NIS2 · IEC 62443 · NCSC CAF

OT cybersecurity defensibility — independently assessed, regulator-ready.

Under NIS2, senior management carries personal liability for OT cybersecurity failures — fines for essential entities reach €10 million or 2% of global turnover. OTVerdict independently assesses your OT cybersecurity controls and reviews any supporting documentation — or guides you to build it where none exists — producing a structured defensibility report you can present to a regulator, insurer, or board. Not policy statements. Not assumptions. A documented, expert-assessed position.

15+ years OT/ICS experience·247-question framework·NIS2 · IEC 62443 · ENISA mapped·Independent. Non-vendor aligned.

What OTVerdict Does

Most organisations do not have cybersecurity documentation in a form that can be clearly presented, justified, and defended under regulatory or insurer scrutiny. OTVerdict addresses this by requiring structured evidence against each control and assessing whether that evidence is sufficient, coherent, and defensible. No existing documentation is not a barrier. Each question in the assessment specifies exactly what needs to exist to substantiate that control. Where documentation does not yet exist, the process defines what needs to be created — guiding organisations through building a defensibility evidence bank from the ground up if necessary. Whether starting from nothing or consolidating what already exists, the process produces the same output: a structured, regulator-ready evidence pack that reflects your actual position. Most organisations already have elements of cybersecurity in place. What they lack is a position that can be clearly demonstrated and defended. OTVerdict produces that position.

The OTVerdict Defensibility Model™

A five-stage defensibility spectrum describing how clearly an organisation can evidence operational security controls under regulatory or insurer scrutiny.

Assessments evaluate evidence sufficiency against expectations reflected in frameworks such as NIS2, CAF, and industrial cyber insurance reviews.

1

Reactive

Controls informal or undocumented.

2

Basic

Controls claimed but with limited supporting evidence.

3

Documented

Controls defined with partial validation.

4

Evidence-Backed

Controls supported by structured and reviewable evidence.

5

Defensible

Evidence sufficient to support regulatory or insurer scrutiny.

Detailed control domains, assessment criteria, and evidence requirements are outlined in the Assessment Framework.

View Full Framework →

Built for Industrial Operators Under Regulatory Pressure

For industrial sites facing regulatory, insurer, and board-level scrutiny.

Designed for

  • OT site managers and CISOs at NIS2 essential and important entities

  • Sites subject to NIS2 (EU 2022/2555) or the UK Cyber Security and Resilience Bill

  • Teams requiring OT-specific evidence readiness and a documented defensibility position

  • Industrial operators who need to demonstrate reasonable steps to a regulator, insurer, or board

Not suitable for

  • Organisations seeking a certification badge or formal compliance certificate

  • Pure IT environments with no operational technology in scope

  • Organisations requiring automated checklist scoring without expert review

Pressure Drivers

  • NIS2 (EU 2022/2555) — personal liability for senior management under Article 20, fines up to €10M or 2% of global turnover

  • UK Cyber Security and Resilience Bill — equivalent technical requirements for UK-regulated entities

  • Cyber insurer requirements — policies increasingly require demonstrable OT security controls

  • Board accountability — directors require documented evidence that reasonable steps were taken

Industry Sectors

EnergyWater & WastewaterManufacturingTransportDigital InfrastructureHealthcareChemicalsProcess Industries

What OTVerdict Is Not

  • A NIS2 certification or compliance guarantee

  • An automated SaaS checklist with no expert review behind it

  • An IT security framework applied to OT environments

  • Penetration testing or technical vulnerability scanning

  • Implementation or remediation of controls

What OTVerdict Is

  • Independent expert assessment by an OT practitioner — not an algorithm

  • 247-question framework across 15 OT control domains

  • Dual mapping to NIS2 Articles and ENISA Technical Implementation Guidance (EU 2024/2690)

  • Every gap documented with a prioritised remediation recommendation

  • Annual Revalidation available for ongoing regulatory assurance

What You Receive

  • Branded PDF defensibility report — executive-ready

  • RAG compliance score across all 15 OT control domains

  • Gap analysis mapped to NIS2 Articles and ENISA EU 2024/2690

  • Prioritised remediation recommendations for every gap identified

  • Defensibility statement for regulators, insurers, and boards

  • Covers NIS2 and the UK Cyber Security and Resilience Bill

Typical Timeline

  • Week 1: Scoping call — scope, tier, and fee confirmed

  • Week 1–2: Engagement confirmed, 50% invoiced upfront

  • Week 2–4: Evidence questionnaire issued and completed

  • Week 4–6: Independent expert review of submitted evidence

  • Week 6–8: Report delivered within 10 working days of complete submission

  • Optional: Annual Revalidation available for ongoing assurance

OTVerdict translates your existing controls and documentation into a structured, defensible position. This is not an automated output. It is a scored, expert-reviewed, and evidenced record of your cybersecurity position — structured for regulatory presentation, insurer submission, or board reporting. OTVerdict does not implement controls, perform penetration testing, or certify compliance.

The Assessment Portal

Purpose-built for OT environments.

The assessment portal guides each engagement from evidence submission through to scored defensibility report. Structured by control domain. Built for operational technology, not adapted from IT.

portal.otverdict.com
Command Centre — domain RAG overview
Command Centre — domain RAG overview
portal.otverdict.com
Evidence questionnaire — individual control view
Evidence questionnaire — individual control view

Frequently Asked Questions

Scope, deliverables, renewals, and what happens after the report.

Establish Your OT Defensibility Position.

A 20-minute scoping call confirms scope, fee, and timeline. No commitment required prior to formal engagement.

Typical fee: £2k–£12k·3–8 weeks delivery
Request a Scope Call