GDF supports operators of building systems, manufacturing, power, water, transportation, logistics, healthcare facilities, and other cyber-physical environments. Life safety and environmental protection come first, followed by stable operation and process integrity. Evidence preservation and security testing proceed within those operating constraints. Passive-first asset discovery and engineering interviews establish the environment before any active method is considered.
Understand the process before the packet
An OT asset has a function, controller relationship, process consequence, maintenance owner, communication pattern, and recovery path. Inventory work captures those facts alongside vendor, model, firmware, network address, protocol, and zone. Unknown devices and unsupported components are prioritized by operational role, not merely by age.
Architecture and segmentation tested against use
ICS security architecture review traces remote access, engineering workstations, historians, domain services, safety systems, vendor connections, wireless links, and IT/OT exchange points. Network segmentation validation checks whether stated zones and conduits work in practice. Any active test requires approval from operator-designated authority, a defined maintenance or test condition, reviewed process hazards, explicit stop points, rollback or recovery steps, and personnel able to recognize an unsafe or unstable condition. Some environments are limited to passive review and configuration analysis.
- Passive-first asset discovery and inventory reconciliation
- Zone, conduit, firewall, jump-host, and remote-access review
- Operational consequence ranking for vulnerabilities and attack paths
- Backup, restore, spares, and recovery-path validation
- OT incident readiness planning and tabletop exercises
Evidence from engineering records, configuration, and observed traffic
An accurate OT assessment reconciles several imperfect views of the environment. Network drawings show design intent. Controller projects and HMI configurations identify process relationships. Firewall, switch, route, jump-host, and remote-access settings show permitted paths. Passive traffic shows communication that occurred during the observation window. Maintenance records and operator knowledge explain dormant, temporary, or safety-related assets that may not appear on the network.
GDF records where those sources agree and where they conflict. Coverage limits, inaccessible cells, encrypted traffic, serial networks, intermittent vendor access, wireless paths, and inactive equipment remain visible. The resulting evidence package supports engineering decisions and later validation instead of presenting an unexplained device count.
- Network and data-flow diagrams reconciled to current configuration
- Asset, process role, owner, zone, protocol, and recovery records
- Firewall, route, remote-access, identity, and jump-host evidence
- Observed cross-zone traffic and documented legitimate conduits
- Exceptions, compensating controls, and post-change validation status
Incident readiness and recovery for cyber-physical systems
OT response plans identify the operator-designated authority for isolation or change, which systems can fail safely, where engineering backups and known-good configurations are stored, how vendors will be reached, and which evidence can be collected without delaying process recovery. The plan places life safety and environmental protection ahead of evidence collection, then addresses stable operation, process integrity, containment, and recovery. It also accounts for manual operation, safety escalation, regulatory coordination, and communications between operations, security, IT, leadership, and counsel.
Tabletop and technical exercises test those dependencies against a credible scenario. Findings can address missing logs, unsupported access, unavailable spares, uncertain restore procedures, undocumented connections, or authority gaps. Corrective work is assigned to an owner and tested under operator control.
Recommendations operators can schedule
A useful finding accounts for maintenance windows, vendor support, safety review, production demand, legacy protocol, and compensating controls. Reports distinguish immediate containment, near-term engineering changes, and longer capital work. The aim is measurable risk reduction without creating avoidable process instability.