Critical infrastructure · Energy, water, telecom, datacenters

From the substation to the operations centre.

Infrastructure operators face two attack surfaces that rarely share a screen: the physical world around the asset and the control systems inside it. We assess both, map what depends on what, model what fails when something breaks, and put the plant's alarms on the same watch floor as the protest at the gate. One report, one set of priorities, one screen.

Physical and control-system posture togetherDependency and cascade mappingAir-gapped deployment available
Dependency mapNOMINAL
Assets 0
NODES 0
DEPENDENCIES 0
WOULD GO DARK —
PLANT ALARMS ON FLOOR YES
Inventory › Exposure › Dependencies › Cascade › PrioritiesSimulated display
2Attack surfaces, physical and control-system, assessed in one report
GraphEvery asset, link and criticality, queryable: what goes dark when this trips
ModelledFlood, earthquake and cascading-failure scenarios with recovery curves
MappedControls mapped to the regime you answer to, with the evidence
1 screenPlant alarms and the physical threat picture, ranked together on the watch
What we assess

Both surfaces. One set of priorities.

We bring an engineer who has built control-room software and an analyst who watches the world around the plant. The assessment covers both, in one report, with one set of priorities.

Control-system assessment. Asset and protocol inventory across the industrial protocols in use, alarm hygiene, network exposure checks against public scanners, and controls mapped to the IEC 62443 standard.

Cyber-physical posture. Where a control-system compromise becomes a physical event, and where a physical breach becomes a control-system one.

Dependency and cascade mapping. A governed asset registry with a dependency graph, so you can answer what goes dark when this feeder trips or this fibre is cut.

Hazard and resilience modelling. Physics-based flood and earthquake simulation, damage estimates, cascading-failure and recovery modelling for portfolios and jurisdictions.

Standards and regulatory. NERC CIP-014, CFATS, ISPS, IEC 62443 and ISO 22301 alignment, with the evidence pack to show it.

The usual split one asset

Physical security assessed byA security consultant
Control systems assessed byA separate cyber firm
Where the two meetNobody's report
What fails when this node failsTribal knowledge
The cascade nobody modelledUNPRICED
GeoBit critical infrastructure: both surfaces, the graph, the model, one screenSCOPED TO YOU
How it runs

Inventory to priorities, with the cascade in between.

STEP 1

Inventory

Assets, protocols, links and criticality into a governed registry. What you have, where it is, what talks to what.

registry
STEP 2

Exposure

Network exposure against public scanners, alarm hygiene, control gaps; and the physical picture around every asset at three scales.

both surfaces
STEP 3

Dependencies

The graph: feeders, fibres, pumps, substations, sites and the people who depend on them.

graph
STEP 4

Cascade

Hazard scenarios run through the graph: what goes dark, for how long, and what it costs. Recovery curves and investment cases.

modelled
STEP 5

Priorities

One roadmap for both surfaces, ranked by exposure reduced per dollar, with the regulatory evidence pack and the playbooks for incidents that cross the boundary.

one roadmap
Engineer

Inside the control room

Someone who has built control-room software: inventory, protocols, alarm management, exposure, and the controls that map to the standard.

Analyst

Outside the fence

Someone who watches the world around the plant: the physical threat picture, the approaches, the actors, the protest forecast.

Together

On the watch floor

Plant alarms pushed to the floor beside the physical picture around the site, ranked together, with a human deciding what happens next.

What lands on your desk

Queryable, modelled, mapped to your regime.

AssessmentBoth surfaces

Control-system security assessment

Inventory, exposure, control gaps and a prioritised roadmap, with the physical posture around the asset in the same report.

WORDPDF
RegistryGoverned

Asset and dependency graph

Assets, links and criticality, queryable and mapped. Answer "what goes dark" in a sentence.

LIVEMAPGEOJSON
ModelPer scenario

Resilience model

Hazard scenarios, expected damage, recovery curves and the investment cases they justify.

WORDSHEET
PlaybooksCross-boundary

Cyber-physical playbooks

For the incidents that cross from the control room to the fence line and back.

WORD
RegulatoryEvidence

Evidence pack

Controls mapped to the regime you answer to, with the evidence behind each one.

WORDPDF
ContinuousThe watch

Physical threat picture, on the watch

Every asset watched around the clock on the managed GSOC, with plant alarms on the same screen.

LIVE
Who buys it

Operators who answer to a regulator, a board and a grid.

Energy

Grid, generation, pipelines

Substations, feeders, terminals and corridors; NERC CIP-014 alignment with the evidence.

Water

Treatment and distribution

Pumps, plants, reservoirs and the control systems that run them, overlaid with incident reporting.

Telecom

Towers, exchanges, cable landings

Dependency mapping for the fibre that everything else assumes will stay up.

Datacenters

Sites and portfolios

Community opposition, planned protests and grid dependency feeding a live rank across the estate.

Ports

Maritime and logistics

Chokepoint infrastructure, ISPS alignment, and the picture around the terminal.

Cities

Jurisdictions

Resilience modelling across portfolios and jurisdictions: what fails first, what to fix first.

A plant alarm and a protest at the gate on the same screen.

Our own control-system and resilience platforms can be deployed for operators who want them: multi-protocol ingestion, alarm management, a historian, an assistant that proposes but never executes control actions, and simulation that runs air-gapped where it must. Everything integrates with the managed GSOC.

How to start

Three steps. The first one is the form below.

Day 1

Tell us the asset

The site or portfolio, the control systems in play, the regime you answer to, and what prompted the question.

Next business day

Scope, date, team

What the assessment covers, remote or on site, when the report lands, and the quote. The engineer and the analyst are named.

On the date

The report, the graph, and a call

Walked through with your operations and security leads. The assets can go onto the watch the same week.

Side by side

Two vendors and a gap, or one assessment.

The jobTwo vendorsGeoBit critical infrastructure
Physical and control-system postureTwo reports that never meetOne report, one set of priorities
What fails when this failsTribal knowledgeA governed dependency graph you can query
HazardsA paragraphPhysics-based scenarios with damage, recovery curves and investment cases
Regulatory evidenceAssembled before the auditControls mapped to the regime, with evidence, as part of the work
After the reportNext year's reportAssets on the watch; plant alarms beside the physical picture
DeploymentCloud onlyOur cloud, yours, on site, or air-gapped
Get in the door

Start with one product. Or one month. Or tell us what you need.

You do not have to hire a desk to start. Pick one fixed first thing, or describe something else entirely, tell us where and when, and a person comes back within one working day with a scope, the date it lands, and the quote. Say yes and the work starts the next business day.

Rather talk first? Book 30 minutes · or call +1 (202) 972-1938
One system, many chairs

This page is one chair. The whole system comes with every one.

Hire any desk on this site and the platform, the watch, the other desks and the people come with it. Nothing is a module.

See everything included →
More ways to hire us

The rest of the lineup.

Assess an asset.

Tell us the asset, the control systems in play and the regime you answer to. We come back within one working day with a scope, a date and a quote.

— or —
Book a call directly
Or call us now: +1 (202) 972-1938