The regulation keeps changing - the threat keeps growing
Your estate still has to run. EOS Modus documents the complex and keeps the evidence a regulator can rely on.
Our approach - four cornerstones
You won’t find these four in a standard. They are our interpretation, built from assessing OT estates for a living, and everything else stands on them.
Control measures only work when they’re being used
Proof your controls are actually used.
Policies, processes and procedures are the control measures everyone recognises.
They only count when they are documented, implemented, operational, monitored and managed, each with a named owner and evidence at every step.
You can only protect what you know
Proof you know what you own.
Sites, zones, conduits, assets and data flows, identified once and held as the spine of the estate.
Firmware, versions, patch status and change control sit against each asset, because CVE and vulnerability management is only ever as good as the register underneath it.
Zones and conduits carry the risk
Proof the estate can contain an attack.
IEC 62443 zones and conduits are where the risk numbers live: security-level targets per zone, every boundary crossing visible, and exposure judged against your organisation’s appetite for risk.
Architecture, asset register and risk profile are one connected model.
Risk raised by the system, not by hand
Proof your risk moved when the estate did.
The platform raises risk from what it holds: a change to an asset or to the organisation, an ingested CVE, a vulnerability finding, cross-referenced against the MITRE ATT&CK catalogue.
Nobody types a risk register into a spreadsheet once a year any more.
The risk engine - risk is derived, never hand-typed
Most GRC tools are forms over a database, and their risk registers go stale the week after the workshop. EOS Modus computes risk from the estate model itself.
Facts, ingested and kept current
Qualitative and quantitative, off the same facts.
Risk assessment, qualitative and quantitative, only works on facts.
Assets, access paths, backups, certificates and data flows are ingested and onboarded during baselining, then kept current. The platform reviews them on a schedule, and the operator can change anything it holds.
A rule is the automated test of a control
The mandate says it. The rule checks it.
The mandate says what must be true. The control makes it true. The rule continuously checks that it is.
Rules arrive by three routes: derived from a mandate, from engineering and technology, or from operational lessons.
Risk is derived, never hand-entered
Every item traceable to what caused it.
Nothing on the risk register is typed in by hand. Every item is derived by the risk engine from the weaknesses the registers, the rules and the facts expose.
Scored 5×5, with residual risk taken through the compensating controls and a line back to whatever caused it.
Multi-framework - one body of evidence
CAF, NIST CSF 2.0, NIS2, a national scheme or your own internal framework. Do the work once and answer them all, because switching lens re-maps the view without touching the record.
NCSC CAF
4 objectives · 14 principles · 41 outcomes
Version 4.0, the framework UK energy regulators work to under the NIS Regulations.
Each outcome is judged against its indicators of good practice, and every judgement needs an owner, a date and evidence.
NIST CSF 2.0
6 functions · 22 categories · 106 subcategories
The most widely used framework in the world, and the common language of group security, insurers and international audits.
Version 2.0 added Govern as a sixth function, putting oversight on the same footing as the technical work.
CyFun 2025
6 functions · 3 levels · 218 requirements
The CyberFundamentals framework from the Centre for Cybersecurity Belgium, co-owned with Ireland’s NCSC.
Re-based on the six NIST CSF 2.0 functions, and mapped by the CCB to ISO/IEC 27001, CIS Controls and IEC 62443.
ANSSI (ICS)
4 classes C1–C4 · 77 recommendations
France’s Cybersecurity for Industrial Control Systems guides, both reissued in 2025.
Classify the system, then apply the measures for its class. Annex A maps them to IEC 62443, which ANSSI is clear it does not replace.
Human-led - AI-assisted
The agent does the donkey work of reading and mapping. Every compliance judgement stays with a named human, and the two are permanently distinguishable in the record.
People score. Machines never do.
A machine’s score is one an auditor discounts.
The system never generates or suggests a compliance score. Scores are set by a named accountable person and recorded forever.
That is exactly what makes them defensible in front of a regulator.
Gaps render red.
Absence of data is a finding, not silence.
Missing owners, unreviewed controls and unassessed outcomes show as visible findings, not blank cells.
A platform that shows its own holes honestly is the one whose greens you can believe.
The audit trail is the database.
Who, when and why, by construction.
Every judgement is an append-only event carrying its actor, its timestamp and its rationale.
History isn’t a report the platform writes, it’s the way the platform stores everything.
AI does the donkey work.
The agent suggests. The assessor decides.
An assisted mapping agent reads your documents and proposes framework mappings from a closed list, every suggestion carrying its supporting passage.
The platform records both, permanently and separately.
Engaging with ODiGE - consultancy first, platform included
EOS Modus isn’t a licence you buy and run alone. It comes with the practitioners who built it, people who assess OT estates for a living.
We get you to your first milestone
Baselined, on your infrastructure or ours.
The first milestone is usually a date: an audit, a submission, a position you need to defend.
We engage with you to populate the system and baseline it against that date, on your own infrastructure or hosted by us on a secure architecture. Depending on your estate, that could be three to six months.
The governance is yours to own
You are the owner. The regulation points at you.
Let us be clear about this. It is your estate, your system and your governance. The regulation is pointing at you, not at us.
We help you govern your assets. At handover the register, the evidence, the derived risk and the controls are yours to run, with named owners in place and the audit trail already accumulating.
Three ways to continue
No lock-in. Pick the level of help you want.
After the initial engagement, whether it ended in an audit or just the baseline you needed internally, you have three options.
Remain as you are. Take an exported snapshot of your position at that date. Or keep going, with platform support while your team runs it, ODiGE consultancy on a monthly agreement, or both.
Contact - let’s talk OT cyber security governance
Re-baselining against CAF, working out what the new regime means for you, or building an asset register that survives contact with reality. We would like to hear from you.
We use what you send us to answer your enquiry and nothing else. No mailing list, no onward sharing.