• Skip to primary navigation
  • Skip to main content
The Mantua Group

The Mantua Group

Simple Black and White Asset Management, Reliability Expertise, and Maintenance Execution Perfection.

  • About Us
    • Meet Our Founder
    • Meet Our Team
    • Scientific Legacy – A Century of Innovation
  • Services
    • Availability Simulation
    • Reliability Centered Maintenance
    • Fault Tree Analysis
    • Reliability Engineering
    • Asset Management
    • Asset Reliability
    • Asset Management and Reliability Consulting
    • Root Cause Analysis
    • Reliability Program Assessment
    • Maintenance Planning, Scheduling Uplift and Assessment
    • FMEA/FMECA
    • Condition Monitoring Assessment
    • Vulnerability Assessment and Analysis
    • Weibull Analysis/Failure Data Analysis / Survival Analysis
    • Other Services
      • Transportation
      • Temporary Fencing
      • Photography
      • Carpet Cleaning
  • Software
    • Isograph Software
      • Availability Workbench
        • Accelerated Life Testing (ALT)
        • Availability Simulation
        • AWB’s Maximo Portal
        • AWB’s SAP Portal
        • RCMCost
        • Weibull Module
        • Process Reliability
        • AWB API
        • AWB Enterprise
      • Reliability Workbench
        • Event Tree Analysis Software
        • Fault Tree Analysis (FTA)
        • FMEA – FMECA
        • Markov Analysis
        • Reliability Block Diagrams (RBD)
        • Reliability Growth Modeling
        • Reliability Prediction
        • RWB Weibull Module
        • RWB – System Safety Analysis (SSA)
        • RWB API
        • RWB Enterprise
        • Reliability Parts Libraries
      • Network Availability Prediction (NAP)
      • Hazardous Operations Analysis – HAZOP
      • Attack Tree Software
      • Life Cycle Cost Software
      • Data Link Manager External Systems
    • PeakAvenue Software
      • eQMS Platform
      • FMEA Software
      • Quality Management Systems
      • System Function Analysis
      • Supply Chain Management
    • Sologic Software
      • Causelink® Software
      • Causelink® RCA Software & Training
  • Industries
    • Mining
    • Rail
    • Automotive
    • Medical Technology
    • Aerospace
    • Electronics
    • Manufacturing
    • IT Security
    • Networks
    • Food and Beverage
    • Agriculture
    • Pharmaceutical
    • Defense
    • Steel
    • Super Alloy
    • Rubber
    • Transportation
  • Utilities
  • Training
  • Resources
    • Insights & News
    • White Papers
    • Case Studies
    • Podcasts
  • Contact Us
  • Show Search
Hide Search

IT Security

Industry Solution · IT Security

IT/OT Cybersecurity: A Unified Threat-and-Resilience Portfolio

Modern cybersecurity in industrial environments sits at the convergence of enterprise IT and operational technology. Pure IT-security frameworks under-address the operational dimension; pure operational-engineering frames under-address the adversarial dimension. TMG operates at the convergence, weaving the Vulnerability Assessment and Analysis service with Isograph's Attack Tree Analysis into a unified threat portfolio, and adding Network Availability Prediction as the resilience layer that quantifies operational availability under directed compromise. The result is a defensible cyber-resilience case grounded in topology, threat, and standards together.

Compliance Coverage

Built for every framework your security posture has to satisfy

The methodology and documentation we deliver is configured against the working set of standards that govern information security, risk management, and operational-technology cybersecurity across IT, OT, and the regulatory frames Australian and international operators work to.

Information Security Management
ISO/IEC 27001:2022, ISO/IEC 27002:2022, ISO/IEC 27005:2022
Risk and Control Frameworks
NIST CSF 2.0, NIST SP 800-53 Rev. 5, NIST SP 800-30, NIST SP 800-37, ISO 31000
Australian Cyber Posture
ACSC Essential Eight, Information Security Manual (ISM), Protective Security Policy Framework (PSPF)
OT and Sector Standards
IEC 62443 series (industrial cybersecurity), TS 50701 (railway cybersecurity), PCI DSS v4.0, SOC 2
The CIA Triad

Confidentiality, Integrity, and Availability: the framework that organises the portfolio

The CIA triad is the foundational lens through which information security organises its threats, its controls, and its assurance activities. The TMG portfolio addresses each pillar with purpose-built methods, and the Availability pillar in particular carries the operational-technology dimension that distinguishes industrial cybersecurity from enterprise IT alone.

Confidentiality

Protection of information from disclosure to unauthorised parties. The working concerns are access control, encryption at rest and in transit, identity and access management, privileged access management, multi-factor authentication, data classification, and the privacy-management overlay (ISO/IEC 27701) when personally identifiable information is in scope. The threat surface is the path from an outsider, an insider, or a compromised credential to the data that should not have left the perimeter.

Integrity

Protection of information and systems from unauthorised modification. The working concerns are configuration management, change control, logging and monitoring, integrity-monitoring controls, code-signing, supply-chain integrity, and the OT-specific concern of preserving the deterministic behaviour of industrial control logic against unauthorised reconfiguration. The threat surface is everywhere an unauthorised actor can write where they should not be able to.

Availability

Protection of authorised access to information and systems. The working concerns are redundancy, backup, business continuity and disaster recovery (BCP / DR), recovery time and recovery point objectives (RTO / RPO), denial-of-service resilience, and the operational-technology dimension of maintaining production availability when nodes are compromised. This is where Network Availability Prediction (NAP) sits in the TMG portfolio: modelling the operational availability the network maintains under directed adversary action, not just under random component failure.

Where the Friction Lives

The challenges we address

Vulnerability backlogs grow faster than they shrink

CVE feeds publish thousands of new vulnerabilities per month; estate scanning identifies tens of thousands of findings; the remediation team closes a fraction of them. The backlog grows because inflow exceeds outflow, and the risk profile drifts despite the work being done. Without prioritisation grounded in real attack-path analysis, the team spends time on the wrong findings.

Threat modelling runs disconnected from vulnerability scanning

Most organisations operate vulnerability scanning and threat modelling as parallel activities, with scan output and threat models held in different tools and reviewed by different teams. The combinatorial attack paths a real adversary would compose across multiple vulnerabilities remain unanalysed, and the kill-chain logic that distinguishes a high-risk vulnerability from a benign one is left implicit.

Availability cases assume random failure, not directed compromise

Conventional availability modelling addresses random component failure. The resilience question, what operational availability the system maintains under directed adversary action that disables specific nodes, is rarely modelled at all. The gap between engineered availability and the availability achievable under attack is invisible to the operator until the day it matters.

IT/OT convergence outpaces the security-engineering frame

Industrial control systems, SCADA networks, asset-management platforms, and condition-monitoring telemetry sit alongside enterprise IT and inherit its threat surface. Pure IT-security frameworks under-address the operational dimension; pure operational-engineering frames under-address the adversarial dimension. The convergence is where TMG concentrates.

The Unified Threat-and-Resilience Portfolio

VAA, Attack Tree Analysis, and NAP: three methods, one portfolio

The TMG implementation weaves three connected practices into a single working portfolio: Vulnerability Assessment and Analysis identifies the exploitable conditions across IT and OT, Isograph Attack Tree Analysis composes them into the multi-step attack paths an adversary would actually follow, and Network Availability Prediction (NAP) models the operational availability the network maintains when those attack paths succeed. The three methods share component data and integrate within the broader Isograph reliability and availability platform, so the threat assessment, the kill-chain analysis, and the resilience case live on the same data model rather than in disconnected tools.

VAA · OT and IT Convergence

Vulnerability Assessment and Analysis (VAA)

TMG's Vulnerability Assessment and Analysis service identifies operational and cyber vulnerabilities through a structured eight-step methodology rooted in HAZOP-style facilitation: scoping, asset identification, threat modelling, vulnerability identification (automated scanning plus manual review of configurations, P&ID and PFD context, corporate topology), classification, severity assessment, risk calculation, prioritisation, and reporting. The scope spans IT infrastructure, OT control systems, identity, configurations, missing patches, missing procedures, and management-of-change gaps. The deliverable is a prioritised remediation backlog the operations team can actually work.

ATA · MITRE ATT&CK · Kill Chain

Isograph Attack Tree Analysis

Where the VAA identifies the individual weaknesses, Attack Tree Analysis composes them into the multi-step attack paths a real adversary would follow. Each leaf is an exploitable condition; each branch is the AND or OR logic the attacker traverses to reach a defined hostile outcome. The tree quantifies the probability of each path, the cumulative cost of compromise, and the effectiveness of each defender countermeasure. TMG implements ATA using the Isograph attack tree platform, with mapping to MITRE ATT&CK tactics, techniques, and procedures so the threat language ties to the broader industry framework.

NAP · Availability Under Compromise

Network Availability Prediction (NAP)

Conventional reliability analysis asks what availability the system maintains under random component failure. The cyber-resilience question is what operational availability the system maintains under directed compromise, when an adversary has disabled, encrypted, or denied service to one or more nodes. Network Availability Prediction (NAP) models the network topology and re-computes operational availability against the scenario sets that the Attack Tree Analysis produces. The result is a resilience case grounded in topology and threat together, not topology alone.

Risk Framework Integration

Integration with ISO 27005, NIST RMF, and the ACSC posture

TMG's vulnerability and threat work plugs into the risk-management framework the organisation already operates under: ISO/IEC 27005 for information security risk management, NIST SP 800-30 and 800-37 for the broader Risk Management Framework, the ACSC Essential Eight for the Australian cyber-hygiene baseline, and the ISM and PSPF where Australian Government engagement is in scope. The findings register translates directly into the corporate risk register without methodological friction.

IR · Tabletop · Playbooks

Incident-response readiness grounded in the analysis

The output of VAA, Attack Tree Analysis, and NAP is also the input to incident-response readiness. The attack-tree scenarios become the tabletop exercises; the NAP outputs become the resilience targets the IR playbooks have to defend; and the vulnerability backlog becomes the corrective-action queue that closes the loop. The result is an IR capability tested against real threat composition, not generic incident scripts.

Reported Outcomes

What the unified portfolio delivers

The descriptors below characterise the typical outputs of a TMG IT/OT security engagement. Depth in any given engagement scales with the size and complexity of the environment, the maturity of the existing security programme, and the regulatory exposure of the operator.

Prioritised
Vulnerability Remediation Backlog
Modelled
Multi-Step Attack-Tree Scenarios
Quantified
Operational Availability Under Compromise
Mapped
MITRE ATT&CK Coverage

Engage TMG for your cyber-resilience programme

The Mantua Group delivers vulnerability assessment, attack tree analysis, and network availability prediction for operators working at the IT / OT convergence under ISO/IEC 27001, NIST CSF, the ACSC Essential Eight, the ISM and PSPF, IEC 62443, and TS 50701. We bring the analytical rigour, the standards familiarity, and the implementation discipline that turns a threat assessment into a defensible cyber-resilience case.

Discuss your programme Vulnerability assessment service
Australia
Ocean Grove, Victoria 3226
+61 (0) 439 118 714
United States
Mantua, Ohio 44255
+1 (330) 294-3744
Email
contact@mantua.group
mantua.group

Software Expertise

Reliability Workbench (RWB)
Availability WorkBench (AWB)
Network Availability Prediction (NAP)
Sologic Root Cause Analysis (RCA)
HAZOP

Terms & Policies

Terms of Service
Privacy Policy
Support Terms
Cookie Policy

Useful Links

FAQ
Training
Latest News
Support

Follow Us

  • LinkedIn

The Mantua Group

Copyright © 2026 The Mantua Group · Site Designed by The Red Checker · Log in