EOS Modus · How It Works

Structured Data In. Defensible Position Out.

EOS Modus is not a questionnaire wrapped in a web page. It is a data model of your operational technology estate, with a governance layer on top that answers whichever framework is in front of you.

The Shape Of It

Know, Assess, Govern, Prove

Four stages, in that order. Skipping the first one is the single most common reason OT compliance programmes stall.

01

Know

Populate the register. Assets, zones, conduits, data flows, remote access routes, third-party connections. Ground truth, held as data with an owner against every record.

02

Assess

Threat model against ATT&CK for ICS, match CVE and KEV advisories to what you actually own, raise risks against real assets, and map your controls once.

03

Govern

Run it as a management system. Policy, supply chain assurance, access reviews and change control keep the register true after go live.

04

Prove

Evidence attaches to controls. The audit pack, the CAF profile and the board report generate from live data rather than a six-week scramble.

Data Model

Built On The Purdue Model, Not Around It

OT estates are layered, and compliance frameworks care about the boundaries between those layers. Modus models the estate the way engineers already draw it, so an asset knows its level, its zone, its target security level, and every conduit it depends on.

That structure is what makes the mapping work. When a control is claimed at the IT/OT boundary, Modus knows which conduits it applies to and which assets sit behind it. When it does not apply, the gap is explicit rather than assumed.

Enterprise IT ERP, business systems, corporate identity Level 4 / 5 Industrial DMZ Historian replica, jump hosts, patch and AV relay Level 3.5 Operations & Control SCADA, historian, engineering workstations Level 3 Supervisory Control HMI, WTG controllers, substation automation Level 2 Basic Control & Process PLCs, protection relays, sensors and actuators Level 0 / 1 Conduits OEM remote access
Fig. 01, Estate structure. Every asset in M1 carries its level, zone and conduit set.
Why this matters

IEC 62443 is a standard, not a framework, and it is prescriptive about zones and conduits. NCSC CAF is outcome-based and asks whether you understand your estate at all. A platform that models the architecture can serve both. One that only stores answers to questions cannot.

Control Mapping

Evidence Once, Answer Everywhere

The single largest saving in EOS Modus is not automation, it is de-duplication. A control set maintained once, mapped to every framework that asks for it, removes most of the parallel effort in an OT compliance programme.

Without a single control set

  • Separate evidence gathered for CAF, NIS2, 62443 and any customer or insurer questionnaire
  • Four versions of the truth, drifting apart between audits
  • Findings that contradict each other, with no way to reconcile them
  • Consultants re-discovering the same estate every engagement
  • No trend, because each assessment starts from a different baseline

With EOS Modus

  • One control, one owner, one piece of evidence, many framework answers
  • Coverage and gaps visible per framework from the same underlying data
  • A change to the estate propagates to every framework view immediately
  • Assessment history retained, so you can show improvement over time
  • Your team holds the position, not an external party's laptop
Ownership

You Own The Data. That Is The Point.

ODiGE has spent nineteen years on the operator's side of the table in offshore wind OT and SCADA delivery. The pattern we keep seeing is an operator paying repeatedly to rediscover its own estate, because the last engagement left with the consultant.

EOS Modus is built the other way round. The register, the risks, the controls and the evidence are yours, exportable, and structured so they remain useful if you never speak to us again. We would rather earn the next piece of work than hold your data hostage to get it.

What that means in practice
  • Full data export, structured, at any time
  • No lock-in on the asset register
  • Your team as the system owner
  • Optional ODiGE support, not a mandatory retainer
  • No product resale or vendor kickbacks
  • Deployment options that suit your security position
Deployment

Three Ways To Run It

EOS Modus holds a detailed map of your OT estate, which makes it sensitive in its own right. The deployment model is a security decision, so it is yours to make.

Option A
Hosted By ODiGE
Managed tenancy, fastest to stand up.

A dedicated tenancy we operate and keep current. Suits operators who want the capability without adding to an internal platform backlog.

Option B
Your Cloud Tenancy
Deployed into your own subscription.

Runs inside your cloud estate under your identity provider, your logging and your data residency rules. ODiGE supports it, you own the boundary.

Option C
On Premise
For estates where nothing leaves the perimeter.

Air-gapped or internally hosted, for operators whose classification of OT architecture data rules out anything else. Discussed case by case.

A note on holding this data

A complete OT asset register, with firmware versions, remote access routes and known vulnerabilities, is exactly the document an attacker would most like to have. We treat that seriously, and we would expect you to interrogate it. Ask us the hard questions about tenancy separation, access control, logging, backup and what happens at the end of a contract. If the answers are not good enough, do not buy it.

See It Against Your Own Estate

The demo that lands is the one using your architecture, not a generic sample. Send us a redacted single line diagram or an asset list and we will show you what the register looks like populated.