ot-ics-security

Assess OT/ICS security posture with Purdue asset inventory and IEC 62443 scoring.

Updated May 11, 2026
One-click install
npx skills add https://github.com/blamejs/exceptd-skills --skill ot-ics-security
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ot-ics-security
Source: https://github.com/blamejs/exceptd-skills/tree/main/skills/ot-ics-security
Command: npx skills add https://github.com/blamejs/exceptd-skills --skill ot-ics-security

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Legacy OT/ICS security frameworks like NIST 800-82r3 and IEC 62443-3-3 were designed for pre-AI, air-gapped industrial environments and fail to address mid-2026 threats including AI-augmented HMI attacks, IT/OT convergence risks, and state-sponsored actor TTPs. This skill eliminates the gap between outdated compliance requirements and real-world OT threat reality by providing a structured, actionable assessment methodology tailored to modern industrial control environments.

Core Features & Use Cases

  • Purdue Model Asset Inventory: Systematically catalog OT assets across all Purdue layers (L0-L4) with OS, firmware, and patch posture tracking.
  • IEC 62443 Security Level Scoring: Map each OT zone to target and actual security levels, identify gaps across foundational requirements, and align findings with regulatory controls.
  • AI-HMI and IT/OT Convergence Risk Audit: Explicitly assess AI assistant integrations, vendor remote access paths, and IT/OT bridge surfaces omitted from traditional OT security assessments.
  • Cross-Jurisdiction Compliance Mapping: Reconcile findings against global regulatory frameworks including NERC CIP, NIS2, UK CAF, AU SOCI, and ISO 27001 for multinational critical infrastructure operators.
  • Use Case: A water utility operator can use this skill to produce a complete OT security posture assessment that identifies unpatched HMI hosts running end-of-life operating systems, unmapped vendor remote access paths, and shadow AI integrations used by control room staff that would fail a NIS2 or NERC CIP audit.

Quick Start

Use the ot-ics-security skill to conduct a full OT/ICS security posture assessment for your industrial control environment, including Purdue layer asset inventory, IEC 62443 security level scoring, and AI-HMI risk evaluation.

Frequently Asked Questions about ot-ics-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess OT/ICS security for NERC CIP and NIS2 compliance?

OT security posture assessment systematically catalogs assets across Purdue layers L0-L4, scoring zones against IEC 62443 security levels to identify compliance gaps and unpatchable legacy control system risks.

How do I audit AI-augmented HMI attacks and IT/OT convergence risks?

You audit these emerging risks by evaluating AI assistant integrations, vendor remote access paths, and IT/OT bridge surfaces to uncover shadow AI usage by control room staff that traditional frameworks miss.

Does this OT security assessment handle unpatchable legacy control systems with multi-decade lifecycles?

Yes, this assessment methodology explicitly accounts for OT-specific constraints including multi-decade device lifecycles and unpatchable legacy control systems when evaluating security posture.

What is the best way to map OT incident response plans to MITRE ATT&CK for ICS?

Mapping OT incident response plans requires framework-aligned findings mapped to MITRE ATT&CK for ICS, ATLAS, and D3FEND, specifically addressing state-sponsored actor TTPs and mid-2026 threat realities.

Why do legacy NIST 800-82r3 and IEC 62443-3-3 frameworks fail against modern OT threats?

Legacy frameworks like NIST 800-82r3 and IEC 62443-3-3 fail because they were designed for pre-AI, air-gapped environments and omit modern threats like AI-augmented HMI attacks and IT/OT convergence risks.