Risk Advisory
Risk Managed
Some security decisions cannot be delegated to the technical team. When you are weighing a nine-figure acquisition, standing in front of your board, choosing which framework to measure your program against, or deciding whether your OT security function is actually equipped for the job, you need more than a scan report. You need judgment from people who have seen these decisions play out across many organizations and know where the risks hide.
Ampyx Cyber provides advisory services for the moments when the stakes are high and the path is not obvious. We translate technical security risk into the language of business, quantify it in terms leadership can act on, and give you the clear-eyed assessment you need to make the call. No fear tactics, no jargon, no upselling. Just straight answers from people who have sat in every seat at the table.
Standards & Frameworks
Gap Asessment
Know where you stand.
Then prove it over time.
You cannot manage what you cannot measure, and you cannot improve what you cannot benchmark. Whether an external entity requires it or you simply need to know, measuring your organization against a recognized standard or framework is fundamental to understanding the effectiveness and coverage of your security program. Done well, a gap assessment does more than produce a snapshot. Measured consistently over time, it demonstrates real improvement, justifies the investment leadership has made, and shows exactly where the next dollar should go.
Ampyx Cyber brings deep, practical experience across a wide range of standards and frameworks. We do not just know the documents. We know how they are actually applied, audited, and interpreted in the field, and we help you understand not just where the gaps are but which ones actually matter for your risk profile and your obligations.
Frameworks and standards we assess against include:
NERC CIP
NIST series, including the Cybersecurity Framework and SP 800 series
ISO 27000 series
IEC 62443
CIS Critical Security Controls
SANS 5 Critical Controls for ICS Security
TSA Security Directives
API 1164
ES-C2M2 and ONG-C2M2
CISA Cybersecurity Performance Goals
Cybersecurity Baselines for Electric Distribution Systems and DER
Cloud Security Alliance CCM
Multiple capability maturity models
Security Program Development & Improvement
An IT security team is not an OT security program.
We help you build the difference.
Many organizations have a capable security function that was built for IT and has never fully adapted to the fundamentally different demands of OT and ICS environments. The threat models are different. The consequences are different. The constraints around patching, downtime, and safety are different. A security program that works well for enterprise IT can miss the mark entirely when applied to operational technology, and the gap often does not surface until something goes wrong.
Ampyx Cyber helps organizations build or mature OT and ICS security programs that reflect the operational reality of industrial environments. We speak OT, IT, and executive fluently, and we have worked with organizations across many sectors, which means we can tell you not just what good looks like but where your program stands relative to peers of similar size, function, and budget. The goal is a program that gives you genuine control and visibility over your OT environment and improves your reliability rather than fighting against it.
Our program development services include:
OT/ICS security program assessment and gap analysis
Program design and roadmap development
Governance, policy, and organizational structure design
OT/IT convergence strategy
Program benchmarking against comparable organizations
Maturity modeling and improvement planning
Staffing and capability development guidance
Metrics and reporting design for ongoing program management
Merger & Acquisition Diligence
You’re not just buying their assets.
You’re buying their security and compliance risks.
The larger the transaction, the greater the financial risk, and the more you need to know before you sign. Industrial assets carry hidden security and compliance liabilities that never appear on a balance sheet: aging control systems, undocumented network connections, unresolved compliance violations, and security debt that the seller may not even be aware of. Discovering these after the deal closes means inheriting someone else's problems at your own expense.
Ampyx Cyber gives buyers deep visibility into the security and compliance risks embedded in industrial assets before the purchase, quantified in financial terms so you can factor them into your valuation and your negotiating position. And if you are on the selling side, we help you demonstrate strong security controls and a defensible compliance posture so you can command the value your assets deserve rather than absorbing a discount for uncertainty.
Our M&A diligence services include:
Pre-acquisition security and compliance due diligence
Financial quantification of identified security and compliance risk
Compliance liability assessment against any/all applicable regulations, standards, and frameworks
OT/ICS asset and architecture review
Sell-side security posture preparation and documentation
Post-acquisition integration risk assessment
Negotiation support and findings translation for deal teams
Executive & Board Briefings
No jargon. No fear tactics.
Just the risk, in terms the board can act on.
Regulators, shareholders, insurers, and business partners have made their expectations clear: executives and board members must understand the security risks, threats, and vulnerabilities facing their organizations. But getting that information in a form that leadership can actually absorb and act on is genuinely difficult. The terminology is unfamiliar, the complexity is daunting, and too many briefings either drown the room in technical detail or resort to fear tactics to make a point.
Ampyx Cyber briefs executives and boards in business terms. We translate the security landscape into the language of risk, consequence, and decision, applied to your specific organization and its specific obligations, without jargon and without scare tactics. Leadership walks away understanding where the organization stands, what the real risks are, and what decisions are in front of them. And when a specific question comes up between briefings, our executive phone-a-friend option means you can get a straight answer without ceremony.
Our executive and board services include:
Board and executive security risk briefings
Regulatory obligation and accountability briefings for leadership
Cyber risk quantification for executive decision-making
Incident and crisis executive advisory
Security investment and prioritization guidance
Executive phone-a-friend advisory access
Tabletop exercises and scenario briefings for leadership teams
Ask An Expert
GOT A TOUGH QUESTION?
Sometimes you just need to phone a friend. Ask us anything, any time. You don’t need to be an existing or prospective client. No cost, no hassle and no commitment. We will not put you on a contact list and our sales team won’t harass you. We will always respect your privacy. We promise. Just real answers from real experts for real problems.