Independent OT Security for Cement & Mining

OEM-independent OT cybersecurity for operators in North America and Latin America. We map the plant network, fix what we find, and run the service. Nothing changes on your network without your written approval.

  1. L5Enterprise networkCorporate IT
  2. L4Site businessERP, email
  3. L3.5Industrial DMZFirewalls, remote access
  4. L3Site operationsHistorian, engineering
  5. L2Supervisory controlHMI, SCADA
  6. L1Basic controlPLCs, drives
  7. L0ProcessKilns, crushers, conveyors
Purdue Model: how we segment a plant network
Proven across a fleet
Multi-year service for a multi-plant cement operator in the USA: far fewer OT network incidents, and no production stopped by our work.
Veteran-Owned
Veteran-owned and operated OT cybersecurity firm.
ISA/IEC 62443
Industrial automation security standard guiding our assessment and architecture methodology.
NIST SP 800-82
NIST guide to OT security, the framework behind our ICS/SCADA risk management approach.

Industrial OT Security

Lifecycle Solutions for Critical Infrastructure

Potenza Services, Inc. is a veteran-owned OT cybersecurity and industrial network engineering firm headquartered in Tampa, Florida, founded in 2012. We assess, segment, and govern operational technology networks for cement, mining, and aggregates operators across the United States, Canada, Mexico, and Latin America, with a bilingual English and Spanish field team.

Our work is OEM-independent: we do not sell equipment or resell vendor support contracts, so the party governing the network has nothing to sell on it. Assessments and architecture follow ISA/IEC 62443, NIST SP 800-82, NIST CSF 2.0, and the Purdue Model.

01Network architecture
Replace flat networks with Purdue Model architectures and zone segmentation across L0 through L5.
02Our own monitoring appliance
PortGuard OT is built by Potenza and sits inside each plant. It watches the network in read-only mode and alerts our engineers before your operators notice a problem.
03Multi-site operations
Every plant in the fleet follows the same assessment procedure and receives a written report each week.

How We Work

Three-Phase Engagement Model

Every engagement follows the same progression, from scoped assessment to maintained topology to full operational ownership.

  1. 01 / The Foundation

    Topology Assessment

    Learn more →

    Engineers walk the plant and document what is on the OT network: asset inventory, topology drawings, severity-rated findings, and a remediation roadmap. The assessment observes and changes nothing. Scoped per plant and delivered to a named owner on your team.

  2. 02 / Document of Record

    Topology Authority

    Learn more →

    The maintained document of record for your OT environment. Continuous topology authority, not a point-in-time pen test or an annual vulnerability scan. The operator's source of truth for what is on the network and how it connects.

  3. 03 / Operational Extension

    OT Service Owner

    Learn more →

    Operational extension of the customer's OT team. ITIL-aligned governance, ongoing service ownership across multi-plant fleets. The OT Service Owner cannot be the OT Vendor. Structural independence is the operating principle.

Ongoing operations are supported by OT Network Monitoring and Managed OT Support.

Why Potenza Services?

14+ Years Securing Critical Infrastructure

Potenza Services is a veteran-owned OT cybersecurity firm serving cement, energy, and critical manufacturing sectors. Every engagement is built on the Purdue Model, NIST SP 800-82, and ISA/IEC 62443.

Structurally independent platforms and standardized security controls allow consistent deployments across multi-site operations, regardless of region or scale.

Founded
2012
Headquarters
Tampa, Florida
Ownership
Veteran-owned
Regions
United States, Canada, Mexico, Latin America
Field team
Bilingual, English and Spanish
Standards
ISA/IEC 62443, NIST SP 800-82, NIST CSF 2.0
Equipment sales
None. OEM-independent.

Frequently asked questions

Have a question that is not listed here? Contact us.

The OT Service Owner Cannot Be the OT Vendor

Operators who own their own topology, independent of the OEM that supplied the equipment, negotiate from parity, not dependency. Start with the Procurement Memo.