Analysts and operators reviewing alerts in a control room as managed OT monitoring begins

How It Works

How managed OT monitoring works, from access to escalation

Four steps take you from an unwatched OT platform to alerts handled by trained analysts. Here is what happens at each one and what we need from you.

01 / Four steps

How managed OT monitoring works in four steps

  1. STEP 01

    1. Connect

    We get read-only access to your existing OT security platform through your secure remote access. If you do not have a secure remote access option, we recommend one.

  2. STEP 02

    2. Onboard

    We review the platform, map escalation contacts, write runbooks and run a test escalation before live monitoring starts.

  3. STEP 03

    3. Monitor

    Analysts watch your alerts during your chosen coverage hours: 24/7/365, nights and weekends, or a single shift.

  4. STEP 04

    4. Escalate and report

    Findings reach you with context through the agreed procedure, and you get monthly reports.

02 / Onboarding

What OT SOC onboarding delivers

Onboarding is where the service is tailored to your sites. You end up with documents your team can use, not just a promise.

Access setup

Read-only, least-privilege access through your secure remote access platform or a hardened jump host.

Platform review

We look at how your platform is configured, which sensors report and what the alert stream looks like.

Escalation mapping

We agree who gets called for which kind of finding, and in which order.

Contact tree

A written list of primary and backup contacts per site, so no escalation depends on one person.

Runbooks

Short, site-specific instructions for how analysts handle common alert types.

Baseline alert review

We go through current alerts with you to separate normal plant behavior from items that need attention.

Test escalation

We send a test escalation through the full path to prove it reaches the right person.

03 / Escalation

The OT alert escalation process

Analysts do not forward raw alerts. For each one they check asset, network and event context, remove duplicates and decide whether it is real. If it needs attention, they assign a severity and write down why.

Confirmed findings escalate to US-based OT specialists and a US-based OT escalation lead. From there the finding goes to your contacts through the channel you chose. We open a ticket, notify the right person and follow up until your team takes the handoff.

We stop at escalation. Containment, remediation, incident response and recovery are your decisions, and we can connect you with response partners.

04 / Reporting

Reporting and ongoing upkeep

You receive a monthly report of alerts and escalations, so you can see what the platform raised and what we did with it. Every quarter we run an asset true-up, so the inventory in the platform keeps matching what is on the plant floor.

We also watch platform connectivity and telemetry health. If a sensor or integration goes quiet, we tell you.

05 / What we need

What we need from you

The list is short. Most of it is information you already have.

  • 01Read-only access to your OT security platform, through your secure remote access.
  • 02A named owner for escalations at each site, plus backups.
  • 03Your preferred escalation channels, such as phone, email or ticketing.
  • 04Known maintenance windows and normal change activity.
  • 05Someone to join a baseline alert review and a test escalation.

06 / Not included

What the process does not cover

We do not deploy, upgrade or administer your platform, do detection engineering or extensive tuning, or perform deep forensics and threat hunting. If your platform is not tuned, we can scope a readiness project before monitoring starts.

07 / Day to day

What your team sees once monitoring is live

After go-live, your day-to-day involvement is small. You receive escalations only when an analyst has validated a finding, added context and assigned a severity. Everything else is handled, logged and rolled into the monthly report.

If a plant change is coming, such as a vendor visit, a firmware update or a new line coming online, tell us ahead of time. Analysts then know what to expect and can separate planned activity from the unplanned kind. Runbooks and the contact tree are living documents, and we update them as your sites change.

If something does not work the way you expect, the onboarding review and test escalation are the places to fix it. We would rather find a wrong phone number in a test than during a real finding.

08 / FAQ

Managed OT monitoring: common questions

01Do you need to install anything in our network?

No. We use read-only access to the platform you already own, through your secure remote access.

02What if we have no secure remote access?

We recommend one. Access should go through a secure remote access platform or a hardened jump host, never a plain VPN.

03Who decides what happens after an escalation?

You do. We provide the finding, context and severity. Your team makes the response decision.

04Can the coverage window change later?

Yes. You can add hours or move to 24/7/365 as your needs change.

Next step

See how it would work at your sites

Book a 20-minute fit call and we will walk through the four steps for your setup.