New Security Standards on the Norwegian Continental Shelf: How to Integrate Security in Barrier Management 

Published Jul 27, 2026 | Last updated Jul 27, 2026

The Norwegian Continental Shelf operates at the frontier of safety management. Hard lessons from the Alexander L. Kielland, Bravo, and Piper Alpha incidents, and the maturation of barrier-based risk management, have made the NCS one of the most systematically safe operating environments in the world.

Now a new frontier is opening. Operational Technology (OT) cybersecurity is moving from the IT department into safety management. Regulatory developments in 2026 make this shift explicit on the Norwegian Continental Shelft (NCS). The first being Havtil’s 2026 Proposed Regulatory Amendments, and the second is the 7th revision of Offshore Norge Guideline 104.

This article explains what OT cybersecurity is, what has changed regulatorily, why it matters beyond the petroleum sector, and how a bowtie-based approach provides a practical and auditable framework for OT cybersecurity risk management.

Understanding OT Cyber Security

Toxic gas pipes and valves containing them

Operational Technology (OT) refers to the hardware and software that monitor and control physical processes.In the terms used by NIST SP 800-82, the reference guide for the field, this covers industrial control systems (ICS), Supervisory Control and Data Acquisition (SCADA), and safety instrumented systems. It also includes the programmable controllers, sensors, and actuators connected to physical equipment. On an offshore installation, these are the systems that open and close valves, manage pressure, monitor gas detection, and execute emergency shutdowns. What sets OT apart is that it acts on the physical world, so the consequences of compromise extend beyond data loss to equipment damage, environmental harm, and threats to life.

Safety is coupled to security. A compromised safety instrumented system is not just a data breach; it is the removal of the last automated defence against a major accident. The coupling runs both ways: an attack can defeat a safety function, and an ill-judged security response, such as taking a controller offline mid-operation, can itself trigger the incident it was meant to prevent. Security decisions in OT are also safety decisions. This reshapes the familiar priorities of confidentiality, integrity, and availability to the point where availability is no longer the priority. Some of the most serious industrial attacks on record, including Stuxnet and Triton, targeted system integrity: they caused systems to misrepresent their own state while continuing to run. The trustworthiness of the information operators base safety decisions on is as critical as uptime.

The installed base is long-lived and often unpatchable. OT assets routinely run for fifteen to twenty years or more, and many predate network connectivity as a design assumption. Standard IT practices can be actively harmful here: aggressive vulnerability scanning can crash fragile legacy controllers, and automated patching may be infeasible when a reboot halts production. The mature response is compensating controls: segmentation, monitoring, and access restriction that reduce risk without destabilising the process.

Convergence has expanded exposure. OT was historically protected by isolation. That separation has eroded through digitalisation: remote monitoring, vendor access, cloud analytics, and the integration of operational data with business systems have opened paths between the enterprise and the plant floor. The Purdue reference model and the zones-and-conduits approach of IEC 62443 exist to manage this, segmenting the environment so that a compromise of the enterprise network cannot propagate to the controllers governing the physical process.

IEC62443 Infographic

What Has Changed: Three Regulatory Developments on the NCS

Havtil’s 2026 Proposed Regulatory Amendments

Havtil, the Norwegian Ocean Industry Authority, has proposed amendments to the offshore HSE regulations that bring industrial ICT and OT systems explicitly into the existing safety management framework.

§59a – Maintenance programmes: For mapping and protecting an installation’s industrial ICT systems, Offshore Norge Guideline 104 should be used. Protective measures should be designed to holistically reduce the risk of, and damage from, digital attacks and cyber incidents, and to ensure the rapid restoration of an adequate security level. This means OT software and components should be assessed and followed up with the same rigour as other systems critical to safe and robust operations. Maintenance of a SCADA system or a distributed control system is no longer treated as purely an IT matter. It is now also a matter of safety.

§21 – Competence and §23 – Training and Exercises: The amendments similarly recommend that Guideline 104, specifically CSBR 10, serve as the basis for competence and training requirements for industrial ICT systems. This recognises that OT cybersecurity requires specialist expertise, and that this competence should be managed and exercised in the same way as other safety-critical competencies.

Offshore Norge Guideline 104, Revision 7 (June 2026)

Simultaneously, Offshore Norge has published Revision 7 of Guideline 104, the industry’s recommended baseline for OT cybersecurity on the NCS. The guideline defines 21 Cyber Security Baseline Requirements (CSBRs), covering the full lifecycle of OT cyber risk management: from governance and supply chain risk through network segmentation, vulnerability management, identity and access controls, secure remote access, incident response, and backup and restore capability.

Guideline 104 is a recommended practice. But with the Havtil amendments referencing it directly as the recommended framework for regulatory compliance in OT cybersecurity, it has become the de facto technical baseline against which supervisory expectations will be assessed.

The Broader Strategic Shift

Beyond the specific regulatory changes, a broader strategic shift is underway. Norway’s national security posture has changed fundamentally since Russia’s invasion of Ukraine in 2022. The sabotage of the Nord Stream pipelines demonstrated that energy infrastructure is a credible target for state-sponsored attack. Norway is now Europe’s largest gas supplier, and the Norwegian Continental Shelf carries strategic importance far beyond its commercial value.

Four instruments have formalised this shift.

Sikkerhetsloven (the National Security Act, in force since 2019) has been extended to Equinor and Gassco by ministerial decision. Gas transport to Europe is designated a Fundamental National Function. Havtil conducted its first formal Sikkerhetsloven audits in 2025. The act creates legally binding obligations around documented risk management, vulnerability analysis, and auditable evidence of ongoing security measures. Unlike Guideline 104, Sikkerhetsloven is not a recommendation. It is enforceable law.

Nasjonal Sikkerhetsstrategi, Norway’s first national security strategy, published in May 2025, explicitly states that the business sector has capacity and expertise relevant to national defence, and that steps will be taken to involve such actors more closely in preparedness efforts and emergency planning.

Totalberedskapsmeldingen (the Total Preparedness White Paper, January 2025) contains over 100 measures to strengthen civilian resilience, including requirements for documented backup solutions, tested restoration capacity, and mandatory preparedness exercises across critical sectors.

Digitalsikkerhetsloven (the Digital Security Act) entered into force on 1 October 2025, implementing the EU’s NIS1 Directive into Norwegian law. It obliges providers of essential services across seven sectors, including energy, to register with NSM, document their risk assessments, implement proportionate security measures, and notify of serious digital incidents, with responsibility explicitly placed on top management.

Its scope, however, is instructive. The continental shelf falls outside the act’s geographic reach, so it does not apply to Norwegian upstream petroleum activity. This is a structural feature of how Norway regulates rather than an oversight, and it explains why the Havtil amendments matter: where the general digital security regime does not reach the shelf, sector regulation does. The gap is also expected to close. Upstream petroleum is anticipated to fall within the digital security regime in time, and the EU has already moved beyond NIS1 to NIS2, which widens both the sectors covered and the obligations imposed, and introduces considerably stronger enforcement powers. NIS2 is not yet incorporated into the EEA Agreement, but preparatory work towards Norwegian implementation is underway.

The combined message is clear: security is no longer purely an internal requirement. It is subject to external audit, regulatory enforcement, and national scrutiny. Operators need to be able to demonstrate their security posture, not just maintain it internally. Those who treat today’s requirements as a floor rather than a ceiling will be the ones prepared for what follows.

Barrier Management on the NCS

The question, then, is how to integrate these regulatory changes. The answer is already sitting in the operator’s barrier management system.

Barrier management is the operating model through which the Norwegian petroleum industry manages major accident risk. The Framework Regulations require that the operator establish a barrier strategy, define the performance requirements each barrier must meet, and ensure that personnel know which barriers are not functioning or have been impaired. Barriers must be sufficient in number and sufficiently independent of one another.

A barrier, in this framework, is never a single object. It is a barrier function, delivered by barrier elements falling into three categories:

Technical elements, such as the system, sensor, or device

Operational elements, the procedure or action required

Organisational elements, the competence, manning, and governance that ensure the other two are in place and working

The function is only realised when all three act in concert. A pressure sensor is only effective if the correct action is taken by a competent and appropriately resourced team. Any of the three can degrade, and when one does, the barrier degrades with it.

This is where the model becomes demanding in practice. A barrier strategy documented once cannot answer the question that matters to the person on shift: which of my barriers are impaired right now? A maintenance backlog on a safety-critical valve, an expired competence certification, an inhibit that has been in place longer than intended, a deferred function test. Each of these degrades a barrier function, and each of them lives in a different source system.

Continuous barrier monitoring

The response, developed on the NCS over the past fifteen years, has been the move from static barrier documentation to continuous barrier monitoring. The principle is straightforward: connect each barrier element to a live indicator drawn from the systems that already hold the data, and surface the aggregate status where decisions are made. Presight Barrier Management was built for exactly this. It draws on the design basis, the bowties, barrier strategies, and performance standards, and then pulls live data from the maintenance system, the inhibit log, the permit-to-work system, deviation records, and HR and competence systems, whether directly or through a data lake. The result is a single view in which the OIM, the HSE manager, or the operations supervisor can see whether the barriers defending each major accident hazard are in the state assumed by the design, drill down to the specific degraded element, and act before an event rather than explain after one.

The controls described in Guideline 104 can also be seen as barrier elements. Network segmentation is a technical element. A patch management procedure is an operational element. OT cyber competence is an organisational element. They degrade in the same way other barrier elements degrade: a patch missed past its window, a vendor access session outside governed parameters, an exercise not conducted on schedule. And, like other barrier elements, their status can be monitored, indicated, and made visible in the same risk picture the organisation already trusts.

What is required to get there is a structure that connects specific cyber threats to the barriers defending against them, and to the consequences that follow if those barriers fail. That structure is the bowtie.

The Bowtie Method

Visualisation of the bowtie methodology

A bowtie diagram visualises the relationship between threats, a central unwanted event (the top event), and the consequences that follow if the top event is not controlled. The diagram is shaped like a bow-tie: threats and preventive barriers on the left, the top event in the centre, consequences and mitigating (recovery) barriers on the right.

In Norwegian petroleum regulation, a top event corresponds closely to what is commonly referred to as a Defined Hazard and Accident Situation (DFU or DSHA) on the NCS. It is a named, observable scenario that the operator’s emergency preparedness and barrier strategy is designed to defend against. For more on DFUs and how they relate to bowtie methodology on the NCS, see our article: Defined Hazard and Accident Situations (DFU/DSHA): How Norway Manages Major-Accident Risk in Offshore Oil and Gas.

The barriers on either side of the diagram are the barrier functions described above, each delivered by its technical, operational, and organisational elements. The bowtie’s contribution is to show which barriers defend against which threat, and which consequences remain if a barrier fails.

For a full introduction to the bowtie method, see our article: What is a bowtie model and analysis, and why use it as part of your risk management approach?

From CSBR to Barrier: A Practical Framework

Offshore Norge Guideline 104 defines 21 Cyber Security Baseline Requirements. These CSBRs are, in effect, a set of security barrier elements. Each one is a control that either prevents a cyber threat from reaching an OT system or mitigates the consequences if it does.

The four bowties below are designed so that an operator who actively manages all barriers within them, with documented performance standards and live indicators, would be well positioned to demonstrate alignment with both Guideline 104 (Revision 7, June 2026) and the intent of the proposed Havtil 2026 regulatory amendments. For operators outside the NCS context, the same bowties provide a structured starting point grounded in industry-leading practice, adaptable to other regulatory frameworks, including NIS2 and sector-specific guidance.

Each bowtie can be opened, inspected, and copied from the OpenRisk public collection. You can adapt them to your specific installation, add plant-specific barrier elements, and connect them to live data from your OT monitoring systems, CMMS, and incident management systems.

Bowtie 1: Cyber Attack on OT/Control Systems

Top event: Unauthorised access to or compromise of OT control systems

This is the primary pathway. A threat actor gains access to the industrial control systems that govern safety-critical processes on the facility.

Threats and preventive barriers (left side):

Phishing and social engineering are addressed by personnel training and awareness (CSBR 10) and an acceptable use policy (CSBR 4). Unpatched software vulnerabilities are controlled through a vulnerability and patch management programme (CSBR 7) and a maintained hardware and software inventory (CSBR 5). Unauthorised remote access is prevented by secure remote access controls, including multi-factor authentication and jump servers (CSBR 13), and identity and account management on a least-privilege basis (CSBR 14). Lateral movement from IT into OT networks is blocked by network segmentation (CSBR 11) and an OT DMZ (CSBR 12). Supply chain and vendor compromise is addressed through supply chain risk management (CSBR 3) and governed vendor access controls (CSBR 13). Infected removable media and unauthorised physical access are mitigated by endpoint hardening (CSBR 15) and malicious software protection (CSBR 16). Misconfiguration and unauthorised change are controlled through change management (CSBR 8) and OT operation and maintenance procedures (CSBR 9).

Consequences and mitigating barriers (right side):

If the top event occurs, the recovery barriers are security monitoring and alerting to detect anomalous behaviour (CSBR 18), an activated incident response plan (CSBR 19), emergency preparedness plans for cyber and digital attacks (CSBR 19, §66 and §76 of the Havtil amendments), island mode capability allowing independent operation (CSBR 20), manual override and fallback operating procedures (CSBR 9), and backup and restore capability with tested, offline backups (CSBR 21).

Overarching escalation factor: Lack of competence in OT cybersecurity degrades all barriers simultaneously. This is addressed by the training and competence programme (CSBR 10), recommended under §21 and §23 of the proposed Havtil amendments.

Bowtie 2: Cyber-Induced Barrier Degradation

Top event: Safety-critical barrier status is unknown or misrepresented due to ICT/OT compromise

This is arguably the most important bowtie for a safety audience, because it captures the scenario that process safety professionals find most unsettling: a cyber incident that does not announce itself with an alarm or a visible failure, but silently and systematically corrupts the information the operator relies on to know whether their barriers are functioning.

A corrupted Computerised Maintenance Management System (CMMS) means that maintenance tasks appear as complete when they have not been carried out. A compromised inhibit log means that defeated safety functions are not visible to the control room. A falsified permit-to-work record means that isolation is believed to be in place when it is not. In each case, the operator believes the barriers are healthy. They are not.

This scenario connects directly to the concept of barrier knowledge quality: the degree to which an operator can actually trust the information underpinning their risk picture. It is also the scenario in which a live, independently monitored barrier management system is most valuable. The same problem exists in any industrial context where safety-critical data is managed digitally. If the data can be corrupted, the risk picture can be corrupted.

Threats and preventive barriers (left side):

Corruption or falsification of CMMS and maintenance data is addressed by ensuring the CMMS is within the scope of OT cyber governance (CSBR 5) and by applying change management controls to safety-critical monitoring systems (CSBR 8). Ransomware encrypting operational data is mitigated by malicious software protection (CSBR 16) and regularly tested, offline backups of safety-critical data (CSBR 21). A compromised inhibit, or isolation log, is controlled through identity and account management, restricting who can modify safety records (CSBR 14), and through security hardening of systems that hold safety-critical data (CSBR 15). Unauthorised configuration changes to monitoring systems are addressed through change management (CSBR 8) and maintained network topology drawings (CSBR 6). The compromise of monitoring software in the supply chain is addressed by supply chain risk management (CSBR 3).

Consequences and mitigating barriers (right side):

Security monitoring and alerting to detect data anomalies and integrity issues (CSBR 18) and independent manual inspection and verification of barrier status (CSBR 9) address undetected degraded barriers. If a major accident event occurs with failed mitigation, the incident response plan (CSBR 19) and island mode (CSBR 20) provide recovery capability. Regulatory non-conformity under §17 risk analysis requirements is addressed through the ongoing cybersecurity risk management process (CSBR 2) and an OT security policy governing data integrity (CSBR 1).

Bowtie 3: Ransomware Attack on Offshore Operations Technology

Top event: Ransomware encryption of OT/business systems causing loss of operational capability

Ransomware has become the dominant threat vector for industrial operators globally. Unlike a targeted intrusion, ransomware does not require a sophisticated actor. It spreads opportunistically, encrypts whatever it reaches, and presents operators with an immediate and highly visible operational crisis. For an offshore facility, loss of the permit-to-work system, the CMMS, or the control room monitoring platform creates an immediate safety management problem, not just an IT inconvenience. The same is true for any industrial operator: a manufacturing plant that loses its production control system or a power generator that loses its SCADA platform faces safety and operational consequences that extend far beyond a data breach.

Threats and preventive barriers (left side):

Phishing leading to malware execution is addressed by personnel training (CSBR 10), acceptable use policy (CSBR 4), and endpoint malicious software protection (CSBR 16). Vulnerable internet-facing systems are controlled through vulnerability and patch management (CSBR 7) and security hardening (CSBR 15). Lateral movement from IT to OT is blocked by network segmentation (CSBR 11) and the OT DMZ (CSBR 12). Compromised vendor or contractor remote access is addressed through secure remote access controls (CSBR 13) and supply chain risk management (CSBR 3).

Consequences and mitigating barriers (right side):

Loss of situational awareness, with monitoring and dashboards offline, is addressed by island mode (CSBR 20) and manual fallback procedures (CSBR 9). The inability to process permits to work is addressed by the incident response plan, prioritising the restoration of safety-critical systems (CSBR 19) and backup and restore for permit and safety management systems (CSBR 21). Disruption to safety-critical maintenance scheduling is addressed by CMMS data recovery (CSBR 21) and early detection through security monitoring and alerting (CSBR 18). Extended production shutdown and escalation risk are addressed by the emergency preparedness plan for digital and cyber incidents (CSBR 19, §66 and §76 of the Havtil amendments) and crisis communications procedures (CSBR 19).

Bowtie 4: Supply Chain and Vendor Access Compromise

Top event: Unauthorised access to OT systems via a third-party vendor or supply chain compromise

The supply chain pathway deserves its own bowtie because the threat profile and available controls differ from a direct external attack. On the NCS, operators rely on a broad ecosystem of vendors for remote access to control systems, software maintenance, and operational support. Each of those connections is a potential entry point. NSM (the National Security Authority) has explicitly identified supply chain risk as one of the most significant threat vectors for Norwegian critical infrastructure. This is not a problem unique to petroleum. The 2020 SolarWinds attack, in which a software update from a trusted vendor was used to gain access to thousands of organisations worldwide, including critical infrastructure operators, demonstrated that the supply chain is one of the most powerful attack vectors available to sophisticated threat actors.

Threats and preventive barriers (left side):

A compromised software update from a trusted vendor is addressed through supply chain risk management (CSBR 3) and a hardware and software inventory that captures all third-party software within the OT environment (CSBR 5). Malicious or negligent vendor remote access is controlled by secure remote access controls with multi-factor authentication and session monitoring (CSBR 13), identity and account management on a least-privilege and time-limited basis (CSBR 14), and security hardening of remote access systems (CSBR 15). Vulnerable third-party components within OT systems are addressed through vulnerability and patch management that covers all software in inventory (CSBR 7) and a change management process that requires review of third-party changes (CSBR 8). Lateral movement from vendor access into broader OT systems is blocked by network segmentation (CSBR 11) and OT DMZ controls (CSBR 12). Vendor personnel with insufficient cybersecurity competence are addressed through training and competence requirements extended to vendors (CSBR 10), as well as acceptable use policies governing vendor access (CSBR 4).

Consequences and mitigating barriers (right side):

Security monitoring and alerting to detect anomalous vendor session behaviour (CSBR 18), and incident response plans covering third-party compromise scenarios (CSBR 19), address the immediate need for response. Backup and restore capability ensures recovery from supply chain-delivered malware or ransomware (CSBR 21). Island mode allows severing vendor connectivity and operating independently during an active incident (CSBR 20). The ongoing cybersecurity risk management process (CSBR 2) and a security policy governing third-party access (CSBR 1) address longer-term governance and regulatory non-conformity risk under §17 of the Havtil amendments.

The Compliance Mapping

The table below shows how the 21 CSBRs from Offshore Norge Guideline 104 and the key requirements from the Havtil 2026 amendments map across all four bowties.

RequirementBowtie 1Bowtie 2Bowtie 3Bowtie 4
CSBR 1 – Security policy
CSBR 2 – Cybersecurity risk management
CSBR 3 – Supply chain risk management
CSBR 4 – Acceptable use policy
CSBR 5 – Hardware and software inventory
CSBR 6 – Network topology drawings
CSBR 7 – Vulnerability and patch management
CSBR 8 – Change management
CSBR 9 – Operation and maintenance procedures
CSBR 10 – Training and competence
CSBR 11 – Network segmentation
CSBR 12 – OT DMZ
CSBR 13 – Secure remote access
CSBR 14 – Identity and account management
CSBR 15 – Security hardening
CSBR 16 – Malicious software protection
CSBR 17 – Virtualisation
CSBR 18 – Security monitoring and alerting
CSBR 19 – Incident response
CSBR 20 – Island mode
CSBR 21 – Backup and restore
§17 Risk analysis – ICT measures
§21 Competence / §23 Training and Exercises
§66 and §76 Emergency preparedness plans

From Framework to Live Risk Picture

Defining a set of bowties is the starting point. It scopes the risk management system and makes cyber threats visible in the same framework as physical and operational hazards. But the real value comes from what happens next.

In the Norwegian regulatory framework, each barrier element falls into one of three categories: Technical (the system or device), Operational (the procedure or action), and Organisational (the competence and governance structure). A barrier is only realised when all three work in concert. A network segmentation control is only effective if it is correctly configured, maintained by competent personnel, and covered by a governance process that ensures it is reviewed and tested regularly. This principle holds equally for any industrial operator, regardless of sector or regulatory context.

For each barrier in these bowties, operators can define performance standards: the criteria that determine whether the barrier is functioning as the design assumed. Those performance standards can then be connected to live indicators: maintenance records from the CMMS, access logs from remote access systems, outputs from security monitoring platforms, exercise completion records, and patch status reports.

With Presight Barrier Management, all of these elements can be tracked in a single view. Decision-makers, the OIM, the HSE manager, and the operations supervisor can see in real time whether the cyber barriers defending each bowtie top event are actually in the state assumed by the design.

Example of a live bowtie within Presight Barrier Monitoring
Example of a live bowtie within Presight Barrier Monitoring

This is the direction the regulatory landscape is pointing towards, on the NCS and beyond. An operator who actively manages their OT cyber barriers, with live indicators and documented performance standards, is doing exactly what Guideline 104 recommends, what the Havtil amendments signal, and what Sikkerhetsloven already requires for those in scope.

Getting Started

All four bowties are available as free public templates in Presight OpenRisk. You can open them, inspect the threats, consequences, and barriers, and copy any of them into your own workspace to add installation-specific barrier elements, performance standards, and metadata.

If you want to connect those bowties to live operational data and build a real-time barrier risk picture across your OT cybersecurity framework, book a demo with Presight Barrier Management.

References

Havtil (2026). Proposed amendments to the offshore HSE regulations, endringsforskrift 2026. Havindustritilsynet, Stavanger.

Offshore Norge (2026). Guideline 104: Recommended Guidelines for Cyber Security Baseline Requirements for Industrial ICT Systems, Revision 7, June 2026.

Havtil (2026). Risikonivå i norsk petroleumsvirksomhet, Hovedrapport, utviklingstrekk 2025, norsk sokkel. Havindustritilsynet, Stavanger, 25 March 2026.

Havtil. Management Regulations, §17: Risk analysis. Available at: https://www.havtil.no/en/regulations/

Havtil. Management Regulations, §5: Barriers. Available at: https://www.havtil.no/en/regulations/

Norwegian Government (2025). Nasjonal Sikkerhetsstrategi. Office of the Prime Minister, Oslo, May 2025.

Norwegian Government (2025). Totalberedskapsmeldingen, Meld. St. 9 (2024–2025): Forberedt på krise og krig. Ministry of Justice and Public Security, Oslo, January 2025.

Lov om nasjonal sikkerhet (sikkerhetsloven), Lov 1. juni 2018 nr. 24. In force 1 January 2019.

Lov om digital sikkerhet (digitalsikkerhetsloven). In force 1 October 2025. Implements Directive (EU) 2016/1148 (NIS1) into Norwegian law.

de Ruijter, A., and Guldenmund, F. (2016). The bowtie method: A review. Safety Science, 88, 211–218.

Larouzee, J., and Le Coze, J.-C. (2020). Good and bad reasons: The Swiss cheese model and its critics. Safety Science, 126, 104660.

NSM (2025). Risiko 2025: Nasjonal sikkerhet, et felles ansvar. Nasjonal Sikkerhetsmyndighet, Oslo.

European Union (2016). Directive (EU) 2016/1148 concerning measures for a high common level of security of network and information systems across the Union (NIS1 Directive). Official Journal of the European Union.

European Union (2022). Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive). Official Journal of the European Union. Not yet incorporated into the EEA Agreement.

NIST (2023). SP 800-82 Revision 3: Guide to Operational Technology (OT) Security. National Institute of Standards and Technology, Gaithersburg, MD.

International Electrotechnical Commission. IEC 62443 series: Security for industrial automation and control systems. Geneva.

About the Author

Book a demo with us!

Interested in finding out more about Presight Solutions and how we can make your operations safer and more efficient?

Click the button and we will together find out more about your needs and the right solution for you.

Contact Us Today for More!

We are here to help you make your operations sager and more efficient!
Click Here