Most ICS security services get bought as a one time assessment, and that's exactly why they don't stick. The plant gets a hundred page report. The report gets filed. A year later the same findings are open and nobody has put a name against any of them.
The work that keeps an industrial control environment defensible is small, and it repeats. A live picture of what's on the plant floor. Control of the boundary between the plant and the business. Triage of the advisories that touch that specific gear. Proof, on a schedule, that the controls still hold.
That's a monthly line on an invoice, not a project.
MSP Pentesting delivers the testing and validation half of it channel only, under your brand. Your manufacturing client keeps seeing one provider, one logo, and one number to call.
Here's the trap. An OT environment barely changes, so an annual snapshot feels like enough. The gear doesn't change. Everything around it does. New vendor accounts, new advisories, a firewall exception for a project that ended in March, three new laptops on the engineering VLAN.
That drift is your recurring revenue.
What ICS security services cover
ICS means the systems that run a physical process. SCADA and DCS platforms, PLCs and RTUs, HMIs and engineering workstations, historians, safety systems, and the network carrying all of it. Wrap a service around that gear and it breaks into five workstreams. Every one of them repeats.
- Asset visibility. A live inventory of controllers, workstations, network gear and firmware versions, built passively. You can't defend a plant you have to rediscover every time somebody asks a question.
- Boundary and access control. The rules on the firewall between plant and business, the accounts allowed to cross it, and every remote path an equipment vendor uses.
- Advisory and vulnerability triage. CISA publishes ICS advisories continuously and every OEM runs its own bulletins. The work is deciding which ones touch this plant, what the compensating control is when patching means an outage, and writing down why.
- Detection and response built for OT. Protocol aware monitoring, alerts a controls engineer will act on, and a playbook that accounts for the fact that isolating a host might stop a line.
- Validation. Periodic testing of the boundary and the identity path into it, tabletop exercises, and evidence that the segmentation you designed still exists.
Two documents frame the whole thing. NIST SP 800-82 Revision 3 is the practical guide to securing operational technology. IEC 62443 is the standards family, and it splits by role: 62443-2-1 describes the security program an asset owner is expected to run, and 62443-2-4 sets requirements for service providers. That second one is about you, not your client.
Why the one time assessment quietly fails
A typical engagement looks like this. A specialist walks the plant over a few weeks, plugs into a span port, interviews the controls team, and hands back a thick report with findings ranked by severity.
Good work.
Twelve months later almost nothing on the list has moved. Three reasons, and none of them are about report quality.
- No owner. The findings land in the gap between IT and engineering, and they stall there.
- No budget line. Remediation was never funded, because the assessment was the funded item.
- No shelf life. A report describing a network from last spring is a historical document, and the client knows it.
An assessment is a photograph. The plant runs every day.

What goes in scope, and what stays out
Scope is the part MSPs get wrong, usually by promising too much in the first meeting. Define the service by the layer you can safely touch. The column on the left of that diagram is the whole of it: the boundary, the machines people log into, the network in between, and the identity that crosses it.
What stays out, unless you've got specialists on hand and a signed change window:
- Modifying safety instrumented systems.
- Active scanning of controllers on the process network.
- Firmware upgrades on OEM warranted equipment.
- Anything that means stopping production.
Write the exclusions into the agreement. Not into an email six months later.
One more boundary worth setting on day one. You're responsible for the security of the control environment, not for the process itself. If a batch fails, that's engineering territory. Say so in writing before you need to say it out loud.
The cadence that makes it a service
A recurring service needs a calendar, and the calendar is the thing you're really selling. This shape holds up across most manufacturing, water and utility clients.
| Cadence | Work | Deliverable | Who reads it |
|---|---|---|---|
| Monthly | Advisory triage, inventory delta, account and remote access review, firewall change review | Two page memo plus updated inventory | OT lead and IT manager |
| Quarterly | Segmentation verification, config drift review, restore check on controller programs, one tabletop | Segmentation evidence pack and exercise notes | Plant manager |
| Annually | Boundary penetration test, identity path testing, program review against IEC 62443, policy refresh | Test report with attack paths, plus a program gap review | Executives, insurers, auditors |
| Event driven | New line, new vendor connection, acquisition, major upgrade | Change review note and updated zone diagram | Project team |
Notice what isn't in that table: a big bang remediation project. The work is small and constant. That's exactly why it renews.

Deliverables that survive contact with a plant manager
Plant managers don't read a hundred pages. They read one page, then they read the exceptions. Build the deliverables accordingly.
- A current asset inventory. Exportable, with firmware versions and owners attached. For a lot of clients this one artifact justifies the fee on its own.
- The monthly advisory memo. What was published, what applies here, what you did, and what you deliberately deferred with the reason. That last column is the one an auditor circles.
- Segmentation and access evidence. Rule exports proving the boundary still matches the diagram, plus the current list of who's allowed to cross it.
- A test report with attack paths. Not a scanner dump. A narrative showing how far somebody gets from a phished office account toward the control network, and where it stopped. Our pentest report template shows the structure we use.
- A one page summary for the people who sign. Risk position, what changed this quarter, what you want funded next.
Every one of those is reusable across clients. Build the templates once and the marginal cost of the second plant drops through the floor.
How to package it as a recurring line
Pricing OT work by device count is a losing game. Nobody agrees on the count, and every renewal turns into an audit of the audit. Price per site, with bands for size.
Three tiers cover most of the market.
- Visibility. Inventory, advisory triage, monthly memo. It's your entry price, and your way into a plant that's never bought security from anybody.
- Governance. Adds access reviews, segmentation verification, change review, and one tabletop a year.
- Validation. Adds annual testing, incident response retainer hours, and executive reporting.
Two structural choices matter more than the tier names.
First, charge onboarding separately. The first baseline is real work: walking the site, building the inventory, mapping the boundary, agreeing on zones. Bundle it into month one and you'll either destroy your margin or inflate the recurring price until the deal stalls.
Second, fold the annual test into the monthly fee instead of quoting it separately every year. A separate line item invites a separate approval fight, and the test is what keeps the rest of the program honest. Spread across twelve months, it stops being a decision anybody has to make.
Twelve month minimum term. Anything shorter is an assessment with extra steps.
What to keep and what to hand off
You don't need an OT security practice to sell this. You need to be clear about which parts you own.
Keep the client relationship, the ticket flow, inventory upkeep, the monthly memo and the change reviews. That's the recurring margin, and it's work your existing team can do with training.
Hand off the specialist pieces: protocol level testing, the annual boundary pentest, and incident response surge capacity. Those need people who do it constantly, and hiring one OT tester to cover four clients doesn't pencil out. A channel only pentest partner delivers that work under your brand, so the client still sees one provider.
The failure mode is the reverse arrangement. MSPs that outsource the monthly work and keep the testing end up with no recurring margin and a capability they use twice a year.
Frequently asked questions
What are ICS security services?
They're the recurring services that keep an industrial control environment defensible: asset inventory, boundary and remote access control, advisory triage, OT aware monitoring, and periodic testing. The difference from an ICS assessment is cadence. An assessment describes a moment. A service maintains a state.
Do you have to scan the plant network?
No, and usually you shouldn't. Start passively with a tap or span port. Active scanning of controllers has caused device faults, which is why NIST SP 800-82 pushes toward passive techniques on the process network. Active work belongs in a lab, or in a maintenance window with the equipment vendor in the room.
How is this different from managing IT for the same client?
The priorities invert. Safety and availability outrank confidentiality, so a control that protects data at the cost of uptime isn't a control here, it's an incident waiting to be written up. Patch cycles get measured in years instead of weeks, and equipment stays in service well past a decade, often two. The vendor support agreement decides what you're allowed to change, not your policy. Most endpoint agents aren't supported on an HMI image either.
Where does IEC 62443 fit into a service like this?
Use 62443-2-1 as the outline for what the client program should cover, and 62443-2-4 as the checklist for your own delivery process. Neither is something you promise a client will pass. They're structure for the work, and a useful way to show a buyer that your service wasn't invented on a whiteboard.
Can an MSP sell this without an OT team?
Yes. The recurring work is inventory, review and reporting, and a trained IT team can run all of it. Bring in specialists for testing and incident response, deliver it under your own brand, and keep the relationship. That's the entire point of a channel model.
Start with one plant
ICS security services sold as a project produce a report. Sold as a program, they produce a defensible plant and a predictable invoice. The difference isn't the depth of the first engagement. It's whether anything happens in month four.
So start narrow. Baseline one site, agree what's out of scope, run the monthly cycle for a quarter, then attach the annual test once the inventory is real. If you want the testing piece scoped before you price the package, get a pentest quote and build the program around it.



.avif)
.png)
.png)
.png)

