OT · ICS · AI Security Advisory
WindlassConsulting
Holding the line on critical infrastructure.
Operational technology, industrial control systems, and AI security advisory for pipeline, energy, and critical-infrastructure operators.
Who We Are
Windlass Consulting is built on a decade running the security program for a regulated pipeline operator: network architecture, enterprise business continuity, the SCADA platform, and the TSA Pipeline Security Directive controls that govern it, all structured against NIST CSF. That included direct involvement in on-site TSA audit meetings. Jacob Behnken built and ran that program before advising on one, and is a member of InfraGard and the International Society of Automation.
What We Do
Assessment & readiness
Independent, vendor-neutral assessments mapped to NIST CSF and IEC 62443, and the regulatory requirements you already answer to.
- OT / ICS security assessments and advisory
- Regulatory and audit readiness
Network & systems
Architecture review and segmentation design for the SCADA and industrial networks running the operation.
- SCADA and industrial network security
- IT/OT segmentation design and review
- Infrastructure resilience
Emerging risk
Security review for AI systems as they enter operational and enterprise environments.
- AI security
TSA-Designated Operators
If TSA has notified your pipeline system, hazardous liquid line, or LNG facility that it's critical, two directives are already running against you. SD Pipeline-2021-01G requires a named Cybersecurity Coordinator and incident reporting to CISA. Separately, SD Pipeline-2021-02G requires an approved Cybersecurity Implementation Plan, backed by a Cybersecurity Assessment Plan that covers one-third of the program every year and 100 percent of it over any three-year period.
SD Pipeline-2021-01G
Enhancing Pipeline Cybersecurity
SD Pipeline-2021-02G
Pipeline Cybersecurity Mitigation Actions, Contingency Planning, and Testing
Annual assessment coverage
one-third of the program every year
Full-cycle coverage
100 percent over any three-year period
Architecture review
Every two years
Field Notes
- Cybersecurity Assessment Plan: preparing for the annual cycleSD Pipeline-2021-02G requires a Cybersecurity Assessment Plan, submitted annually, that proves the Implementation Plan actually works. What the schedule requires, what counts as an assessment method, and what the annual report has to say.
- What a Pipeline Cybersecurity Coordinator is actually responsible forSD Pipeline-2021-01G requires a named Cybersecurity Coordinator and an alternate. The designation itself is administrative. What the role does afterward is where programs succeed or stall.
To discuss an engagement