OT / ICS Cybersecurity Services
Build an OT Security Program That Holds Up Under Pressure and Under Audit
Most OT security programs don’t fail because the technology is wrong. They fail because no one owns the program, the policies don’t match how the plant actually operates, or the team has never rehearsed what happens when an incident actually hits.
Armexa’s Risk Governance & Compliance services are built to close that gap: assessing where your program stands today, building the governance structure to sustain it, and testing your people against realistic OT incident scenarios before a real one forces the issue.
Development
Governance Model & Policy Development

Security policies that were copied from an IT template rarely survive contact with a control room. Armexa builds OT security governance structures and policy sets that assign clear ownership, reflect real operational constraints, and stand up to regulatory scrutiny — including TSA and MTSA directives where applicable.
Topics: Governance structure · Policy development · Regulatory alignment (TSA, MTSA) · Ownership & accountability
Maturity Review
Cybersecurity Program Review

A structured engagement that gives leadership a clear, evidence-based picture of your OT security program — where it stands today and what to prioritize next. Think of it as preventative maintenance for your security program: regular inspection prevents the unexpected downtime of an unmanaged risk.
Topics: Program maturity · Team structure · Standards benchmarking (IEC 62443, NIST CSF) · Risk prioritization
Contingency
Incident Response Drills & Exercises

Plans on paper don’t tell you whether your team can execute under pressure. Armexa designs and facilitates tabletop and functional exercises built around realistic OT consequence scenarios, so your IT, OT, and plant leadership teams find the gaps in a controlled room, not during a live event.
Topics: Tabletop exercises · Functional drills · Playbook validation · IT/OT coordination
Specialty
COMPLIANCE
TSA Compliance Assessments 
Evaluates pipeline and surface transportation operators against TSA Security Directives SD-02G, and related requirements — providing documented evidence of compliance and a remediation plan for identified gaps.
Topics: TSA SD-02G · Pipeline · Transportation
COMPLIANCE
MTSA Compliance Assessments
Supports maritime facility operators and vessel owners in meeting U.S. Coast Guard Maritime Transportation Security Act cybersecurity requirements, including Facility Security Plans and cyber risk assessments aligned to USCG guidance.
Topics: USCG / MTSA · Maritime · Facility Security Plan
A practical path from assessment to a sustainable program
Assess
.
Baseline your current program, policies, and readiness against recognized standards and your regulatory obligations.
Design
.
Build the governance model, policy set, or exercise plan tailored to your facility’s operations and risk profile.
Validate
.
Stress-test the program through drills and exercises that surface real gaps before they become real incidents.
Sustain
.
Leave your team with a roadmap, documented ownership, and the cadence to keep the program current.