Background

About

Windlass Consulting draws on a decade as a senior infrastructure and OT executive at a regulated pipeline operator, with oversight spanning network architecture, enterprise business continuity, the SCADA platform supporting the regulated pipeline lines, and required TSA Pipeline Security Directive controls, all structured against NIST CSF. That oversight included direct involvement in on-site TSA audit meetings, stepping in on auditor questions the team's paperwork alone didn't settle. That's the vantage point behind this assessment: an executive program that spanned the operational SCADA environment and the regulatory relationship behind it, not just the network perimeter around it.

The problems that program addressed aren't specific to a TSA-regulated pipeline. IT/OT segmentation, a SCADA environment that can't take the same patching or scanning cadence as a corporate network, and a security program built to hold up under outside review are common to operational technology environments generally, whether or not a specific federal directive applies. IEC 62443 and NIST CSF are the frameworks this practice uses either way.

How engagements work

Assessments are vendor-neutral: no reseller arrangement or product line decides what gets recommended. Findings map to NIST CSF and the regulatory requirements a pipeline or critical-infrastructure operator already has to answer to, rather than a generic checklist adapted after the fact. On the OT side specifically, assessment work stays passive by design: architecture review, configuration audit, and protocol capture that characterize a network without sending it traffic it was not built to handle.

To discuss an engagement