Enterprise AI, cybersecurity, cloud and software for organizations worldwide.
Manufacturing

Security for industrial control systems, written for the people who run them.

F Creative Studio 360 reviews PLCs, SCADA, historians and the paths into them for operators in any country. Safety systems stay out of scope unless a qualified engineer is part of the work and the change is written down.

A controller is not a server.

NIST SP 800-82 describes how to secure operational technology without treating it as office IT. IEC 62443 is the series many asset owners measure against. Neither document is a certificate F Creative Studio 360 can issue.

The default is a review of architecture, access and known exposure. We do not modify a safety instrumented system as part of a standard engagement.

Safety is a boundary
If a change could affect a safety function, it is out of scope until the right engineer agrees it in writing.
Passive first
Inventories and traffic are preferred to probes against a live controller.
Engineering workstations
The laptop that programs the controller is often the practical way in.
Vendors remain in the picture
Remote support accounts are named, not waved through.

What can be in scope

The lines and systems you list.

Controllers and SCADA
What is installed, how it is reached, and how it is changed.
Historians and links
The path from the plant into corporate reporting.
Engineering access
Who can program a controller, and from which machine.
Known exposure
Published vulnerabilities that can be mitigated without a reckless patch.

How an engagement runs

Each site has its own operational window, in whatever country it sits.

  1. 1

    Name the systems

    Including what is safety-related and therefore out of scope.

  2. 2

    Read the architecture

    With the operations team, not against them.

  3. 3

    Write mitigations that operations can accept

    Segmentation and access before a patch that the vendor has not approved.

  4. 4

    Leave the change controlled

    Implementation follows the plant’s change process.

What you receive

  • An architecture note for the systems in scope.
  • Access and remote-support findings.
  • Mitigations that respect safety boundaries.
  • No claim of IEC 62443 certification, and no change to a safety system by default.

The network around the controller

Zones, remote access and plant-wide visibility are on the OT security page. This page stays with the control systems.

Common questions

Will you patch our PLCs?+

Not as a default, and not where the vendor or a safety case forbids it. We identify exposure and the controls that do not require an unapproved change.

Do you only do this in one country?+

No. Plants in any country can be in scope. A local critical-infrastructure duty is added only when that site is subject to it.

Where do you deliver this?+

For organisations in any country. A local rule is used only when that organisation is actually subject to it. F Creative Studio 360 does not limit the work to one jurisdiction.

How much does it cost, and how long does it take?+

It depends on the systems in scope and whether you want an assessment only or help afterwards. A scoping conversation with F Creative Studio 360 is the way to get a quote. There is no obligation to proceed.

Name the controllers before anyone connects.

F Creative Studio 360 will look at the systems and the safety boundaries, then say what the review includes.