Home About Services Articles Contact Discuss a requirement
OscarTango

OT/ICS Security  ·  Offensive Security  ·  Critical Infrastructure Assurance

Cybersecurity for
operational technology
and critical infrastructure

We help operators of essential infrastructure find cybersecurity weaknesses before attackers can exploit them, and recommend how to address them. A founder-led specialist firm based in Abu Dhabi, working across the UAE and wider GCC on systems where a security failure can have physical consequences.

OT / ICS
Specialist Focus
Offensive
Adversary-Led Testing
Assurance
Independent Validation
Abu Dhabi
UAE & GCC

Specialists in the
operational attack
surface

OscarTango is a specialist cybersecurity firm focused on operational technology, critical infrastructure and adversarial security. Complex operational environments require practitioners who understand both how systems are designed to operate and how adversaries attempt to compromise them. We work at that intersection — industrial and control systems, the networks and software that connect to them, and the safety-critical processes that depend on them.

More about OscarTango
Founder-Led Delivery
Engagements are led and delivered by senior practitioners. Clients work directly with the person accountable for the technical outcome.
OT-Native, Not OT-Adjacent
Working knowledge of SCADA, DCS, PLCs and the protocols that bind them — Modbus, DNP3, IEC 61850, OPC-UA — alongside the standards that govern them: IEC 62443, NIST SP 800-82, NCA OTCC, NERC CIP.
Safety-First Methodology
Testing approaches are adapted to the operational state of the environment, with production safety, process integrity and availability taking precedence over test coverage. Techniques and timing are agreed with the engineers who own the systems, and we say so plainly when a technique is out of scope.

External validation,
before it matters

Specialist external validation gives organisations independent confidence that cybersecurity controls, architectures and critical projects perform as intended — before weaknesses become operational problems.

Where it fits

  • Major projects and critical-infrastructure investments — design assurance, factory and site acceptance testing, and pre-go-live validation for new plant, networks and control systems.
  • Transformation programmes — an independent technical view at the stage gates where sponsors decide whether to proceed.
  • Third-party and vendor assurance — review of integrator, vendor and service-provider work against what was specified and contracted.
  • Independent review for executives and boards — an external view of cyber risk and control effectiveness, for the people accountable for it.
01

Independent of Delivery

We do not build, integrate or operate the systems we assess, and we are not a reseller for anyone else's products. Our conclusions answer to the evidence.

02

Assurance at the Right Gate

Design review, factory and site acceptance testing, pre-go-live validation and post-implementation review — assurance applied at the stage where findings are still inexpensive to act on.

03

Evidence, Not Assertion

Conclusions are grounded in hands-on testing and technical review, expressed in terms boards, regulators and engineering teams can each act on.

Sectors
We Work In

Energy Oil, Gas & Petrochemicals Water Transport & Rail Aviation Ports & Logistics Mining & Resources Manufacturing Defence Autonomous Vehicles Smart Buildings & Cities

Discuss a requirement

Tell us about your environment and what you are trying to achieve. Enquiries from client organisations, procurement teams and prospective partners are all welcome.