Frequently asked questions
What a plant manager or IT director usually asks before the first call: who Potenza is, how OT security differs from IT, and how an engagement is scoped and delivered.
About Potenza Services
Potenza Services, Inc. is a veteran-owned OT cybersecurity and industrial network engineering firm headquartered in Tampa, Florida, founded in 2012. We assess, segment, and govern operational technology networks for cement, mining, and aggregates operators across the United States, Canada, Mexico, and Latin America, with a bilingual English and Spanish field team. Our work is OEM-independent: we do not sell equipment or resell vendor support contracts, so the party governing the network has nothing to sell on it. Assessments and architecture follow ISA/IEC 62443, NIST SP 800-82, NIST CSF 2.0, and the Purdue Model.
About Potenza →Cement, mining, and aggregates, including ready-mix and concrete batch plants, are the core focus. Cement is the only sector where Potenza has published field numbers: the 2025 State of OT Security report covers 267 OT network switches assessed across an active multi-plant cement operation, 82% of them End-of-Life or Discontinued. Adjacent sectors with the same OT characteristics include water infrastructure, energy and utilities, food and beverage, critical manufacturing, and transportation.
Industries we serve →Potenza is headquartered in Tampa, Florida, and serves operators in the United States, Canada, Mexico, and Latin America. The field team is bilingual in English and Spanish, and this site is published in both languages. Assessments are performed on active plant sites rather than from platform telemetry alone.
No. Potenza does not sell hardware, does not resell OEM support contracts, and does not take referral revenue from vendors whose access it governs. Potenza calls this structural independence: the party that governs the OT network has nothing to sell on it. It is the reason the OT Service Owner cannot also be the OT vendor.
Structural independence, defined →
OT security basics
Operational technology (OT) is the network of PLCs, HMIs, drives, and engineering workstations that runs physical processes: kilns, crushers, conveyors, and batch systems. IT security protects data and assumes modern operating systems, frequent patching, and endpoint agents. OT security protects availability and safety first: controllers often run legacy software, cannot be patched on an IT cadence, and cannot host agents without risking process stability. That is why OT security relies on network-level controls, segmentation, governed access, and passive monitoring, rather than the endpoint tools that work in the office.
IT vs OT security, in depth →The Purdue Model groups a plant's systems into levels, from field devices and controllers at Levels 0 to 2, through site operations at Level 3, to business systems at Levels 4 and 5. Segmenting by Purdue level means traffic between levels crosses a defined conduit with an explicit policy instead of a flat network. The largest change on most roadmaps is an industrial DMZ between Levels 3 and 4: business systems read production data from a replica there, vendors land on a jump host there, and updates are staged there before they reach the plant. ISA/IEC 62443 formalizes this as zones and conduits, each with a target security level.
Purdue Model, defined →ISA/IEC 62443 for zones, conduits, and security-level capability mapping; NIST SP 800-82 revision 3 for OT-specific guidance; NIST Cybersecurity Framework 2.0, including its Govern function, for program governance; and the Purdue Enterprise Reference Architecture for network levels. Where a jurisdiction or a customer adds sector rules, they map onto the same baseline.
ISA/IEC 62443, defined →A penetration test tells you what was exploitable on the day it ran. A Topology Assessment documents what is on the network, how it connects, how it is segmented, and which ISA/IEC 62443 security level each zone can support. Potenza starts with the topology because every later decision, including whether a penetration test is worth running, depends on it.
A four-stage diagnostic of a plant's OT security posture. Blind: no reliable inventory, topology, or lifecycle visibility. Aware: documented on paper but not yet controlled. Controlled: segmentation, governed access, and lifecycle management maintained for priority systems. Resilient: controls continuous and tested, so the environment degrades gracefully under stress rather than failing silently. The free OT Readiness Self-Assessment places a plant on the model in twelve questions.
Take the readiness self-assessment →
How an engagement works
Every engagement starts with a Topology Assessment, scoped per plant. Phase 2, Topology Authority, keeps that documentation as a maintained document of record with governed change tracking. Phase 3, OT Service Owner, is an operational extension of the customer's OT team with ITIL-aligned governance across the fleet. Each phase builds on the documentation from the one before, so nothing is designed or implemented before the topology is known.
The three phases →The assessment combines physical verification of switches, firewalls, and patch panels with passive and active discovery on the OT segments. It produces an OT asset inventory with lifecycle status, network topology diagrams by production area, a segmentation evidence report mapped to the Purdue Model, and a security-level capability matrix against ISA/IEC 62443. Scoping depends on the number of production areas and network closets, not on tonnage. A single integrated plant is typically one assessment, with the window defined in the statement of work before work begins.
Topology Assessment →No. The assessment is designed for a running plant, and monitoring never sits inline with control traffic or installs agents on controllers. If a planned outage falls inside the window, it is used for physical verification in areas that are otherwise hard to reach, but it is not a prerequisite. Access requirements are defined in the statement of work and coordinated with plant operations.
Governed remote and privileged access is one of the five controls in Potenza's Cement & Mining OT Baseline. In practice, every OEM, integrator, and contractor path into the plant is inventoried by vendor, then brokered through a jump host in the industrial DMZ with logging and least privilege, instead of direct connections to controllers. As OT Service Owner, Potenza governs that access on the operator's behalf, and because it sells no equipment it has no conflict of interest with the vendors whose sessions it controls. Potenza is a BeyondTrust technology partner for privileged access.
Partners →Yes, and independently of them. Existing tooling and monitoring infrastructure are assessed and integrated rather than replaced by default. Legacy SCADA and PLCs can usually be protected through segmentation, governed access, and monitoring without replacement; replacement is a lifecycle decision made from the inventory of record, not a prerequisite for security.
OEM-independent vs OEM OT security →Yes. Assessments are scoped per plant, and a multi-plant operation is sequenced so the first topology of record exists before the second plant begins. Deliverables are returned to a named owner on the operator's team, not posted to a portal or emailed to a distribution list.
Still have a question?
Write to helpdesk@potenzaservices.com or book a Topology Assessment. Both reach an engineer, not a sales queue.
Contact Potenza