Security for industrial control systems, written for the people who run them.
F Creative Studio 360 reviews PLCs, SCADA, historians and the paths into them for operators in any country. Safety systems stay out of scope unless a qualified engineer is part of the work and the change is written down.
A controller is not a server.
NIST SP 800-82 describes how to secure operational technology without treating it as office IT. IEC 62443 is the series many asset owners measure against. Neither document is a certificate F Creative Studio 360 can issue.
The default is a review of architecture, access and known exposure. We do not modify a safety instrumented system as part of a standard engagement.
- Safety is a boundary
- If a change could affect a safety function, it is out of scope until the right engineer agrees it in writing.
- Passive first
- Inventories and traffic are preferred to probes against a live controller.
- Engineering workstations
- The laptop that programs the controller is often the practical way in.
- Vendors remain in the picture
- Remote support accounts are named, not waved through.
What can be in scope
The lines and systems you list.
- Controllers and SCADA
- What is installed, how it is reached, and how it is changed.
- Historians and links
- The path from the plant into corporate reporting.
- Engineering access
- Who can program a controller, and from which machine.
- Known exposure
- Published vulnerabilities that can be mitigated without a reckless patch.
How an engagement runs
Each site has its own operational window, in whatever country it sits.
- 1
Name the systems
Including what is safety-related and therefore out of scope.
- 2
Read the architecture
With the operations team, not against them.
- 3
Write mitigations that operations can accept
Segmentation and access before a patch that the vendor has not approved.
- 4
Leave the change controlled
Implementation follows the plant’s change process.
What you receive
- An architecture note for the systems in scope.
- Access and remote-support findings.
- Mitigations that respect safety boundaries.
- No claim of IEC 62443 certification, and no change to a safety system by default.
The network around the controller
Zones, remote access and plant-wide visibility are on the OT security page. This page stays with the control systems.
Common questions
Will you patch our PLCs?+
Not as a default, and not where the vendor or a safety case forbids it. We identify exposure and the controls that do not require an unapproved change.
Do you only do this in one country?+
No. Plants in any country can be in scope. A local critical-infrastructure duty is added only when that site is subject to it.
Where do you deliver this?+
For organisations in any country. A local rule is used only when that organisation is actually subject to it. F Creative Studio 360 does not limit the work to one jurisdiction.
How much does it cost, and how long does it take?+
It depends on the systems in scope and whether you want an assessment only or help afterwards. A scoping conversation with F Creative Studio 360 is the way to get a quote. There is no obligation to proceed.
Name the controllers before anyone connects.
F Creative Studio 360 will look at the systems and the safety boundaries, then say what the review includes.
