FAQ
Frequently asked questions
Answers to better understand RĒSUNIX's approach and IT/OT challenges.
What is the difference between IT and OT?
This difference is best understood through the nature of the systems themselves. IT manages information — emails, databases, business applications. OT controls the physical world — machines, sensors, PLCs, field infrastructure.
In IT, an update can be deployed quickly. In OT, taking a system offline can mean stopping a production line, opening a valve or interrupting a critical service. Real-time constraints, availability and personnel safety fundamentally shift the priorities:
IT · CIA model
- Confidentiality
- Integrity
- Availability
OT · SAIC model
- Safety
- Availability
- Integrity
- Confidentiality
This difference in culture and priorities is at the heart of IT/OT convergence challenges.
In which sectors is OT present?
OT is present wherever a computing system interacts with the physical world — well beyond factories and control rooms:
- Industry and processes — PLCs, SCADA, HMI, automation, conveyors, presses
- Building and home automation — BMS/BAS, HVAC, lighting, access control, video surveillance
- Transportation — rail signaling, embedded systems, fleet control, aerospace
- Energy and utilities — power grids, water, gas, telemetry
- Defense — embedded systems, tactical communications, sensitive infrastructure
- Maritime — navigation, propulsion, cargo systems
- IoT and IIoT — connected sensors, remote sites, field gateways
If it measures, controls or actuates something in the physical world — it's OT, regardless of the sector.
Does RĒSUNIX only provide cybersecurity services?
No. Cybersecurity is an important element, but it cannot be addressed in isolation. Securing a system that is not well understood — whose flows, dependencies, field constraints and operational priorities are unknown — leads to poorly calibrated decisions that can be counterproductive.
In IT/OT environments, a poorly applied security measure can block a critical communication path, introduce latency into a real-time system, or create a false sense of protection without addressing the actual risks.
This is why RĒSUNIX approaches every mandate holistically: architecture, integration, segmentation, flow documentation, controlled modernization and knowledge transfer — cybersecurity is part of that whole, not separate from it.
What deliverables are usually produced?
Deliverables vary depending on the nature of the mandate, but generally include:
- Target architectures — diagrams, topologies, network segmentation and IT/OT flows
- Flow matrices — mapping of communications between systems, zones and external access
- Technical documentation — architecture files, system sheets, procedures and operational guides
- Analysis and recommendations — findings, identified risks, priorities and action paths
- Modernization plans — phasing of changes, field constraints and milestones
- Training materials — content adapted for IT, OT, engineering, operations and management teams
All deliverables are designed to be usable, maintainable and audit-ready — not just produced to be produced.
Do you offer training?
Yes. Training is an integral part of the RĒSUNIX approach — it is not a standard product, but a response built around the client's actual needs.
Content, level, format and target audience are defined together: IT, OT, engineering, operations, maintenance, cybersecurity or management teams — based on what is missing, unclear or needs to be shared across stakeholders.
The goal is to build a common language and shared understanding of risks, field constraints and best practices — not to deliver a generic course.
Which frameworks do you use?
The frameworks used depend on the context, sector and specific requirements of the mandate. The most common in IT/OT environments:
- NIST SP 800 / SP 800-82 — cybersecurity and risk management, including the OT-specific version
- Purdue model — structuring levels, zones and IT/OT flows
- ISA/IEC 62443 — security for industrial automation and control systems
- ITSG (Canada) — Canadian guidance for sensitive systems
This list is not exhaustive. Depending on client needs, other frameworks may apply — sector-specific, regulatory or organization-specific. RĒSUNIX adapts the approach to the real context, without mechanically applying a single framework.