CIARA is a risk assessment and management platform for industrial environments. It allows you to analyze the effectiveness and economic impact of risk mitigation measures, taking into account various factors such as: networks, assets, type of industry, sector, location, attack tactics currently used, and criticality of plant assets.
The end result is the risk assessment, its prioritization, and a set of recommendations for its mitigation: according to IEC62443 standards and indicating which controls to apply, which offer a greater reduction, and therefore, how to invest each euro to maximize cybersecurity.
Key features
Threat Intelligence
Intelligence based on simulations of real attacks.
ROI Optimization
Risk mitigation plan optimizing ROI, based on user preferences and budget.
Customizable reports
Adapt the reports to your audit needs.
Indicators by zone
Details of the level of risk and protection for each of the monitored zones.
IEC62443 compliant
Follows the zone, conduit, and fundamental requirement models defined in the IEC-62443 standards.
Prepared for OT-MSSP SOC
Managed Security Service Providers (MSSPs) have become a viable option for small and medium-sized organizations in OT looking for enterprise-level security.
How it works
Follow the steps defined in the ISA/IEC 62443 standards:
- STEP 1 (ZCR #1): Learn the network.
Through traffic monitoring and profiling software (this phrase=link to iSID), a digital model of the network is obtained that contains the assets, protocols, communications, and potential vulnerabilities of these. This information will be used in CIARA to calculate the level of exposure and vulnerability of the environment. - STEP 2 (ZCR #2-4): Initial risk modeling and analysis
The zones and conduits are defined, and the economic impact is assigned to each of them, as well as the desired level of cybersecurity (SL-T). In this way, we model our reality with the IEC62443 standard.
In addition, the type of industry and its geolocation are defined to assess the relevance of the adversaries (using the MITRE ATT&CK database) and see what threats can affect us and how. - STEP 3 (ZCR #5): Analysis of the fundamental security requirements (FR) of each zone
CIARA compares the current and desired level of cybersecurity of each zone and presents the controls (or mitigation measures) necessary to achieve the objective (SL-T) based on the IEC62443 standards. The controls are prioritized based on their contribution to risk reduction. It presents the user with a report with the detailed risk assessment, including threats, vulnerabilities, countermeasures, probabilities, etc. - STEP 4 (ZCR #6-7): Mitigation plan and cybersecurity controls
With the implementation of each control, CIARA will recalculate the overall risk score of the network, as well as the level of protection of each zone.


Get in Touch with an Expert
Fill in your information and we’ll contact you.