Industrial facilities keep society running. Power plants, water systems, oil and gas networks, chemical plants, food production lines, and even amusement attractions all rely on operational technology that must stay available, safe, and reliable every hour of every day. When those systems face cyber risk, the consequences reach far beyond data loss. Production stops, safety margins shrink, and public trust erodes. The challenge has grown sharper as artificial intelligence lowers the knowledge barrier that once protected these environments. Attackers no longer need years of specialized industrial experience to move from a remote connection into the heart of a process. Defenders therefore need partners who understand both the technology and the operational realities that make generic IT security approaches unworkable.
Cutaway Security meets that need as a veteran-owned consultancy focused exclusively on industrial control systems and operational technology. The firm works with operators across critical infrastructure, including electric and energy utilities, oil and gas, natural gas, water, chemical processing, food and beverage, warehousing and distribution, and amusement attractions. Every engagement respects continuous operations and safety requirements. Findings arrive prioritized and actionable, aligned to the way each process actually runs rather than to a checklist designed for office networks.
Leadership rests with Don C. Weber, founder and principal consultant. An ISA-certified ISA/IEC 62443 Cybersecurity Expert, SANS Principal Instructor, and co-author of SANS ICS613, Weber brings deep experience testing environments the way adversaries would, building defenses that fit plant realities, researching devices and protocols, and teaching the next generation of practitioners. His credentials include GICSP, GCLD, GSTRT, and NACD Cyber-Risk Oversight certifications, along with contributions to industry standards work for amusement rides. This combination of offensive insight, defensive practicality, research rigor, and instructional reach shapes the firm’s entire approach.
Respecting Operations While Proving Security
Operators must demonstrate that their environments are secure to boards, auditors, insurers, and regulators. They must do so without interrupting production or compromising safety. Most security offerings were built for information technology and struggle to fit the constraints of industrial processes. Cutaway Security closes that gap by treating operational continuity as a non-negotiable requirement. Assessments begin with an understanding of how the process runs and progress only as far as the foundation safely allows. The result is evidence that stands up to scrutiny while leaving the plant online and the operators in control.
The firm organizes its work around four complementary disciplines. As aggressors, the team examines technology the way an adversary would, looking for unintended uses and overlooked paths while conducting authorized testing with the discipline an OT environment demands. As defenders, they help teams prevent, detect, respond, and recover in ways that match real operations, turning offensive findings into stronger controls and shrinking the window between detection and protection. As researchers, they pull apart devices, protocols, and emerging techniques so clients and the wider community gain clearer visibility into what they know and what they do not. As instructors, they spread practical knowledge through SANS courses, workshops, open-source tools, and conference presentations, raising the overall resilience of the industries they serve.
Turning Artificial Intelligence into a Defensive Advantage
The same advances that arm attackers can strengthen defenders when applied with care. Cutaway Security integrates artificial intelligence into architecture analysis, configuration review, monitoring content development, and threat-hunting support. The approach accelerates the work behind the scenes while keeping operators firmly in control. AI assists and speeds human judgment; it does not replace it and never runs autonomous actions against a live process. Work occurs in controlled accounts with model training disabled. Sensitive configurations stay private and are never used to train external models or shared across clients. Every recommendation is grounded in the specific environment and reviewed by people who understand it.
This capability already supports real engagements, including work with an electric cooperative. Architecture and configuration reviews produce prioritized, human-verified hardening steps mapped to the SANS Five ICS Critical Controls and ISA/IEC 62443. Monitoring and threat-hunting content is developed and tuned for the actual environment. When a needed tool does not exist, the team can stand up a working prototype in days, always with human oversight of the results. Open-source projects such as ICS Watch Dog and CHAPS extend the same practical mindset to the broader community.
A Measured Path from Baseline to Proven Resilience
The firm’s assessment journey meets operators where they are and advances at the pace their operations allow. An executive briefing often serves as the starting point, helping leadership organize the program and select the right next step. High-level and gap assessments establish a baseline against the Five Controls and deliver a prioritized roadmap. Architecture reviews examine segmentation, data flows, and trust boundaries against recognized industrial reference models. Security assessments confirm that controls function in the live environment without disruption. Penetration testing, including assumed-breach and related analysis, follows only when the foundation supports it and operational safety remains assured. A separate program-maturity track evaluates how security practices are implemented across the organization, measures progress, and helps leadership show clear direction to external stakeholders.
Throughout, the emphasis stays on implementation realities rather than abstract vulnerability lists. Devices and solutions were chosen for operational reasons; the work focuses on making those choices as defensible as possible. Continuous improvement begins to complement periodic assessment cycles as AI strengthens architecture and hunting capabilities. Cutaway Security positions its clients to move with that shift rather than react to it later.
The firm’s guiding principle is straightforward: go forth and do good things. Relationships matter. Communication matters. Taking care of the team, clients, and the wider community strengthens everyone involved. In an industrial landscape where cyber threats grow more accessible and the cost of disruption remains high, operators need partners who combine technical depth with genuine respect for the process. Cutaway Security delivers that combination, helping critical infrastructure organizations prove their environments are secure, keep operations running, and stay ahead of the threats that matter most.







