OT cyber security governance - simplify the complex

The regulation keeps changing - the threat keeps growing

Your estate still has to run. EOS Modus documents the complex and keeps the evidence a regulator can rely on.

CAF CSRBill NCSC-NL BSIGermany RDI NCSC UKOperator NIS2018 CRE EUOperator NIS2 DESNZ Ofgem ISO27001 ANSSI BNetzA CyFun MITREATT&CK IEC62443 CCB
United Kingdom European Union Operator obligations Standards and catalogues Regulation in force

Our approach - four cornerstones

You won’t find these four in a standard. They are our interpretation, built from assessing OT estates for a living, and everything else stands on them.

Accountable

Control measures only work when they’re being used

Proof your controls are actually used.

Policies, processes and procedures are the control measures everyone recognises.

They only count when they are documented, implemented, operational, monitored and managed, each with a named owner and evidence at every step.

Known

You can only protect what you know

Proof you know what you own.

Sites, zones, conduits, assets and data flows, identified once and held as the spine of the estate.

Firmware, versions, patch status and change control sit against each asset, because CVE and vulnerability management is only ever as good as the register underneath it.

Secure by design

Zones and conduits carry the risk

Proof the estate can contain an attack.

IEC 62443 zones and conduits are where the risk numbers live: security-level targets per zone, every boundary crossing visible, and exposure judged against your organisation’s appetite for risk.

Architecture, asset register and risk profile are one connected model.

Aware

Risk raised by the system, not by hand

Proof your risk moved when the estate did.

The platform raises risk from what it holds: a change to an asset or to the organisation, an ingested CVE, a vulnerability finding, cross-referenced against the MITRE ATT&CK catalogue.

Nobody types a risk register into a spreadsheet once a year any more.

The risk engine - risk is derived, never hand-typed

Most GRC tools are forms over a database, and their risk registers go stale the week after the workshop. EOS Modus computes risk from the estate model itself.

Step one

Facts, ingested and kept current

Qualitative and quantitative, off the same facts.

Risk assessment, qualitative and quantitative, only works on facts.

Assets, access paths, backups, certificates and data flows are ingested and onboarded during baselining, then kept current. The platform reviews them on a schedule, and the operator can change anything it holds.

Step two

A rule is the automated test of a control

The mandate says it. The rule checks it.

MANDATEENGINEERINGOPERATIONSR-01R-02R-03R-04

The mandate says what must be true. The control makes it true. The rule continuously checks that it is.

Rules arrive by three routes: derived from a mandate, from engineering and technology, or from operational lessons.

Step three

Risk is derived, never hand-entered

Every item traceable to what caused it.

213172IMPACTLIKELIHOOD

Nothing on the risk register is typed in by hand. Every item is derived by the risk engine from the weaknesses the registers, the rules and the facts expose.

Scored 5×5, with residual risk taken through the compensating controls and a line back to whatever caused it.

Multi-framework - one body of evidence

CAF, NIST CSF 2.0, NIS2, a national scheme or your own internal framework. Do the work once and answer them all, because switching lens re-maps the view without touching the record.

United Kingdom

NCSC CAF

National Cyber Security Centre · Cyber Assessment Framework

4 objectives · 14 principles · 41 outcomes

Version 4.0, the framework UK energy regulators work to under the NIS Regulations.

Each outcome is judged against its indicators of good practice, and every judgement needs an owner, a date and evidence.

International

NIST CSF 2.0

National Institute of Standards and Technology · Cyber Security Framework

6 functions · 22 categories · 106 subcategories

The most widely used framework in the world, and the common language of group security, insurers and international audits.

Version 2.0 added Govern as a sixth function, putting oversight on the same footing as the technical work.

Belgium and Ireland

CyFun 2025

Cyber Fundamentals

6 functions · 3 levels · 218 requirements

The CyberFundamentals framework from the Centre for Cybersecurity Belgium, co-owned with Ireland’s NCSC.

Re-based on the six NIST CSF 2.0 functions, and mapped by the CCB to ISO/IEC 27001, CIS Controls and IEC 62443.

France

ANSSI (ICS)

Agence nationale de la sécurité des systèmes d’information

4 classes C1–C4 · 77 recommendations

France’s Cybersecurity for Industrial Control Systems guides, both reissued in 2025.

Classify the system, then apply the measures for its class. Annex A maps them to IEC 62443, which ANSSI is clear it does not replace.

Human-led - AI-assisted

The agent does the donkey work of reading and mapping. Every compliance judgement stays with a named human, and the two are permanently distinguishable in the record.

Human sovereign

People score. Machines never do.

A machine’s score is one an auditor discounts.

345SIGNED & DATED

The system never generates or suggests a compliance score. Scores are set by a named accountable person and recorded forever.

That is exactly what makes them defensible in front of a regulator.

Honest by design

Gaps render red.

Absence of data is a finding, not silence.

Missing owners, unreviewed controls and unassessed outcomes show as visible findings, not blank cells.

A platform that shows its own holes honestly is the one whose greens you can believe.

Evidenced

The audit trail is the database.

Who, when and why, by construction.

WHO · WHEN · WHYWHO · WHEN · WHYWHO · WHEN · WHYWHO · WHEN · WHY

Every judgement is an append-only event carrying its actor, its timestamp and its rationale.

History isn’t a report the platform writes, it’s the way the platform stores everything.

In development

AI does the donkey work.

The agent suggests. The assessor decides.

AI

An assisted mapping agent reads your documents and proposes framework mappings from a closed list, every suggestion carrying its supporting passage.

The platform records both, permanently and separately.

Engaging with ODiGE - consultancy first, platform included

EOS Modus isn’t a licence you buy and run alone. It comes with the practitioners who built it, people who assess OT estates for a living.

Step one

We get you to your first milestone

Baselined, on your infrastructure or ours.

STARTPOPULATEBASELINE3 TO 6 MONTHS

The first milestone is usually a date: an audit, a submission, a position you need to defend.

We engage with you to populate the system and baseline it against that date, on your own infrastructure or hosted by us on a secure architecture. Depending on your estate, that could be three to six months.

Step two

The governance is yours to own

You are the owner. The regulation points at you.

HANDOVERYOURS

Let us be clear about this. It is your estate, your system and your governance. The regulation is pointing at you, not at us.

We help you govern your assets. At handover the register, the evidence, the derived risk and the controls are yours to run, with named owners in place and the audit trail already accumulating.

Step three

Three ways to continue

No lock-in. Pick the level of help you want.

REMAINSNAPSHOTCONTINUE

After the initial engagement, whether it ended in an audit or just the baseline you needed internally, you have three options.

Remain as you are. Take an exported snapshot of your position at that date. Or keep going, with platform support while your team runs it, ODiGE consultancy on a monthly agreement, or both.

Contact - let’s talk OT cyber security governance

Re-baselining against CAF, working out what the new regime means for you, or building an asset register that survives contact with reality. We would like to hear from you.

We use what you send us to answer your enquiry and nothing else. No mailing list, no onward sharing.

Governance maintained continuously beats governance reconstructed annually.

See EOS Modus on your own estate, and what it takes to stand your compliance position up properly.

Request a demo