Services
Three pillars — one goal: a defensible production.
Aganum puts OT security into practice: evaluate, build, integrate, tune — until it runs. Three service pillars cover the path — from visibility across assets and networks, to alerts your SOC understands, to protection measures that respect live operations.
Pillar 1 Visibility
OT Visibility & Asset Intelligence
You can only protect what you can see.
Building a technical OT situational picture as a basis for decisions — from vendor-neutral tool selection to continuous monitoring.
Services
-
01
Vendor-neutral evaluation and PoC design of OT monitoring platforms (including Claroty, Nozomi Networks, Dragos, Forescout, Microsoft Defender for IoT)
-
02
Integration architecture and sensor placement (SPAN/TAP, collector design, multi-site rollout)
-
03
Asset inventory and network topology along the Purdue Model
-
04
Vulnerability correlation and prioritization by reachability and asset criticality
-
05
Technical OT situational picture including a prioritized shortlist of measures
For fast initial situational pictures, Aganum additionally offers self-developed analysis tooling (passive network analysis, asset discovery, topology mapping).
Pillar 2 Detection
OT Detection & SOC Enablement
Alerts your SOC understands — and production can take seriously.
Making OT detection work in day-to-day SOC operations: use cases, tuning, and clear procedures between SOC and production.
Services
-
01
Support in connecting OT data sources to SIEM and SOC — from target architecture to coordination with the SIEM and SOC teams
-
02
Use case engineering, aligned with the customer's specific threat landscape and established best practices (including MITRE ATT&CK for ICS)
-
03
Alert tuning: baselining, whitelisting of legitimate OT communication, reduction of false positives
-
04
Runbooks and escalation paths between SOC, production, and maintenance
-
05
Measurability: making detection coverage and alert quality transparent
Pillar 3 Protection
OT Protection Engineering
Protection that doesn't endanger production.
Selecting and introducing OT protection technologies so that availability and process stability keep priority.
Services
-
01
Evaluation, compatibility testing, and piloting of OT security tools (including endpoint protection/EDR, application control, secure remote access)
-
02
Step-by-step transition from pure detection to automated remediation — including exception, rollback, and maintenance window concepts
-
03
Hardening of OT endpoints and IT/OT handover points
-
04
Support all the way into steady-state operation (operating documentation, handover to the operations teams)
Where to start? With what your plant needs.
Tell us briefly where your production OT stands — Aganum responds with an honest assessment of the right entry point. For all three pillars there are clearly scoped packages with a defined outcome.