OT · ICS · AI Security Advisory

WindlassConsulting

Holding the line on critical infrastructure.

Operational technology, industrial control systems, and AI security advisory for pipeline, energy, and critical-infrastructure operators.

Who We Are

Windlass Consulting is built on a decade running the security program for a regulated pipeline operator: network architecture, enterprise business continuity, the SCADA platform, and the TSA Pipeline Security Directive controls that govern it, all structured against NIST CSF. That included direct involvement in on-site TSA audit meetings. Jacob Behnken built and ran that program before advising on one, and is a member of InfraGard and the International Society of Automation.

Read more about the background

What We Do

Assessment & readiness

Independent, vendor-neutral assessments mapped to NIST CSF and IEC 62443, and the regulatory requirements you already answer to.

  • OT / ICS security assessments and advisory
  • Regulatory and audit readiness

Network & systems

Architecture review and segmentation design for the SCADA and industrial networks running the operation.

  • SCADA and industrial network security
  • IT/OT segmentation design and review
  • Infrastructure resilience

Emerging risk

Security review for AI systems as they enter operational and enterprise environments.

  • AI security

Full service scope

TSA-Designated Operators

If TSA has notified your pipeline system, hazardous liquid line, or LNG facility that it's critical, two directives are already running against you. SD Pipeline-2021-01G requires a named Cybersecurity Coordinator and incident reporting to CISA. Separately, SD Pipeline-2021-02G requires an approved Cybersecurity Implementation Plan, backed by a Cybersecurity Assessment Plan that covers one-third of the program every year and 100 percent of it over any three-year period.

SD Pipeline-2021-01G

Enhancing Pipeline Cybersecurity

SD Pipeline-2021-02G

Pipeline Cybersecurity Mitigation Actions, Contingency Planning, and Testing

Annual assessment coverage

one-third of the program every year

Full-cycle coverage

100 percent over any three-year period

Architecture review

Every two years

TSA pipeline cybersecurity consulting

To discuss an engagement