Security
A secure offshore SOC for OT, built on read-only access
Giving a third party access to plant networks is a serious decision. Here is exactly how ForgeSOC limits access, protects your data and answers the questions you should be asking.
01 / Disclosure
Where our analysts work, stated plainly
ForgeSOC is US-led. Our L1/L2 analysts work from a dedicated, secured SOC in the Philippines. Confirmed findings escalate to US-based OT specialists. Access is read-only, and your data stays in your environment.
We say this up front because you should not have to find it in a contract. A secure offshore SOC for OT is only credible if the location, the access model and the limits are all clear before you sign.
02 / Security commitments
Security checks on every engagement
These apply to every customer and every coverage option.
- 01Read-only, least-privilege access. Analysts can view alerts and context. They cannot change your platform or your control systems.
- 02Multi-factor authentication on every account.
- 03Sessions are logged and recorded.
- 04Access runs through your secure remote access platform or a hardened jump host or VDI, never a plain VPN.
- 05Customer data is never stored on analyst endpoints.
- 06Analysts are background-checked.
- 07The SOC floor is dedicated, with biometric, multi-factor entry and a phone-free floor.
- 08Backup power from a generator and redundant connectivity keep the SOC running.
- 09A data processing agreement states what alert data leaves your environment.
03 / Read-only
Why read-only OT monitoring matters
Read-only access means a compromised analyst account cannot push a change to your PLCs, HMIs or platform. The worst case is limited by design, not by trust.
It also keeps responsibility clear. We see and report. You decide and act. That split is the same reason we do not perform containment or remediation.
04 / Questions to ask
Questions to ask any third-party OT monitoring provider
Use these with us and with anyone else you evaluate. Here are our answers.
Where do analysts physically sit?
A dedicated, secured SOC in the Philippines for L1 and L2. Escalation goes to US-based OT specialists.
What can an analyst change?
Nothing in your environment. Access is read-only and least-privilege.
How do they connect?
Through your secure remote access platform or a hardened jump host or VDI. Not a plain VPN.
Can you prove who did what?
Yes. Sessions are logged and recorded, and every account uses multi-factor authentication.
Where does my data go?
It stays in your environment. We hold US data residency, and the data processing agreement defines what alert data leaves.
Could data end up on a laptop?
No. Customer data is never stored on analyst endpoints.
Who are the people?
Background-checked analysts working on a phone-free, biometric-entry floor.
05 / Data handling
How we handle your data
Your OT data stays in your environment. Analysts view it through the access path you control, and you can end that access at any time. We do not copy plant data to local drives or analyst laptops.
Some alert data may need to leave your environment, such as ticket text or the content of a report. The data processing agreement spells out what that is, how it is protected and where it lives. US data residency applies.
The SOC itself has backup power and redundant connectivity, so a local outage does not leave your sites unwatched.
06 / Context
Frameworks you work under
Many of our customers work under ISA/IEC 62443, NIST CSF, AWIA risk assessments or FDA and GMP data integrity expectations. We design access and handling to fit alongside those programs. We do not claim to certify your compliance. Your auditors and your own policies set the rules, and we work inside them.
07 / Your control
What stays under your control
You own the access path. Analysts connect through your secure remote access platform or a hardened jump host or VDI, so you can see sessions, restrict them and end them. Nothing about our access depends on a tunnel you do not manage.
You also own the decisions. We escalate findings with context, and your team chooses the response. That keeps responsibility where it belongs and keeps our footprint in your environment as small as it can be.
If your security team wants to audit the setup, ask for the data processing agreement, the access design and the SOC floor controls before you sign. We would rather answer hard questions early.
08 / FAQ
Security questions we hear most
01Is an offshore SOC safe for critical infrastructure?
Safety comes from the controls, not the location. Read-only access, recorded sessions, hardened entry points and US escalation limit what any analyst can do.
02Can your analysts change our systems?
No. Access is read-only. We cannot push changes to your platform or control systems.
03Do you store our data?
Customer data is never stored on analyst endpoints and stays in your environment. The data processing agreement covers anything that leaves.
04Can we review your access setup first?
Yes. We are glad to walk your security team through it on a call.
Keep reading
Next step
Put our security model to the test
Book a 20-minute fit call and bring your toughest questions.