KairosVector

Frequently Asked Questions


Straightforward answers about cybersecurity, compliance, OT and ICS security, AI governance, risk assessment, and how KairosVector supports organisations.

01 About KairosVector

What does KairosVector do?

KairosVector provides cybersecurity consulting focused on IT, operational technology, AI governance, risk, and regulatory requirements. The scope of each engagement is tailored to the organisation’s environment and objectives.

What types of organisations can work with KairosVector?

We work with organisations that need support with cybersecurity, operational technology, AI risk, compliance, or resilience. The engagement can be scoped around a specific assessment, regulatory requirement, security programme, or broader transformation.

How is a consulting engagement typically structured?

Engagements generally begin by understanding the organisation’s environment, objectives, and constraints. The scope, deliverables, timeline, and responsibilities are then defined before the assessment or implementation work begins.

02 IT & Cloud Security

What does an IT security assessment cover?

An assessment can review identity and access controls, network architecture, endpoint security, vulnerability management, logging, incident readiness, and security governance. The exact scope depends on the organisation’s environment and risk priorities.

How do you approach cloud security?

Cloud security reviews can cover identity and access management, network controls, data protection, logging, configuration, workload security, and the connections between cloud and on-premises environments.

What is Zero Trust?

Zero Trust is a security approach that does not automatically trust users, devices, or network locations. Access is evaluated using factors such as identity, device state, context, and policy rather than relying solely on network location.

03 OT & ICS Security

What is OT security, and how is it different from IT security?

OT security protects systems that monitor or control physical processes. Unlike many IT environments, OT must account for safety, availability, legacy equipment, operational continuity, and the potential physical consequences of a security event.

Why is IT-OT convergence a security concern?

Connections between enterprise IT and industrial environments can create additional paths for threats to reach OT systems. Security controls therefore need to account for both the business network and the operational environment.

Can OT environments be secured without disrupting operations?

Security work in OT environments should account for production schedules, safety requirements, system dependencies, and maintenance windows. Assessments and remediation should therefore be planned around operational constraints rather than applying IT controls without modification.

What is IEC 62443?

IEC 62443 is a family of standards focused on cybersecurity for industrial automation and control systems. It provides a structured approach to security across system design, components, processes, and the lifecycle of industrial environments.

04 AI Governance & Security

What is AI governance?

AI governance defines how an organisation evaluates, deploys, monitors, and manages AI systems. It can cover security, data handling, accountability, human oversight, risk management, and regulatory requirements.

Why does AI governance matter if we only use third-party AI tools?

Using third-party AI still creates questions around data, vendor risk, access, acceptable use, security, and accountability. A governance framework helps define which tools and use cases are permitted and what controls are required.

Can an AI security assessment include prompt injection and data leakage risks?

Yes. Depending on the system, an assessment can examine prompt injection, unauthorized data exposure, access controls, model and application dependencies, output handling, and other security risks relevant to the AI implementation.

05 Compliance & Standards

What is the EU Cyber Resilience Act?

The EU Cyber Resilience Act establishes cybersecurity requirements for products with digital elements placed on the EU market. organisations may need to address security throughout product design, development, maintenance, vulnerability handling, and the product lifecycle.

What is NIS2?

NIS2 is an EU cybersecurity directive that expands and strengthens cybersecurity requirements for organisations in covered sectors. Its requirements include risk management, incident handling, governance, and supply-chain security, subject to the applicable national implementation.

What is ISO 27001?

ISO/IEC 27001 is an international standard for establishing, implementing, maintaining, and continually improving an information security management system. organisations use it to manage information security risks through a structured management system.

Can KairosVector help with compliance readiness?

Compliance readiness can include gap assessment, control mapping, evidence preparation, remediation planning, and support for implementation. The exact scope depends on the applicable regulation, standard, and organisation.

06 Risk Assessment

What happens during a cybersecurity risk assessment?

A typical assessment considers the organisation’s business context, assets, threats, existing controls, vulnerabilities, and potential impact. The findings can then be prioritised into practical remediation actions based on risk and business requirements.

How is cyber risk communicated to business leadership?

Technical findings are translated into business impact, priorities, dependencies, and remediation options. This helps leadership understand which risks require immediate attention and where security investment can have the greatest effect.

Do you assess third-party and supply-chain risk?

Yes, where it is relevant to the engagement. A supply-chain review can consider vendor access, security requirements, data handling, dependencies, incident processes, and the risks associated with critical third parties.

07 Incident Response

What should an organisation do after discovering a suspected security incident?

Follow the organisation’s incident response plan, preserve relevant evidence, contain affected systems where appropriate, and involve the designated incident response and leadership teams. Actions should be coordinated carefully to avoid destroying evidence or disrupting critical operations unnecessarily.

Can KairosVector help develop incident response plans?

Incident response planning can include roles and responsibilities, escalation paths, communication procedures, evidence handling, recovery considerations, and scenario-based exercises. The plan should reflect the organisation’s technology, operations, and regulatory obligations.

Can you help organisations prepare for ransomware incidents?

Preparation can include backup and recovery reviews, incident response planning, access-control improvements, network segmentation, tabletop exercises, and recovery testing. The objective is to reduce both the likelihood and operational impact of a ransomware event.

08 Engagement & Services

Can we start with a focused assessment before a larger engagement?

Yes. A focused assessment can be a practical starting point when an organisation wants to understand a specific risk or requirement before expanding the scope. The initial scope can be defined around a system, site, regulation, or business priority.

How long does a cybersecurity assessment take?

There is no single timeline. Duration depends on the scope, number of systems or sites, availability of information, and the depth of assessment required. A focused review may be completed faster than a multi-site or enterprise-wide assessment.

How do we discuss our security requirements with KairosVector?

You can contact KairosVector with an overview of your environment, security challenge, regulatory requirement, or project objective. The initial discussion can be used to determine whether a focused assessment or broader engagement is appropriate.

Still have questions? Let’s discuss your security requirements.

Scroll to Top