What we do
01  Advanced Infrastructure 02  Applied AI & Data 03  AI Cybersecurity 04  AI Assurance
Engagements
AI estate inventory Assurance review
Industries
Financial Services Government & Public Sector Energy & Utilities Telecommunications Healthcare & Life Sciences Transport & Logistics Industrial & Manufacturing Retail, Hospitality & Real Estate
Research
The Trust Maturity Model The GCC Assurance Index Readiness self-assessment Case studies Perspectives Sector briefings Technology evaluations
Company
About us Partners Events Careers Contact العربية Talk to our team
AI Cybersecurity  ·  OT Security

You cannot turn it off to fix it.

On an operational estate the objective is rarely data. It is visibility, control, and the ability to keep running safely — and every recommendation has to be written against a maintenance window rather than against a best practice.

6–12 WEEKSWRITTEN AGAINST YOUR MAINTENANCE WINDOWSSAFETY CASE RESPECTED
The decisions underneath

Three questions decide the design.

OT security fails when a corporate playbook is applied to an estate that cannot accept it. These are the three questions that keep it honest.

01

Do the two estates really fail independently

Shared identity, shared DNS, and an engineering laptop that lives on both sides. Independence is asserted far more often than it is verified.

02

Who owns the crossing

The single most common blank on an org chart is the boundary between corporate IT and operations. Both sides assume the other holds it.

03

What can you actually change, and when

A recommendation that requires an unscheduled outage is not a recommendation. Sequencing against real maintenance windows is most of the work.

How the path runs

The crossing nobody owns.

On an operational estate the objective is rarely data. It is visibility, control, and the ability to keep running safely. Choose an entry point.

ENTRY

FOOTHOLD

CREDENTIAL

LATERAL

OBJECTIVE

ATTACK PATH— GATES USUALLY PRESENT
Select an entry point

Five stages, from the way in to the thing the attacker came for. What changes between paths is how long each stage stays invisible.

OT security is constrained by availability in a way corporate security is not. Every recommendation we make here is written against a maintenance window, not against a best practice.

What you receive

Findings written against your windows.

Four stages, every engagement. Hover a stage to see what happens in it.

DURATION
6–12 weeks
DELIVERABLE
Crossing map and windowed remediation plan
DELIVERED
On site for discovery; remotely thereafter
INDICATIVE FEE
[FEE BAND — pending sign-off]
The boundary

We run it. We do not audit what we run.

Three moves. Two of them are ours, and the one in the middle is deliberately somebody else’s.

MOVE 01 — OURS

We operate the capability

Detection engineering, triage, response and the reporting that goes with it. This is an operational service with a named duty owner, not an advisory engagement.

MOVE 02 — NOT OURS

Somebody else tests it

Effectiveness testing of a service Orvix runs is performed by a party that does not report to the team running it. Where a regulator or a board needs the result to carry weight, that party is not Orvix.

MOVE 03 — OURS

We close what the test opened

Detection gaps found by the test become engineering work with a date against them, and the re-test is run by the tester rather than by us.

The sharpest argument we make about other suppliers is that nobody should audit their own estate. It applies here first.
AI Cybersecurity

The rest of this pillar.

Three engagements inside this pillar. Start with the question you can name, or take the whole estate at once.

Questions we are asked

Before you ask us.

Will you scan our production network?
Not without an explicit, written agreement that active scanning is safe on the specific segment and equipment involved. The default is passive discovery, because an availability incident caused by an assessment is a worse outcome than a slower assessment.
Our OT estate is air-gapped.
It may be. It usually is not, once engineering laptops, remote vendor support, historian replication and shared identity are counted. Testing the claim is normally the first useful output of the engagement.
Can you patch our controllers?
No, and you should be wary of anyone who offers to. Patching on an operational estate belongs to whoever holds the safety case, inside a window they control. We write what needs to change and the order to do it in.
How does this relate to the detection service?
A crossing map makes detection placement possible on the operational side. Where the detection service is also operated by us, the effectiveness of that detection is still tested by somebody who does not report to the team running it.

Start with the crossing nobody owns.

Thirty minutes. If you cannot immediately name who owns the boundary between your corporate and operational estates, that is the conversation.

Book a 30-minute scoping call

ORVIX · INDEPENDENT AI & TECHNOLOGY ASSURANCE · WE DISCLOSE EVERY COMMERCIAL RELATIONSHIP ON THE PAGE FOR THE SERVICE IT BELONGS TO. WHERE LICENSING IS REQUIRED, DELIVERY IS PERFORMED BY NAMED PARTNERS UNDER THEIR OWN LICENCE.