NEO SENTINEL — Industrial Cybersecurity for Control-System Subsystems

An OT-native cybersecurity scope for DCS, SIS, CEMS, DAS and packaged control subsystems — six engineered defence domains delivered against IEC 62443, and proven at acceptance with signed evidence rather than statements of intent. NEO SENTINEL is our own asset-monitoring, secure-configuration and maintenance platform at the centre of it.

The Problem: Subsystems Inherit the Plant’s Risk but Not Its Security Budget

Analyser shelters, CEMS and DAS packages, compressor and boiler control skids — these arrive as vendor-supplied subsystems, get patched into the plant network, and then sit there for fifteen years. They exchange data with enterprise IT, they are accessed remotely by the vendor, and they very often run unmanaged local accounts on unpatched operating systems.

Six risk drivers show up on almost every subsystem we assess:

Risk driverWhy it matters on a control subsystem
IT/OT interconnectionThe subsystem exchanges data with enterprise IT. Without a controlled DMZ, any enterprise incident can reach control assets.
Uncontrolled remote accessVendor and engineering access without gateway, MFA and audit is the most common breach entry path in industrial systems.
Malware and USB exposureSignature-based antivirus alone cannot stop zero-day or USB-borne malware on OT hosts.
Unpatched vulnerabilitiesOS patches cannot be applied blindly during operation — unmanaged, they accumulate into exploitable debt.
Unmanaged accountsLocal accounts with weak or shared passwords defeat every other control and cannot be audited.
No visibility, untested recoveryWithout monitoring, incidents are found late. Without restore tests, backups fail exactly when needed.

Positioning: OT-Native, Not IT-Generic

The difference between an IT security scope and an OT security scope is not the technology list — it is what happens when a control decision conflicts with a security decision. We engineer inside Level 2 and Level 3 control networks as our day job, so the controls are designed around plant operation rather than against it: patching is scheduled by network level with restart under manual control, monitoring collects passively first, and no control is accepted until it has been demonstrated on the running configuration.

Standards Alignment

ReferenceHow it is used
IEC 62443 (SL2 target)Zone and conduit design, security-level target for the subsystem boundary
Purdue / ISA-99 layeringLevel 2 control, Level 3 site operations, Level 3.5 DMZ, Level 4 enterprise
Owner security requirements (OSR-class checklists)Per-category control requirements, executed row by row and signed at FAT/SAT
Plant operating proceduresPatch windows, restart authority, access approval workflow

Six Coordinated Defence Domains

Every layer an attacker must cross is engineered, verified and evidenced. Each domain is a separate work-breakdown family, so scope and price move together.

#DomainWhat is engineered
1Identity & AccessDomain governance: redundant domain controllers, DNS zones, OU/GPO policy set, certificate authority, RADIUS authentication, local-account cleanup
2Endpoint ProtectionCentralised antivirus, application whitelisting, OS hardening baseline, WSUS patch management with plant-safe scheduling
3Network SegregationZone and conduit design, perimeter (L3.5) and control (L2) firewalls, managed switch hardening, controller and HMI protocol protection
4Secure Remote Access (option)Remote access gateway, multi-factor authentication, time-limited least-privilege sessions, full session audit
5Monitoring & DetectionNEO SENTINEL platform, NIDS on SPAN mirrors, centralised log collection, configuration compliance baseline
6Backup & RecoveryBackup infrastructure and schedules, retention cycles, and a verified restore — timed and documented

Governance and assurance — functional design specification, risk assessment, FAT and SAT execution, documentation — span all six domains.

NEO SENTINEL project operations dashboard showing availability, critical alarms, configuration drift and data quality
NEO SENTINEL project operations dashboard — availability, critical alarms, configuration drift and data quality on one screen (demo dataset).

NEO SENTINEL: One Platform for Visibility, Configuration and Maintenance

NEO SENTINEL is neoDrive proprietary software, engineered for the same L2/L3 control networks it protects. It is what turns the monitoring domain from a shopping list of third-party tools into a single system with one accountable vendor.

CapabilityWhat it does
Asset monitoringLive availability and performance of every server, workstation and network device; complete asset inventory fed by NIDS discovery
Secure configurationConfiguration baselines, drift detection and scheduled compliance reports mapped to the approved setting values
Intelligent maintenanceMaintenance planning from real device health data — alarms, trends and lifecycle records in one place
NEO SENTINEL network topology view showing zones, links and offline blast radius
Topology view — zones, conduits and the blast radius of any offline node (demo dataset).

How It Collects

SourceMethodWhat it yields
Servers & workstationsAgent / WMI / SNMPHealth, performance, configuration state
Switches & firewallsSNMP / syslogStatus, interfaces, rule and configuration changes
NIDS sensorsPassive SPAN mirrorAsset discovery and threat alerts feeding the asset base
Security logsCentral syslogRetained per specification for the evidence record

The SENTINEL server sits on the control network (Level 3). Collection is passive first, so there is no added load on plant traffic. Reports export to CSV and PDF, which is what makes them usable directly as FAT and SAT evidence.

NEO SENTINEL asset centre listing every server, workstation, switch and firewall with criticality, health and lifecycle
Asset centre — every in-scope device with criticality, connection, health and lifecycle state (demo dataset).

Evidence-First Acceptance

The failure mode of most industrial security scopes is that they are accepted on a document rather than on a demonstration. Every control we deliver has a defined verification method fixed before configuration starts:

DomainDeliverablesAcceptance evidence
Identity & AccessDomain controllers, GPO policy set, CA, RADIUS, account inventoryReplication and DNS test logs, gpresult exports per endpoint, signed checklist rows
EndpointAV server and agents, enforced whitelist, hardened endpoints, WSUSAgent and scan reports, blocked-execution test on the enforced whitelist, per-endpoint hardening checklists
NetworkFirewall rule matrix, configured firewalls, hardened switchesRule exports, blocked-traffic and port-security tests, design review record
MonitoringNEO SENTINEL in operation, NIDS, central logging, compliance reportsAlarm and alert tests, asset-list export, sample compliance report
Backup & RecoveryBackup infrastructure, clients, schedules, restore procedureBackup job success logs and a timed restore test report
GovernanceFDS, risk assessment, FAT/SAT reports, evidence pack, as-built documentsApproval records, signed FAT and SAT reports, transmittals

The principle: you sign against a record — test logs, exports, screenshots and reports — collected item by item. A backup that has never been restored is a hope, not a control.

NEO SENTINEL report centre with asset inventory report and CSV or PDF export
Report centre — inventory and compliance reports exported to CSV/PDF for the FAT and SAT evidence record (demo dataset).

Requirement Coverage and Traceability

Owner cybersecurity checklists for subsystem-class equipment typically define around thirteen control categories and well over a hundred individual check rows. Each category is mapped to a solution module, a work-breakdown family and a named piece of acceptance evidence before work starts — nothing implicit:

Control categorySolution moduleWBS family
Access controlIdentity & AccessACC
Vulnerability management — hardeningEndpoint ProtectionEND
Vulnerability management — patchingEndpoint ProtectionEND
Malware protectionEndpoint ProtectionEND
Controller / HMI protectionNetwork SegregationNET
Switch and firewall hardeningNetwork SegregationNET
Security log collectionMonitoring & DetectionMON
Asset management / NIDSMonitoring & DetectionMON
Network monitoring systemMonitoring & DetectionMON
Configuration compliance managementMonitoring & DetectionMON
System backupBackup & RecoveryREC
Documentation and drawingsDeliverablesGOV
Cybersecurity risk assessmentImplementationGOV
NEO SENTINEL audit log showing recorded configuration and access changes with integrity status
Audit log — every configuration and access change recorded with an integrity check (demo dataset).

A Gated Delivery Method

The scope is frozen at a gate, designed at a gate, and accepted against a procedure. No date is promised before kickoff, because the schedule depends on inputs only the client holds.

StageContentGate
1. Requirement confirmationAsset inventory, drawings, checklist applicabilityScope freeze (G1)
2. Detailed designFDS, architecture, firewall rule matrix, policy valuesDesign approval (G2)
3. ConfigurationBuild and configure all six domains per approved design
4. Internal verificationChecklist dry run — findings fixed before the client sees the system
5. Factory acceptance testClient-witnessed tests per approved procedureSigned FAT report
6. Site acceptance testSite validation and punch-list closureSigned SAT report
7. HandoverDocumentation package, as-built, training and transfer

Transparent Pricing Mechanics

Cybersecurity scopes are notorious for quotations that cannot be interrogated. Ours is built from a unit man-day model with an explicit quantity factor, so repeat work is charged at its true marginal cost:

Work typeBehaviourRepeat ratio
Type A — design and documentsFirst unit carries the design effort; later units reuse heavilyr ≈ 0.2
Type B — repeat configurationFirst device validates the design; same-type devices reuse itr ≈ 0.5
Type C — per-device and site workEffort repeats per unit; site days are never compressedr ≈ 0.9

Kq = 1 + (Quantity − 1) × r, and Total = Base × Kq × Kc. A worked example: base 10 man-days at quantity 4 with r = 0.5 gives Kq = 2.5, so 25 man-days — not 40. Every quantity change re-prices mechanically, which removes renegotiation ambiguity in both directions.

Scope Boundaries

A clearly bounded scope is what prevents surprises at acceptance. Quantities are frozen against the client asset inventory at kickoff; anything outside the inventory is outside the scope until it is priced in.

Typically includedTypically excluded unless separately quoted
Design, configuration and verification of the six domainsHardware and software licences
FDS, procedures, risk assessment, test documentationCorporate IT network changes
FAT execution and SAT support with evidence packsLegacy or third-party systems outside the asset inventory
Checklist execution and signed results24/7 managed SOC operations and post-warranty updates
Single technical and commercial point of contactTravel, visas and accommodation (quoted separately)

Where This Fits

  • Vendor packages entering a secured plant — CEMS, DAS, analyser shelters, compressor and boiler skids that must satisfy an owner’s third-party cybersecurity requirements before they are accepted.
  • Existing subsystems being brought into compliance — where a security audit has produced findings and someone has to close them with evidence.
  • DCS and SIS revamps — where segmentation, account governance and monitoring should be engineered in during the project rather than retrofitted afterwards.
  • Multi-site programmes — where a repeatable baseline and a quantity-based price model matter more than a single bespoke design.

Request a NEO SENTINEL Assessment

Tell us the subsystem, the approximate device count (servers, workstations, firewalls, switches) and the owner requirement set you have to satisfy. We will come back with a scope outline, the applicable control categories and a quantity-based estimate — and the conversation will be with an engineer, not a sales call.

Related pages: NEO AEGIS — Alarm Management · NEO SynBlend — Blending Optimisation · DCS Engineering and Configuration

Software Consultation
Scroll to Top