Home About Services Articles Contact Discuss a requirement

Services

Six capability areas, built around the realities of operational environments — where availability is paramount, change is tightly controlled, and the consequences of failure can be physical.

01

OT / ICS
Cybersecurity

Understanding and improving the security of operational and industrial environments — the control systems, networks and engineering practices that keep plant, process and infrastructure running. Work is scoped against operational risk first, and planned with the site's engineers around maintenance windows, change control and production continuity.

  • Security assessments of control systems, SCADA and DCS environments, engineering workstations, historians and the IT/OT boundary.
  • Architecture and segmentation reviews against IEC/ISA 62443 zones and conduits, including remote access and vendor connectivity.
  • Cyber-risk assessments that connect technical exposure to process, safety and availability consequence.
  • Maturity assessments against IEC 62443, NIST SP 800-82, NCA OTCC and NERC CIP.
  • Remediation planning sequenced around outage windows, engineering change control and vendor dependencies.
SCADA DCS PLC HMI Historian IT/OT Boundary IEC 62443 NIST SP 800-82 NCA OTCC

02

Offensive Security &
Adversary-Led Testing

Testing that identifies the attack paths which actually exist in an environment, and demonstrates them under controls agreed with the people who run it. Engagements are shaped by how an adversary would reach the systems that matter — through the network, through the building, or through the air.

  • Penetration testing across enterprise IT, OT and industrial environments, from the corporate perimeter through to the engineering layer.
  • Red teaming and adversary emulation against people, process and technology, using the tradecraft of threat actors with documented OT capability.
  • Cyber-physical security assessments covering perimeter protection, surveillance and CCTV, intrusion detection, and badge, RFID and access control systems — standalone, or as the physical dimension of a full-scope red team.
  • Wireless, cellular and private 5G testing across Wi-Fi, Bluetooth and proprietary RF, through to private 4G/5G RAN, core and SIM/device trust boundaries — including the rogue modems, unauthorised access points and out-of-band paths that quietly bridge segmentation.
  • Purple team and detection validation to establish what your monitoring and response actually catch.
Penetration Testing Red Team MITRE ATT&CK ICS Cyber-Physical Access Control Private 5G / 4G RF Survey Purple Team

Testing in live environments

Testing approaches are adapted to the operational state of the environment, with production safety, process integrity and availability taking precedence over test coverage. Techniques, timing and stop conditions are agreed with the engineers who own the systems. Where a technique carries unacceptable risk to a live system, it is carried out against a test, standby or offline equivalent, or left out of scope.

03

AI Security &
Adversarial Assurance

We test AI systems and autonomous software to understand how they can be manipulated, misused or cause unintended operational consequences. It is the adversarial testing we apply elsewhere, extended to large language models, autonomous agents and AI-enabled workflows, and to their integration with enterprise and operational environments — with particular focus on AI that holds privileged access in or adjacent to critical infrastructure.

  • AI / LLM red teaming through prompt injection, crafted inputs and manipulated content, to establish what a model-backed application can be made to do.
  • Agentic security testing of autonomous and semi-autonomous workflows, including whether unsafe autonomous actions are stopped before they execute.
  • AI threat modelling that identifies realistic abuse paths, trust-boundary failures and their operational consequences.
  • AI security architecture review of how AI systems connect to identities, APIs, data stores, cloud platforms and enterprise applications and, where they reach that far, OT and ICS environments.
  • Privileged tool and API abuse testing that establishes whether the tools and credentials an AI system holds can be turned against the systems they connect to, and whether privilege boundaries hold.
  • Data leakage and trust-boundary assessment covering where sensitive data can leave through an AI system, and where untrusted content crosses into trusted context.
  • AI-to-OT and cyber-physical assurance for AI systems that can influence industrial, transport, energy or other physical operations, including AI-assisted operations with access to historians and engineering systems.
LLM Red Teaming Prompt Injection Agentic Workflows Tool & API Abuse Trust Boundaries OWASP LLM Top 10 MITRE ATLAS AI-to-OT

Control authority

Where AI meets an operational environment, the questions are engineering ones. Does the system support an operator's decision, or can it act on the process? What stands between its output and an actuation? Does human override remain available, and do safety boundaries hold when the model is manipulated? Assessment answers those questions under the same operational controls as all of our testing.

04

Critical Infrastructure
Assurance

Independent cybersecurity assurance and external validation for safety-critical environments, major projects, critical-infrastructure investments and transformation programmes. It gives executives, boards, regulators and asset owners independent confidence that controls, architectures and critical projects perform as intended — before weaknesses become operational problems.

  • Design and architecture assurance on major projects, before decisions become expensive to reverse.
  • Factory and site acceptance security testing for control systems and operational technology being brought into service, planned around the commissioning schedule.
  • Pre-go-live validation that agreed security requirements have actually been implemented, not merely specified.
  • Third-party and vendor security assurance — independent review of integrator, vendor and service-provider work, where an objective technical opinion is required.
  • Programme, stage-gate and post-implementation assurance for transformation and modernisation initiatives, giving sponsors an independent technical view at each decision point.

We do not build, integrate or operate the systems we assess, and we are not a reseller for anyone else's products. That separation is what makes the assurance meaningful to boards, regulators and asset owners.

05

Incident Response
& Resilience

Preparation, investigation, containment, recovery and resilience support across complex IT and OT environments — where response decisions carry operational and safety consequences alongside security ones.

  • Response readiness — playbooks, escalation paths and decision authority for incidents that cross the IT/OT boundary.
  • Investigation and containment support during live incidents, working alongside engineering and operations teams.
  • Recovery and restoration planning for control systems, including validation that recovered systems are safe to return to service.
  • Tabletop and simulation exercises for engineering, security and executive audiences.
  • Resilience review of the assumptions a recovery plan depends on — backups, spares, vendor availability and manual fallback.
IR Readiness Containment Recovery Tabletop Exercises IT/OT Escalation

06

Cybersecurity
Advisory

Senior technical and strategic cybersecurity advisory for CIOs, CISOs, boards and programme sponsors who require specialist expertise, independent challenge or technical leadership they do not hold in-house.

  • Strategic cyber-risk advisory that translates technical exposure in operational environments into business, safety and regulatory risk that executives can govern and fund.
  • Security strategy and roadmap for OT and critical infrastructure programmes, grounded in operational reality rather than framework compliance alone.
  • Independent challenge to internal proposals, vendor recommendations and business cases.
  • Architecture and technical design review at the point where it changes the outcome.
  • Interim and fractional technical leadership where specialist capability is needed for a defined period.
  • Briefings and technical training for engineering teams, security functions and executive audiences.
Cyber Risk Security Strategy Independent Challenge Architecture Review Technical Leadership Executive Briefing

Tooling

OscarTango uses a mixture of open-source, commercial and proprietary tooling, chosen to suit the environment being assessed. No single toolset covers an OT estate — the right instrument depends on the protocol, the vendor, and what the plant will tolerate.

Discuss a requirement

Describe the environment, the project or the question, and we will tell you how we would scope it.