FAQS

What is Critical Infrastructure?
+
Critical infrastructure encompasses the assets, systems, networks, facilities, and services essential to national security, economic security, public health, and public safety. These environments increasingly depend on interconnected cyber and physical systems, making their security and resilience essential to maintaining critical operations and essential services.
What is Critical Infrastructure Security and Resilience?
+
Critical infrastructure security and resilience encompass the strategies, programs, technologies, and operational measures used to protect essential assets, systems, networks, and services from cyber, physical, and operational threats.Effective resilience extends beyond preventing disruption. It requires organizations to anticipate threats, reduce vulnerabilities, adapt to changing conditions, maintain critical functions during incidents, and recover effectively when disruptions occur.
What are the U.S. Critical Infrastructure Sectors?
+
The U.S. Government identifies 16 critical infrastructure sectors whose assets, systems, and networks are considered vital to national security, economic security, public health, and public safety. These sectors span both public and private infrastructure and represent many of the complex operating environments OPACC supports.
Presidential Policy Directive 21 (PPD-21): Critical Infrastructure Security and Resilience advances a national policy to strengthen and maintain secure, functioning, and resilient critical infrastructure. This directive supersedes Homeland Security Presidential Directive 7. The sectors that make up U.S. critical infrastructure include:
1.
Energy
2.
Water and Wastewater Systems
3.
Transportation Systems
4.
Food and Agriculture
5.
Healthcare and Public Health
6.
Emergency Services
7.
Chemical
8.
Commercial Facilities
9.
Critical Manufacturing
10.
Dams
11.
Defense Industrial Base
12.
Financial Services
13.
Government Facilities
14.
Information Technology
15.
Communications
16.
Nuclear Reactors, Materials, and Waste
What is a Converged Operational Environment?
+
A converged operational environment is one in which information technology (IT), operational technology (OT), physical security systems, industrial control systems, connected devices, and operational processes increasingly interact and depend upon one another.
This convergence can extend across IT/OT, IoT/IIoT, ICS/SCADA, BACS/PACS, and other cyber-physical systems. As these environments become more interconnected, vulnerabilities in one domain can create operational consequences across another, requiring organizations to evaluate cyber and physical risk collectively rather than independently.    
How are Cyber and Physical Security Interdependent?
+
Cyber and physical security are increasingly interdependent as physical operations, facilities, and security systems rely on connected technologies for monitoring, access, control, automation, and decision-making. A compromise originating in the cyber domain can create physical or operational consequences, while physical vulnerabilities can expose or enable access to cyber systems.
Attack Scenario: An attacker exploits a vulnerability in a critical operational technology (OT) system and gains access. The network is compromised, causing operator loss, view, and control. Further, the attacker directly manipulates operational performance of high-risk systems causing dire consequences including physical damage resulting in a cyber-physical attack.
Understanding these dependencies is central to cyber-physical security. OPACC evaluates how systems, assets, vulnerabilities, and potential attack pathways interact across domains to identify risks that may not be apparent when cyber and physical security are assessed independently.    
What is Operational Intelligence?
+
Operational intelligence transforms threat information, intelligence reporting, open-source information, and operational data into actionable insight that supports decision-making. It helps organizations understand emerging threats, adversary activity, vulnerabilities, and changes in the threat environment that may affect their missions, personnel, assets, infrastructure, and operations.
OPACC applies operational intelligence across national security, critical infrastructure, government, and commercial environments to help clients anticipate threats, assess risk, inform protective measures, and make risk-informed operational decisions.    
How do Emerging Threats and Adversary TTPs Affect Organizations?
+
The threat environment continuously evolves as adversaries adopt new tactics, techniques, and procedures (TTPs), exploit emerging technologies, and identify new ways to target people, facilities, systems, and critical infrastructure. Understanding these changes enables organizations to evaluate how emerging threats may affect their specific operating environments rather than relying solely on historical risk assumptions.
OPACC analyzes emerging threats and adversary TTPs across cyber and physical domains to identify potential attack pathways, assess operational implications, and inform intelligence, security, and risk-management decisions.    
What is Physical Penetration Testing?
+
Physical penetration testing is a controlled assessment designed to evaluate whether an organization's physical security measures can prevent, detect, and respond to unauthorized access or other simulated threats. Testing may evaluate facilities, access controls, security procedures, personnel awareness, surveillance, perimeter security, and other protective measures within an authorized scope.
OPACC uses physical penetration testing to identify vulnerabilities and potential attack pathways that may not be apparent through traditional assessments alone, helping organizations evaluate the effectiveness of their physical security posture and prioritize corrective actions.    
What is OPACC's Cyber-Physical Security Assessment (CPSA™)?
+
OPACC's Cyber-Physical Security Assessment (CPSA™) evaluates risk at the convergence of cyber, physical, and operational environments. Conducted on-site, the assessment examines critical assets, systems, technologies, dependencies, vulnerabilities, potential attack pathways, and operational consequences across the organization.

Each CPSA™ is tailored to the organization's mission, operating environment, infrastructure, threat landscape, regulatory requirements, and existing security capabilities. Findings are analyzed and prioritized based on risk and operational impact, providing organizations with actionable recommendations to strengthen security and resilience.    
What is Cyber Penetration Testing?
+
Cyber penetration testing is a controlled security assessment that simulates real-world attack techniques to identify and validate vulnerabilities within systems, networks, applications, and other technology environments. Unlike automated vulnerability scanning alone, penetration testing evaluates whether identified weaknesses can be exploited and the potential impact of successful exploitation.
OPACC conducts penetration testing to help organizations identify exploitable weaknesses, evaluate existing defenses, understand potential attack pathways, and prioritize remediation based on risk.    
What is the Difference Between a Vulnerability Assessment and a Penetration Test?
+
A vulnerability assessment identifies and evaluates known vulnerabilities, configuration weaknesses, and other security deficiencies across an organization's systems and technology environment. It provides a broader view of potential weaknesses and helps organizations understand where security improvements may be required.

A penetration test goes further by using controlled attack techniques to determine whether vulnerabilities can actually be exploited, how an attacker could progress through an environment, and what operational or security impact could result. Used together, vulnerability assessments and penetration testing provide complementary insight into an organization's security posture.    
How Does OPACC Assess Cyber-Physical Risk?
+
OPACC assesses cyber-physical risk by examining the relationships among critical assets, technologies, physical systems, operational dependencies, vulnerabilities, threat actors, and potential attack pathways. Rather than evaluating cyber and physical findings independently, OPACC considers how vulnerabilities across domains may interact and the potential consequences to critical operations and mission objectives.
Findings are analyzed and prioritized based on threat, vulnerability, and operational consequence, providing organizations with actionable insight to strengthen defenses, allocate resources effectively, mitigate priority risks, and improve operational resilience.    
Further Questions?
Let's Talk Security.
Contact Us