production continuity. Unlike IT security, it prioritizes availability and safety over confidentiality.

How is OT cybersecurity different from IT cybersecurity?

IT security focuses on protecting data confidentiality across enterprise networks, while OT security focuses on keeping physical processes running safely and reliably. OT environments often involve legacy equipment, real-time constraints and safety systems that require specialized, engineering-aware approaches rather than standard IT tools.

Does NineTenths help with NCA OTCC and ECC compliance in Saudi Arabia?

Yes. NineTenths maps applicable NCA ECC 2-2024 and OTCC-1:2022 requirements to each facility, conducts gap assessments, and supports accountable implementation with the evidence needed for compliance reporting.

How long does an OT cybersecurity risk assessment take?

Timelines vary by facility size, asset count and site access constraints, but a typical asset discovery and risk assessment engagement is scoped after an initial discovery phase that defines critical assets, site limitations and regulatory requirements.

Does NineTenths provide 24/7 OT security monitoring?

Yes, through its OT SOC & threat monitoring service. Coverage models — including any 24/7 monitoring — are agreed contractually based on the facility’s risk profile and operational requirements.

Which industries does NineTenths’ OT cybersecurity service cover?

NineTenths secures oil, gas & petrochemicals, power & substations, water & desalination, manufacturing, mining & minerals, renewables & infrastructure, and military & security facilities, tailoring scope to each sector’s equipment and operating model.