Shaun Six, UTSI | The Cyber Security Review | Top OT Cybersecurity ConsultantsShaun Six, President
Efficiency in critical infrastructure now hinges on a delicate balance between IT systems and operational technology. The convergence of these two layers has become central to how industries operate, as speed, responsiveness, and cost control all depend on it.

However, while the digital layer evolves quickly, the physical systems underneath often do not. Many organizations still rely on aging equipment that was never built to connect with modern networks. Much of it is undocumented.

And the people who once installed and managed it? They have already left the workforce.

That knowledge gap, combined with growing digital exposure, creates costly blind spots hidden across refineries, pipelines, water systems, and transit networks. Companies often cannot say with certainty what equipment is installed, how it communicates, or where it might be vulnerable. Audits, compliance deadlines, and rising threats place added pressure on teams that are already stretched thin.

UTSI helps organizations make sense of this complexity.

What began as a control room systems integrator 40 years ago now plays a global role in protecting critical infrastructure. UTSIs work spans oil and gas, renewables, power generation, transportation, and public utilities. Its team supports companies that run complex, often undocumented environments where security gaps are easy to miss and difficult to fix.

Technical Chops To Take On Any Challenge

“UTSI has embraced technology, including AI, and uses tools like Fortinet, Nozomi, and FRENOS (a native AI platform), which scan control systems and generate a digital map of the network by identifying each connected device, access path, and weak point,” says Shaun Six, president.

Many clients operate with legacy equipment, so the process often reveals systems no one realized were still active. Once the network is visible, the team documents vulnerabilities and builds a cybersecurity roadmap using frameworks such as NERC CIP or IEC 62443 to structure their recommendations.

  • UTSI has embraced technology, including AI, and uses tools like Fortinet, Nozomi, and FRENOS (a native AI platform), which scan control systems and generate a digital map of the network by identifying each connected device, access path, and weak point


Rather than separating strategy from execution, the company supports both. It helps executive leaders shape funding requests and board presentations, while also guiding field technicians through technical fixes. Tools like Axio convert raw security data into board-level insights. Simulations from ThreatGen demonstrate how the organization would respond to a real attack and where gaps remain. These tabletop exercises go beyond compliance they educate, test, and improve response plans with every run.

One multinational company initially came in with limited buy-in and low maturity scores across its cybersecurity domains. Over two years, the team helped them transition to a more advanced posture. Simulations improved engagement across departments. Gaps were documented, and emergency response plans were rebuilt. The leadership team secured board approval for new roles and budget allocations, describing the initiative as the first board-approved proposal they had seen from a consultant in years.

More Than A Vendor Relationship

The results stem from a team that has worked on both sides of the problem. Some consultants have been with the company for decades. Others left for roles in large industrial firms before returning. That mix brings both technical depth and practical perspective across upstream and downstream energy, water systems, and control networks. Our vendor-agnostic approach means employees train directly with Siemens, Fortinet, Schneider Electric, Nozomi, AVEVA, Ignition, etc. They attend and participate in industry-specific OT Cybersecurity conferences, track emerging threats, and prepare for challenges that most others have not yet begun to address, including post-quantum security.

That level of preparation extends to UTSIs internal environment. The company has migrated its systems into a SOC 2-compliant co-location facility and uses the same architecture and protections it recommends to clients. A private SCADA lab supports R&D and internal testing. Presentations at cybersecurity forums and advisory roles on federal mandates further reflect the companys commitment to raising industry standards.

Everything delivered to clients is something UTSI has practiced first. That is what makes the work credible. And in a space where failure carries national consequences, credibility is what matters most.