Company name | Description and specialisation | Service categories | Certifications | VAT register | REGON register |
|---|---|---|---|---|---|
| Anzena | Distributor and integrator of data protection technology: backup and disaster recovery, data loss prevention, privileged access management and security for IT and OT networks. | Data Protection Infrastructure Security OT/ICS Security | Loading... | Loading... | |
| Apius Technologies | Network integrator running a SOC and deploying network, endpoint, application, data and communication security, public cloud, container and SaaS security, DevSecOps, digital identity and OT cybersecurity, alongside its LAN, DC and SD-WAN business. | Infrastructure Security Cloud Security Data Protection Monitoring & SOC OT/ICS Security | Loading... | Loading... | |
| Arkanet | IT security integrator from Katowice: antivirus and EDR-XDR, email and cloud protection, encryption, MDM, PAM, DLP, SIEM and SOAR, vulnerability detection, backup, UTM and firewall network security, plus industrial OT protection. | Infrastructure Security Cloud Security Data Protection Monitoring & SOC OT/ICS Security Security Training & Awareness | Loading... | Loading... | |
| Cryptomage | Maker of Cryptomage Cyber Eye, an NDR probe applying AI to network traffic analysis to detect threats and anomalies in IT and OT networks, including personal data leaks. | Monitoring & SOC OT/ICS Security Data Protection | Loading... | Loading... | |
| Deloitte | Cybersecurity practice within the Deloitte advisory firm: NIS2, DORA and GDPR compliance, SOC build and run, MXDR, threat intelligence, cloud and OT/ICS security, data protection and Zero Trust architecture. | Infrastructure Security GRC & Compliance Cloud Security Data Protection Monitoring & SOC OT/ICS Security | Loading... | Loading... | |
| Dynacon | Engineering company specialising in industrial cybersecurity, building network communication, monitoring and protection systems for critical infrastructure and OT environments. | OT/ICS Security Monitoring & SOC | ISO/IEC 27001 ISO 9001 | Loading... | Loading... |
| EY | Cybersecurity unit of the EY advisory firm: penetration testing, red teaming, security architecture, IAM/PAM, SIEM and SOAR, cloud and data protection, CSIRT incident response, OT security, compliance advisory and training. | Infrastructure Security Penetration Testing & Audits GRC & Compliance Security Training & Awareness Cloud Security Data Protection Monitoring & SOC OT/ICS Security | Loading... | Loading... | |
| ICsec | Maker of SCADvance XP, a system for monitoring, threat detection and protection of industrial OT/ICS automation networks. | OT/ICS Security Monitoring & SOC | Loading... | Loading... | |
| LogicalTrust | Wroclaw-based offensive security firm running web and mobile penetration tests, source code audits, red team exercises, social engineering tests, ransomware simulations and cloud, container, PCI DSS, DORA and NIS2 audits. | Infrastructure Security Penetration Testing & Audits GRC & Compliance Security Training & Awareness Cloud Security OT/ICS Security | Loading... | Loading... | |
| Olban | OT security specialist providing audits, risk assessment, penetration testing, network segmentation, hardening, monitoring and deployments aligned with IEC 62443 and NIS2. | OT/ICS Security Penetration Testing & Audits Monitoring & SOC | Loading... | Loading... | |
| Orange Polska | Telecom operator running cybersecurity on its own SOC: managed SOC with SIEM, DDoS protection, Secure DNS, email and web application protection, penetration tests, staff training, ISMS advisory and industrial infrastructure security. | Infrastructure Security Penetration Testing & Audits GRC & Compliance Security Training & Awareness Data Protection Monitoring & SOC OT/ICS Security | Loading... | Loading... | |
| Pancernik.IT (Bezpieczni.IT) | Katowice security integrator operating as Bezpieczni.IT: NGFW and UTM, NIPS and NDR, DDoS protection, NAC, WAF, EDR, PAM, DLP, email protection, backup, SIEM and SOC services, plus security audits, trainings and OT network protection. | Infrastructure Security GRC & Compliance Security Training & Awareness OT/ICS Security Data Protection Monitoring & SOC | Loading... | Loading... | |
| PwC | Cybersecurity practice of advisory firm PwC in Poland: penetration testing and red team, IT and OT security architecture reviews, NIS2 and GDPR compliance, managed SOC with 24/7 incident response, cloud security, DLP and training. | Infrastructure Security Penetration Testing & Audits GRC & Compliance Security Training & Awareness Cloud Security Data Protection Monitoring & SOC OT/ICS Security | Loading... | Loading... | |
| Red Team | Specialists in penetration testing, red teaming, IT/OT/IoT audits and social engineering, also delivering threat hunting, forensic analysis and incident response. | OT/ICS Security Penetration Testing & Audits Monitoring & SOC | Loading... | Loading... | |
| SISOFT | Cybersecurity consultancy running penetration tests (applications, infrastructure, IoT/OT, vehicles), social engineering tests, compliance audits (ISO 27001, TISAX, NIS2) and Cybersecurity-as-a-Service. | Penetration Testing & Audits GRC & Compliance OT/ICS Security | Loading... | Loading... |
OT/ICS security in a production plant
OT/ICS security protects industrial control systems from attacks and faults that stop a physical process. It reaches the plant network, PLC controllers, HMI panels and SCADA stations, the layers where an incident means downtime and risk to people rather than a lost file. It parts ways with office IT because a control loop cannot be restarted mid shift and part of the equipment runs firmware the vendor no longer supports. Work therefore opens with an asset inventory and traffic observation instead of a scan.
The service usually combines four parts: an inventory of devices and protocols on the control network, a segmentation design built on zones and conduits following the Purdue model and the ISA/IEC 62443 standards, passive monitoring with anomaly detection on industrial traffic, and controlled security testing inside an agreed maintenance window. Documentation handed to the plant covers an OT asset register, a map of every crossing between office and production networks, weaknesses written in terms of process impact, the segmentation design and a response plan that assumes manual operation.
Price and schedule follow the number of sites and network segments, the count of controllers and operator stations, the mix of protocols such as Modbus, Profinet, OPC UA and DNP3, the share of equipment without vendor support, and whether the work ends with a report or continues into implementation and monitoring. The order of steps repeats across most plants: a conversation about the process and the cost of downtime, passive discovery during normal production, a workshop with the maintenance team, active work in a service window, a prioritised report, then staged remediation.
When to order OT/ICS security work
- You are connecting the production network to IT systems, cloud services or vendor remote access, and nobody can say how traffic crosses between zones.
- There is no current inventory of controllers, operator stations and network devices on the shop floor, so the protected scope is unknown.
- The plant falls under NIS2 or its national transposition, and the automation integrator starts asking about ISA/IEC 62443 requirements.
- You are modernising a line, migrating SCADA or replacing controllers, and segmentation is far cheaper to design before commissioning than after.
- An incident on the office network forced a shutdown of links, and production stopped together with the back office.
How to choose an OT/ICS security provider
- Ask for engagements in your sector, because power, water, food processing and automotive plants run different processes and very different maintenance windows.
- Check how the provider collects data: passive capture from a mirror port or active scanning, and who authorises any active test on a running line.
- Ask about the industrial protocols and controller families you actually operate, instead of accepting a general claim of OT experience.
- Confirm that the segmentation design uses zones and conduits per ISA/IEC 62443 and that the maintenance team reviews it before anything changes.
- Verify that findings describe the impact on the production process and that the provider supports remediation rather than only listing weaknesses.
OT/ICS security - frequently asked questions
Answers for teams that are about to buy services from this category.
An OT/ICS security service protects the equipment that runs a physical process, from the controllers on the line up to the operator consoles. The work covers asset discovery, splitting the network into zones, control over remote access, passive traffic monitoring and a response plan, with controlled security testing as one stage rather than the whole job. Scope follows the process, because a plant values availability and worker safety first.
An OT schedule is built around the plant maintenance calendar, because access to controllers often exists only during a shutdown. Passive discovery and asset inventory run alongside normal production, while network changes and active attempts wait for a service window. Across several halls or distributed sites the job splits into visits, and its length depends on how much time plant engineers can give it.
Duties arising from NIS2 apply to the organisation as a whole, so control systems fall in scope alongside office infrastructure. The rules name no single technical standard; they require risk management, access control, continuity and incident reporting, and the ISA/IEC 62443 standards are commonly used to show those duties are met on the OT side. Sector and organisation size decide whether a plant is in scope at all.
A single plant runs OT security around one network and one maintenance team, so an asset inventory, separation of production traffic from office traffic and control over vendor remote access close most of the risk. A group of factories adds shared zone standards, one set of access rules for integrators and central event collection from sites with uneven levels of automation. Coordination then weighs more than technology, because every plant keeps its own shutdown calendar.
The usual misstep is commissioning OT work without the maintenance and automation engineers who answer for the line. The provider then gets access to the network but not to knowledge about the process, so weaknesses land in a report with nothing said about what fixing them does to production. What follows is a list nobody implements, because every change needs approval from people left out at the start.
Preparation means gathering the documentation the plant already holds: network diagrams, controller lists, configuration backups and a record of remote access granted to integrators and machine builders. Someone from the maintenance team also has to be named, able to explain the process, authorise entry to a control cabinet and confirm the next planned shutdowns. The more of that material exists up front, the less time goes into rebuilding the picture of the network.
An OT audit report is best ordered by process impact rather than by technical severity, because part of the findings close through segmentation without touching a controller. Fixes that need no shutdown, such as removing unused crossings between zones or cleaning up remote service accounts, go first. The rest becomes a work plan tied to specific maintenance dates, together with a decision on who watches for anomalies once the project ends.
Most OT work runs without touching the line, because discovery relies on listening to a copy of network traffic rather than querying controllers. Risk appears with active testing and changes to network configuration, so those are scheduled into a shutdown, a test bench or a configuration copy. The condition is a written agreement stating which methods are allowed and on which devices.
On a small budget the highest return comes from an inventory of the control network and tidy remote access, since neither needs new hardware. Money after that usually goes to separating production traffic from the office network and to configuration backups for controllers, which shorten recovery after a failure. Anomaly monitoring and a full zone design can wait until those basics hold.
A contract for OT work should name the devices and segments in scope, the methods allowed on a running line and the person at the plant who approves every active attempt. It should also set out what happens if the process looks affected: who calls a stop, how contact works outside business hours and who restores a configuration. Continuous monitoring adds alert response times and the route for passing events to the maintenance team.
Not sure which provider fits?
Describe what you need. An enquiry sent from here reaches us only. To reach a provider, send it from the profile of a ot/ics security company you pick.
You do not need to know the exact category. Describing the problem is enough.
Cybersecurity service categories
Browse the full list of cybersecurity specialisations available in the directory and find the right partner for your organisation.
Infrastructure security covers the rollout and day-to-day running of endpoint, identity and network defences: EDR, MFA, access control and segmentation. The directory lists providers who run such projects from inventory to handover.
A penetration test is an authorised attack on your own system that shows which flaws an intruder would actually use. Compare providers testing web and mobile apps, networks and source code.
GRC and compliance work turns security into a managed system: risk analysis, policies, continuity planning and the evidence an auditor asks for. Browse the providers who run those projects in Poland.
Security awareness programmes, phishing simulations and certification courses for IT staff - from spotting a fake payment request to exam preparation. Compare training providers delivering in Poland.
OT/ICS security protects the plant network, PLC controllers and SCADA stations from incidents that stop production. See providers who work on the shop floor without shutting the line down.
Cloud security means reviewing and tightening how AWS, Azure and GCP accounts are set up: identity, permissions, encryption, containers and deployment pipelines. Browse Polish firms that examine your estate and help close what they find.
Data protection means inventory and classification of data sets, encryption, DLP and key management in a cloud KMS or an HSM. Compare providers that map where your records sit and cut the risk of them leaving the company.
Continuous security monitoring and incident detection: SOC as a Service, MDR, SIEM rollouts and SOAR automation. Find Polish providers that watch your logs around the clock and escalate real attacks.