Skip to main content
Lumiar
Home/Services/Ongoing advisory
HOW YOU CAN WORK WITH US

Ongoing advisory

Some challenges require continuity without becoming a full project. An ongoing advisory engagement gives your organization access to senior strategic and technical advice when decisions, clarifications, or complex issues arise.

The engagement can be used by organizations and public bodies that need advice for their own purposes, by consulting firms that need external OT expertise in their own engagements, and, where relevant, by owners, investors, and analysts who need independent technical and market insight.

Continuity without turning everything into a project

Some decisions must be made quickly, but arise too irregularly to justify setting up a separate project each time. In other cases, management or technical staff need an independent sparring partner over time.

Lumiar can then set up an ongoing advisory engagement with agreed capacity, availability, and response time. The capacity is used when the need arises. If an issue develops into a larger engagement, it’s agreed separately.

An external expert on your side of the table

An ongoing adviser can be used before an issue becomes a project. To challenge a supplier proposal. Prepare a difficult decision. Read a report before it goes to management. Discuss a regulatory requirement. Or give a specialist an independent perspective before they recommend a direction internally.

You get an experienced external expert to test the assessment against, in addition to the answer.

Who the engagement is for

For organizations, boards, and public bodiesSenior strategic and technical advice when decisions, priorities, or complex issues require independent judgment.
Sparring with management, the board, or technical staff before important decisions
Expert assessment of strategies, decision documents, regulations, and consultation papers
Independent assessment of difficult findings, deviations, incidents, and priorities
Participation in working sessions, workshops, and decision processes
Preparation for dialogue with regulators, auditors, suppliers, or other stakeholders
Quality assurance of direction, method, and priorities before larger measures are started
For consulting firms and partnersSenior OT expertise that can be integrated into a partner’s own engagements, with clear roles, responsibilities, and commercial boundaries.

Lumiar can take part as an independent expert adviser in the partner’s engagement. The role is agreed in advance, so it’s clear who holds client responsibility, delivery responsibility, and commercial responsibility.

Quality assurance of deliverables, reports, and recommendations
Senior expert support in client dialogue, workshops, and decision processes
Contributions to solution design, method, and quality in proposals and larger engagements
Development and quality assurance of the partner’s OT security services, methods, and templates
Competence development and expert sparring for the partner’s consultants
Market and domain understanding of industrial cybersecurity in Norway and the Nordics
For owners, investors, and analystsIndependent technical and market perspectives on industrial cybersecurity, technology, and operational risk.

The market for industrial cybersecurity is increasingly shaped by consolidation, new regulatory requirements, technology development, and changes in how industrial risk is priced and owned. Lumiar can provide independent expert insight into technology, markets, and operational conditions.

Technical and commercial assessment of companies in OT security and industrial technology
Expert support in connection with transactions, portfolio development, and strategic assessments
Assessment of OT security and technology risk in industrial companies
Insight into markets, regulations, technology trends, and the Nordic landscape
Expert sparring for owners, investment teams, and analysts
Sparring with management and boards in portfolio companies
Lumiar doesn’t provide investment advice, recommendations to buy or sell financial instruments, or valuations. We never share confidential client information or inside information.

When ongoing advisory fits

The model fits when the need is important enough to require experienced advice, but too irregular or cross-cutting to be organized as a separate project.

You face decisions that affect OT security, engineering, operations, or governance
Management or technical leads need an independent sparring partner over time
A partner or consulting firm needs senior OT expertise without building the capacity itself
SÅRBARHETER · OFFSHORE NORGE 104, CSBR 7
Nå, Neste, Aldri

Sårbarheter prioriteres etter risikoen de gir i det faktiske anlegget.

SårbarheterVurdering av OT-risiko i sammenhengMetode fra veiledningenNåHøy risiko: kan utnyttes eller angripesaktivt.Tiltak eller utbedring med en gang.NesteBør håndteres, men haster ikke.Planlegges, testes og tas i etendringsvindu.AldriLav risiko: kan ikke utnyttes, eller er utenbetydning i anlegget.Ingen patch. Beslutningen føres irisikoregisteret.Ikke patch i dagens risikobilde.Vurderes på nytt ved utløpsdato.Krav og veiledningKompenserende tiltak medjevnlig kontroll (krav 7-4)Risikoeier akseptererrisikoen (krav 7-5)Fast intervall for nyvurdering og utløpsdato(krav 7-5)Patcher testes og godkjennesfør produksjon (veiledning)
SårbarheterVurdering av OT-risiko i sammenhengMetode fra veiledningenNåHøy risiko: kan utnyttes eller angripesaktivt.Tiltak eller utbedring med en gang.NesteBør håndteres, men haster ikke.Planlegges, testes og tas i etendringsvindu.AldriLav risiko: kan ikke utnyttes, eller eruten betydning i anlegget.Ingen patch. Beslutningen føres irisikoregisteret. Ikke patch i dagensrisikobilde. Vurderes på nytt vedutløpsdato.Krav og veiledningKompenserende tiltak med jevnlig kontroll(krav 7-4)Risikoeier aksepterer risikoen (krav 7-5)Fast intervall for ny vurdering ogutløpsdato (krav 7-5)Patcher testes og godkjennes før produksjon(veiledning)

Grunnlag: Offshore Norge 104 rev. 7, CSBR 7. Nå/Neste/Aldri er en metode som veiledningen foreslår. Kravene i sidefeltet er krav 7-4 og 7-5.

VULNERABILITIES · OFFSHORE NORGE 104, CSBR 7

Now, Next, Never

Vulnerabilities are prioritized by the risk they pose in the actual plant.

VulnerabilitiesOT risk assessed in contextMethod from the guidanceNowHigh risk: exploitable or actively attacked.Mitigate or remediate immediately.NextShould be handled, but isn’t urgent.Planned, tested, and applied in a changewindow.NeverLow risk: not exploitable, or irrelevant inthe plant.No patch. The decision is recorded in therisk register.Don’t patch in the current riskpicture. Reassessed at the expirydate.Requirements and guidanceCompensating measures withregular checks (requirement7-4)The risk owner accepts therisk (requirement 7-5)Fixed review interval andexpiry date (requirement7-5)Patches are tested andapproved before production(guidance)
VulnerabilitiesOT risk assessed in contextMethod from the guidanceNowHigh risk: exploitable or activelyattacked.Mitigate or remediate immediately.NextShould be handled, but isn’t urgent.Planned, tested, and applied in a changewindow.NeverLow risk: not exploitable, orirrelevant in the plant.No patch. The decision is recorded in therisk register. Don’t patch in the currentrisk picture. Reassessed at the expirydate.Requirements and guidanceCompensating measures with regular checks(requirement 7-4)The risk owner accepts the risk(requirement 7-5)Fixed review interval and expiry date(requirement 7-5)Patches are tested and approved beforeproduction (guidance)

Basis: Offshore Norge 104 rev. 7, CSBR 7. Now/Next/Never is a method suggested in the guidance. The requirements in the side panel are requirements 7-4 and 7-5.

LIVSLØP · OFFSHORE NORGE 104
Sikkerhet gjennom livsløpet

Sikkerheten må vedlikeholdes gjennom hele livsløpet, fordi systemet, trusselbildet og evidensen endrer seg.

LivsløpProsjektOverleveringDriftEndringAvviklingPlanleggPolicy, omfang, risiko, krav ogrollerGjennomførArkitektur, tiltak og kompetanseKontrollerEvidens, verifikasjon, vurderingog målingForbedreAvvik, utbedring og oppdatertrisikoUtløser ny vurderingEndringNy sårbarhet
LivsløpProsjekt → Overlevering → Drift → Endring →AvviklingPlanleggPolicy, omfang, risiko, krav og rollerGjennomførArkitektur, tiltak og kompetanseKontrollerEvidens, verifikasjon, vurdering og målingForbedreAvvik, utbedring og oppdatert risikoDeretter tilbake til Planlegg.Utløser ny vurderingEndring → KontrollerNy sårbarhet → Kontroller

Lumiar-syntese. Offshore Norge 104 rev. 7 knytter NIST CSF 2.0 til Planlegg–Gjennomfør–Kontroller–Forbedre og krever at tiltakene styres gjennom livsløpet (kapittel 1.3 og 2).

LIFECYCLE · OFFSHORE NORGE 104

Security through the lifecycle

Security must be maintained throughout the lifecycle, because the system, the threat picture, and the evidence change.

LifecycleProjectHandoverOperationChangeDecommissioningPlanPolicy, scope, risk,requirements, and rolesImplementArchitecture, measures, andcompetenceCheckEvidence, verification,assessment, and measurementImproveDeviations, remediation, andupdated riskTriggers a new assessmentChangeNew vulnerability
LifecycleProject → Handover → Operation → Change →DecommissioningPlanPolicy, scope, risk, requirements, androlesImplementArchitecture, measures, and competenceCheckEvidence, verification, assessment, andmeasurementImproveDeviations, remediation, and updated riskThen back to Plan.Triggers a new assessmentChange → CheckNew vulnerability → Check

Lumiar synthesis. Offshore Norge 104 rev. 7 links NIST CSF 2.0 to Plan–Implement–Check–Improve and requires the measures to be managed throughout the lifecycle (chapters 1.3 and 2).

How we set up the engagement

We agree on scope, period, availability, and response time in advance. The engagement can be based on a set number of hours or other agreed capacity. Usage is documented on an ongoing basis. If an issue develops into a larger engagement, scope, responsibility, and commercial model are clarified separately.

SCOPE
What the advice will cover.
AVAILABILITY
Expected response time and form of contact.
CAPACITY
Agreed allocation for the period.
FURTHER WORK
Larger engagements are agreed separately.

Clear terms for the collaboration

Ongoing advisory works best when roles and interfaces are clear from the start.

Who holds client, delivery, and commercial responsibility when Lumiar works with a partner
Confidentiality toward the client and third parties
Potential conflicts of interest and how they’re handled
Whether market development or commercial work is part of the engagement
How larger engagements that arise along the way are defined and agreed
Read about independence and collaboration →

Questions and answers

When is ongoing advisory better than a project?
When the need consists of several decisions or issues over time, but without a fixed scope of deliverables. A defined project fits better when results, schedule, and deliverables can be clearly defined from the start.
Who leads the advisory work?
Kenneth Titlestad leads this type of advisory engagement at Lumiar. If needed, the work can be supplemented with relevant specialist expertise by agreement with the client.
How are confidentiality and conflicts of interest handled?
Confidentiality is agreed with each client, and information from one engagement isn’t shared with others. Relevant conflicts of interest are assessed before start-up and if the situation changes. Lumiar declines engagements when necessary.
Can Lumiar act as an adviser in our own engagements?
Yes. Role, client responsibility, delivery responsibility, confidentiality, and commercial interfaces are clarified before start-up.
Does Lumiar give investment advice?
No. Lumiar provides expert assessments of technology, markets, operations, and industrial risk, not recommendations to buy or sell financial instruments.

Do you need someone to test your assessment against?

If you need ongoing senior advice, a partner collaboration, or an independent assessment, we’re happy to have a first conversation about the issue and which way of working fits.