العربية

Service · Critical infrastructure and OT

The plant cannot be stopped for the audit.

An IT assessment method applied to operational technology produces two outcomes, both bad: findings nobody can act on without a shutdown, or an active scan that trips a safety system. The constraint is the engagement design, not a caveat at the end of it.

What changes when the asset is plant

Availability outranks confidentiality. Equipment runs for twenty years on firmware that cannot be patched without vendor recertification. Maintenance windows are annual, contractual, and already spoken for. The people who know the process are engineers, not security staff, and they are right to be sceptical of anyone who arrives with a vulnerability scanner.

So assessment is passive by default: configuration review, network architecture review, span-port traffic capture where it is safe, and structured interview with the people who run the process. Active testing happens only inside an agreed window, on an agreed segment, with an agreed abort condition, and usually not at all on the first engagement.

The first deliverable is almost always an asset inventory, because in most Gulf plants one does not exist in any form a regulator would accept. Nothing else in a control set can be evidenced until it does.

What reaches an operator here

Critical infrastructure is defined nationally, and the definitions do not match each other. The first question is whether you are designated, not whether you feel critical.

Saudi Arabia

Operational Technology Cybersecurity Controls

OTCC-1:2022

The most developed OT instrument in the Gulf. It covers industrial control systems and OT environments and ships with a methodology and mapping annex plus a spreadsheet assessment and compliance tool, which makes self-assessment genuinely possible before anyone is engaged. It sits above the Critical Systems Cybersecurity Controls — 32 main controls and 73 sub-controls across governance, defence, resilience, and third-party and cloud — and both build on the ECC baseline.

Who signsThe NCA's own programme. Note that providing cyber security services in the Kingdom requires Haseen registration, and legal analysis concludes overseas firms can no longer lawfully deliver in-scope services into Saudi Arabia from outside it.
United Arab Emirates

Information Assurance Regulation and the CIIP Policy

IAR v1.1

Designation under the Critical Information Infrastructure Protection Policy is what converts the IAR from recommended to binding. Six management and nine technical control families across four priority tiers, with policy leadership at the UAE Cyber Security Council and the standard administered by TDRA. Dubai entities carry the DESC regulation in addition, including its cloud service provider, data centre and SOC security standards.

Who signsPeriodic reporting, with no fixed cadence in the document. Penetration testing and incident response for Dubai government and critical infrastructure is gated to Cyber Force certified firms — we are not one.
Qatar

National Information Assurance Standard

NIA v2.1

Binds critical information infrastructure operators across energy and the other designated sectors alongside government entities, and runs the clearest certification path in the region: scope and documentation, audit planning with an accredited auditor, compliance audit, then the NCSA's certification decision. Classification under the national data classification policy is the practical first step.

Who signsAn NCSA-accredited auditor. Certificate valid three years with an annual maintenance audit.
Kuwait

Cyber and Operational Resilience Framework

CORF v1.0

Not an OT instrument, but the reason it belongs here is the word operational: since December 2025 CBK-regulated entities are assessed on resilience of service delivery, not only on information security controls. Twenty-seven domains, 93 sub-domains and 876 controls on a five-level maturity scale, with full compliance required before an entity can claim baseline or above.

Who signsTier 1 annual, tier 2 every 18 months, tier 3 two-yearly, plus annual self-assessment.

How the engagement runs

Four stages. The first two produce most of the value.

01

Asset inventory and network architecture

What is actually connected, at what level, talking to what. Built passively from configuration, documentation and engineer interview, then reconciled against traffic capture where capture is safe. This is the evidence base every control in every framework depends on.

Purdue levelsPassive
02

Segregation review

Where the IT and OT boundary actually sits as opposed to where the drawing says it sits, including remote access paths, vendor connections, engineering workstations and the shared jump hosts that almost always turn out to be the real finding.

IEC 62443 zonesVendor access
03

Control assessment against the named instrument

Assessed in the regulator's own control references — OTCC and CSCC in Saudi, the IAR families in the UAE, NIA in Qatar — with IEC 62443 used as the engineering vocabulary where it helps your team, not substituted for the instrument that binds you.

OTCC-1:2022IEC 62443
04

Remediation plan built around maintenance windows

Sequenced against the outage calendar you actually have, separating what can be done live, what needs the next window, and what needs to wait for an equipment refresh. Costed in effort and downtime rather than in our day rates.

Live / window / refresh

We do not test what we cannot safely test, and we do not remediate what we assess

No active scanning of a live safety-instrumented system, ever, and no testing at all outside an agreed window with an agreed abort condition. If a finding needs a vendor to recertify firmware, we say so rather than writing a control gap you cannot close. And we do not bid for the remediation arising from our own report — which matters more in OT than anywhere else, because the remediation here is capital equipment and the incentive to find more of it would be substantial.

Start with a scoping call

Tell us the sector, the country, whether you have been designated as critical, and when your next maintenance window is. That last one shapes the engagement more than anything else.