Houston, Texas

OT/ICS Cybersecurity Consulting in Houston

Windlass Consulting is based in Houston and works on-site with Gulf Coast refining, petrochemical, and midstream operators, and remotely with operators anywhere else. The assessment methodology is the same wherever the engagement happens; being based here just means less lead time to get on-site when it matters.

Why Houston

The Houston Ship Channel and the wider Gulf Coast corridor carry a high concentration of refining, petrochemical, and pipeline infrastructure. TSA-designated pipeline and LNG operators, refiners, petrochemical plants, and midstream terminals often run OT environments within a short drive of downtown Houston. Being based here means firsthand familiarity with the region's control-system vendors, the local ISA and InfraGard communities, and the practical realities of scheduling a plant visit around a turnaround or a shift change, not just the regulatory paperwork.

How engagements work

Houston and Gulf Coast engagements are on-site by default: architecture walkthroughs, protocol capture, and stakeholder interviews happen in person. For operators outside the region, the same methodology runs remotely, configuration audit, passive network capture, and document review all work without a site visit, and travel happens when an engagement genuinely needs it: a kickoff, a physical walkthrough, or standing in on a TSA audit meeting. Distance isn't the deciding factor. What the engagement actually requires is.

Local credentials

Windlass Consulting is a member of the International Society of Automation's Houston Section and the Houston chapter of InfraGard, the FBI-affiliated partnership between the private sector and law enforcement on critical-infrastructure protection.

What's covered

For TSA-designated pipeline, hazardous liquid, and LNG operators, see the TSA pipeline cybersecurity consulting page for what the directives require and how an engagement is structured. For refining, petrochemical, midstream, and other OT/ICS operators without a TSA designation, see the OT/ICS security assessment page. Both use the same passive-by-design methodology described there; this page is about where and how the work happens, not a separate service.

Frequently asked questions

Do you only work with Houston-based operators?

No. Houston and the Gulf Coast are where on-site engagements happen by default, but the same assessment methodology runs remotely for operators anywhere else, with travel when an engagement requires it.

How far do you travel for an on-site engagement?

There's no fixed radius. Houston and the Gulf Coast are the on-site default; beyond that, it depends on what the engagement actually needs rather than a mileage cutoff.

Which page should I start with, TSA pipeline cybersecurity or OT/ICS security assessment?

If TSA has notified you that a pipeline system, hazardous liquid line, or LNG facility is critical, start with the TSA pipeline cybersecurity page. Otherwise, or if you're not sure, the OT/ICS security assessment page or the readiness check above will sort it out.

Discuss a Houston or Gulf Coast engagement