
Independent OT Security for Cement & Mining
OEM-independent OT cybersecurity for operators in North America and Latin America. We map the plant network, fix what we find, and run the service. Nothing changes on your network without your written approval.
- L5Enterprise networkCorporate IT
- L4Site businessERP, email
- L3.5Industrial DMZFirewalls, remote access
- L3Site operationsHistorian, engineering
- L2Supervisory controlHMI, SCADA
- L1Basic controlPLCs, drives
- L0ProcessKilns, crushers, conveyors
- Proven across a fleet
- Multi-year service for a multi-plant cement operator in the USA: far fewer OT network incidents, and no production stopped by our work.
- Veteran-Owned
- Veteran-owned and operated OT cybersecurity firm.
- ISA/IEC 62443
- Industrial automation security standard guiding our assessment and architecture methodology.
- NIST SP 800-82
- NIST guide to OT security, the framework behind our ICS/SCADA risk management approach.
Industrial OT Security
Lifecycle Solutions for Critical Infrastructure
Potenza Services, Inc. is a veteran-owned OT cybersecurity and industrial network engineering firm headquartered in Tampa, Florida, founded in 2012. We assess, segment, and govern operational technology networks for cement, mining, and aggregates operators across the United States, Canada, Mexico, and Latin America, with a bilingual English and Spanish field team.
Our work is OEM-independent: we do not sell equipment or resell vendor support contracts, so the party governing the network has nothing to sell on it. Assessments and architecture follow ISA/IEC 62443, NIST SP 800-82, NIST CSF 2.0, and the Purdue Model.
- 01Network architecture
- Replace flat networks with Purdue Model architectures and zone segmentation across L0 through L5.
- 02Our own monitoring appliance
- PortGuard OT is built by Potenza and sits inside each plant. It watches the network in read-only mode and alerts our engineers before your operators notice a problem.
- 03Multi-site operations
- Every plant in the fleet follows the same assessment procedure and receives a written report each week.
How We Work
Three-Phase Engagement Model
Every engagement follows the same progression, from scoped assessment to maintained topology to full operational ownership.

01 / The Foundation
Topology Assessment
Learn more →Engineers walk the plant and document what is on the OT network: asset inventory, topology drawings, severity-rated findings, and a remediation roadmap. The assessment observes and changes nothing. Scoped per plant and delivered to a named owner on your team.

02 / Document of Record
Topology Authority
Learn more →The maintained document of record for your OT environment. Continuous topology authority, not a point-in-time pen test or an annual vulnerability scan. The operator's source of truth for what is on the network and how it connects.

03 / Operational Extension
OT Service Owner
Learn more →Operational extension of the customer's OT team. ITIL-aligned governance, ongoing service ownership across multi-plant fleets. The OT Service Owner cannot be the OT Vendor. Structural independence is the operating principle.
Ongoing operations are supported by OT Network Monitoring and Managed OT Support.
Why Potenza Services?
14+ Years Securing Critical Infrastructure
Potenza Services is a veteran-owned OT cybersecurity firm serving cement, energy, and critical manufacturing sectors. Every engagement is built on the Purdue Model, NIST SP 800-82, and ISA/IEC 62443.
Structurally independent platforms and standardized security controls allow consistent deployments across multi-site operations, regardless of region or scale.
- Founded
- 2012
- Headquarters
- Tampa, Florida
- Ownership
- Veteran-owned
- Regions
- United States, Canada, Mexico, Latin America
- Field team
- Bilingual, English and Spanish
- Standards
- ISA/IEC 62443, NIST SP 800-82, NIST CSF 2.0
- Equipment sales
- None. OEM-independent.
Frequently asked questions
Have a question that is not listed here? Contact us.
The OT Service Owner Cannot Be the OT Vendor
Operators who own their own topology, independent of the OEM that supplied the equipment, negotiate from parity, not dependency. Start with the Procurement Memo.