How It Works
How managed OT monitoring works, from access to escalation
Four steps take you from an unwatched OT platform to alerts handled by trained analysts. Here is what happens at each one and what we need from you.
01 / Four steps
How managed OT monitoring works in four steps
- STEP 01
1. Connect
We get read-only access to your existing OT security platform through your secure remote access. If you do not have a secure remote access option, we recommend one.
- STEP 02
2. Onboard
We review the platform, map escalation contacts, write runbooks and run a test escalation before live monitoring starts.
- STEP 03
3. Monitor
Analysts watch your alerts during your chosen coverage hours: 24/7/365, nights and weekends, or a single shift.
- STEP 04
4. Escalate and report
Findings reach you with context through the agreed procedure, and you get monthly reports.
02 / Onboarding
What OT SOC onboarding delivers
Onboarding is where the service is tailored to your sites. You end up with documents your team can use, not just a promise.
Access setup
Read-only, least-privilege access through your secure remote access platform or a hardened jump host.
Platform review
We look at how your platform is configured, which sensors report and what the alert stream looks like.
Escalation mapping
We agree who gets called for which kind of finding, and in which order.
Contact tree
A written list of primary and backup contacts per site, so no escalation depends on one person.
Runbooks
Short, site-specific instructions for how analysts handle common alert types.
Baseline alert review
We go through current alerts with you to separate normal plant behavior from items that need attention.
Test escalation
We send a test escalation through the full path to prove it reaches the right person.
03 / Escalation
The OT alert escalation process
Analysts do not forward raw alerts. For each one they check asset, network and event context, remove duplicates and decide whether it is real. If it needs attention, they assign a severity and write down why.
Confirmed findings escalate to US-based OT specialists and a US-based OT escalation lead. From there the finding goes to your contacts through the channel you chose. We open a ticket, notify the right person and follow up until your team takes the handoff.
We stop at escalation. Containment, remediation, incident response and recovery are your decisions, and we can connect you with response partners.
04 / Reporting
Reporting and ongoing upkeep
You receive a monthly report of alerts and escalations, so you can see what the platform raised and what we did with it. Every quarter we run an asset true-up, so the inventory in the platform keeps matching what is on the plant floor.
We also watch platform connectivity and telemetry health. If a sensor or integration goes quiet, we tell you.
05 / What we need
What we need from you
The list is short. Most of it is information you already have.
- 01Read-only access to your OT security platform, through your secure remote access.
- 02A named owner for escalations at each site, plus backups.
- 03Your preferred escalation channels, such as phone, email or ticketing.
- 04Known maintenance windows and normal change activity.
- 05Someone to join a baseline alert review and a test escalation.
06 / Not included
What the process does not cover
We do not deploy, upgrade or administer your platform, do detection engineering or extensive tuning, or perform deep forensics and threat hunting. If your platform is not tuned, we can scope a readiness project before monitoring starts.
07 / Day to day
What your team sees once monitoring is live
After go-live, your day-to-day involvement is small. You receive escalations only when an analyst has validated a finding, added context and assigned a severity. Everything else is handled, logged and rolled into the monthly report.
If a plant change is coming, such as a vendor visit, a firmware update or a new line coming online, tell us ahead of time. Analysts then know what to expect and can separate planned activity from the unplanned kind. Runbooks and the contact tree are living documents, and we update them as your sites change.
If something does not work the way you expect, the onboarding review and test escalation are the places to fix it. We would rather find a wrong phone number in a test than during a real finding.
08 / FAQ
Managed OT monitoring: common questions
01Do you need to install anything in our network?
No. We use read-only access to the platform you already own, through your secure remote access.
02What if we have no secure remote access?
We recommend one. Access should go through a secure remote access platform or a hardened jump host, never a plain VPN.
03Who decides what happens after an escalation?
You do. We provide the finding, context and severity. Your team makes the response decision.
04Can the coverage window change later?
Yes. You can add hours or move to 24/7/365 as your needs change.
Keep reading
Next step
See how it would work at your sites
Book a 20-minute fit call and we will walk through the four steps for your setup.