Webinar: Bridging IT–OT Gaps: OT-Led Data Transformation in Action

The Three Assessment Paths Every Critical Infrastructure Leader Must Understand

Many critical infrastructure leaders recognize that they need a Cyber Security assessment. The challenge is not awareness. The challenge is clarity. With so many assessment types available, it becomes difficult to determine which one answers the question your organization is actually trying to solve.

This confusion slows progress. It leads to misaligned expectations. It results in wasted effort, unnecessary cost, and frustration among operations, engineering, and security teams. Leaders often ask for the wrong assessment, or begin with an assessment that does not address their actual concerns. In OT environments where time, resources, and maintenance windows are limited, choosing the wrong starting point creates avoidable setbacks.

There are three primary assessment paths that support Cyber Security resilience in critical infrastructure. Each one answers a different question. Each one serves a different purpose. Understanding the difference between these assessment types is essential for choosing the right path forward.

The Confusion Problem: One Word, Many Meanings

When someone says, “We need a Cyber Security assessment,” it could mean many things. For example:

  • Are we compliant with regulations?
  • Are we mature enough to defend our OT environment?
  • Where are we most exposed to risk?
  • Are we ready for an audit?
  • What improvements should we prioritize?
  • How effective are our Cyber Security practices?


Different questions require different assessments. There is no single assessment that answers all of them. Leaders often assume that one assessment type can address every need, which is why confusion is so common.

Understanding the three main assessment categories eliminates this confusion and helps leaders make informed decisions.

Assessment 1: Posture or Maturity Assessment

A Posture or Maturity Assessment evaluates Cyber Security capability across people, processes, and technology. It does not focus on compliance or risk alone. Instead, it examines how well your Cyber Security practices function in real life, across the entire OT environment.

This type of assessment answers questions such as:

  • How effective are our Cyber Security controls?
  • Are our processes consistent and repeatable?
  • Do teams understand and follow documented procedures?
  • Does governance support execution or simply describe it?
  • Where do we have gaps in capability?


This assessment is best for organizations that want a holistic view of their Cyber Security strength. It is the right choice when leaders need clarity on their current state before investing in new controls, tools, or transformation initiatives.

A posture or maturity assessment provides a baseline that can be used to measure progress over time. It reveals the strengths and weaknesses that influence both compliance and operational resilience. It helps leaders avoid guessing, avoid unnecessary spending, and align their Cyber Security efforts with real capability rather than assumptions.

Assessment 2: Compliance Readiness Assessment

A Compliance Readiness Assessment focuses on verifying whether an organization is prepared to meet the expectations of a specific regulatory or standards-based framework. For Canadian critical infrastructure organizations, these frameworks often include:

  • NERC CIP
  • NIST Cyber Security Framework
  • ISO 27001
  • IEC 62443
  • TSA Pipeline Security Guidelines


This type of assessment answers questions such as:

  • Are we ready for an external audit?
  • Can we produce evidence for every required control?
  • Do our documents reflect our actual practices?
  • Where do we have compliance gaps that need immediate attention?


This assessment is not about measuring maturity. It is about verifying that controls, processes, and documentation meet regulatory expectations. Leaders choose this assessment when they have an upcoming audit, certification requirement, or regulatory deadline.

A compliance readiness assessment helps organizations avoid surprises during audits, reduce the risk of nonconformities, and streamline remediation. In critical infrastructure sectors where compliance has direct operational and regulatory implications, this assessment is essential.

Assessment 3: Cyber Security Risk Assessment

A Cyber Security Risk Assessment evaluates threats, vulnerabilities, and business impacts within the OT environment. It focuses on the adversarial side of Cyber Security by identifying what could go wrong, how it could happen, and what the operational consequences would be.

This type of assessment answers questions such as:

  • What are the highest Cyber Security risks in our OT environment?
  • Which threats are most relevant to our sector?
  • What would happen if a critical asset or system were compromised?
  • Where are we most vulnerable to attack?
  • Which improvements would reduce risk most effectively?


This assessment is ideal for leaders who need to understand operational exposure, business impact, or potential pathways adversaries could exploit. It helps organizations prioritize improvements based on risk, not assumptions or convenience. It is especially valuable for organizations that need to justify Cyber Security investments to executives or boards.

A risk assessment provides a lens that is different from both posture assessments and compliance readiness checks. It focuses on what could harm the organization and how that harm can be prevented.

Why Choosing the Wrong Assessment Creates Waste

When leaders ask for an assessment without understanding the differences, several problems occur:

  • Teams receive results that do not answer their actual questions.
  • Remediation efforts become scattered and unfocused.
  • Budget is spent on activities that do not reduce meaningful risk.
  • Compliance challenges remain unsolved.
  • Operational teams lose trust in the process.
  • Leadership becomes frustrated with unclear outcomes.


For example, an organization might request a compliance readiness assessment when what they truly need is a maturity assessment. The result would be a list of compliance gaps, but not a full understanding of capability. Conversely, requesting a maturity assessment for an upcoming audit would delay necessary compliance activities.

Choosing the wrong assessment creates misalignment that slows progress and increases cost.

How Leaders Can Choose the Right Assessment

Leaders can identify the right assessment by asking three simple questions:

Question 1: Are we trying to understand our capability or our compliance status?

Capability requires a posture or maturity assessment.
Compliance status requires a readiness assessment.

Question 2: Are we preparing for a regulatory or certification requirement?

If the answer is yes, begin with a compliance readiness assessment.

Question 3: Are we trying to understand risk or justify investment?

If so, a Cyber Security risk assessment is the most appropriate starting point.

These questions help organizations avoid confusion and choose the assessment that aligns with their goals, constraints, and operational reality.

Each Assessment Supports a Different Part of the Cyber Security Journey

Posture or Maturity Assessment = Capability
Compliance Readiness Assessment = Confirmation
Cyber Security Risk Assessment = Prioritization
Roadmap = Execution
Resilience = Outcome

When leaders understand this progression, they can plan their Cyber Security journey with clarity and confidence.

A Logical Next Step

If this article clarified some uncertainty, the deeper dive can be found inside Dexcent’s full ebook, The Pathway to OT Cyber Resilience. The guide explains:

  • The difference between posture, readiness, and risk assessments
  • How to build a Cyber Security roadmap
  • The compliance readiness gap in Canadian critical infrastructure
  • Real incidents that illustrate the cost of inaction
  • What resilience looks like in OT environments


You can access the complete guide through Dexcent’s resource library.

Sarah Burghardt

CPHR President

Read Bio

Sarah Burghardt is the President of Dexcent, responsible for the day-to-day leadership of the organization, enabling strong execution across teams and delivering exceptional value to customers. With a track record of building high-performing teams and strengthening delivery capability, she has been an integral part of Dexcent’s growth and evolution. Sarah is known for a leadership style grounded in authenticity, clarity, and collaboration, consistently embodying Dexcent’s core values of Integrity, Care, and Excellence. She brings experience spanning executive leadership, consulting, and business operations, helping organizations align people and priorities to achieve meaningful outcomes. 

Andrew Capper

Vice President of Industrial Digital Transformation

Read Bio

Andrew Capper is Vice President of Industrial Digital Transformation at Dexcent, helping industrial organizations improve data-driven decision-making by optimizing the data journey, reuniting siloed information, and delivering a trustworthy version of the truth.

With more than 25 years of experience, he is known as a results-driven leader who delivers on commitments and tackles complex information management challenges with a practical, human-centric approach. His work spans digital transformation strategy and roadmaps, governance, digital maturity assessments, and performance measurement through clear KPIs and metrics. Andrew is a NAIT graduate with training in Instrumentation Engineering Technology and Security Systems, and he brings a strong focus on safer, more effective operations from data producers through to data consumers

Nader Asgharinia

MP, P.Eng.

Vice President of Enterprise SCADA & Advanced Applications.

Read Bio

Nader Asgharinia, PMP, P.Eng., is Vice President of Enterprise SCADA & Advanced Applications at Dexcent, leading the delivery of complex, mission-critical solutions with a clear focus on client experience and operational excellence. With more than 30 years in business execution and over 25 years managing multi-million-dollar programs for mission-critical and SCADA systems, he brings a pragmatic, delivery-at-scale approach to every engagement. Nader is recognized for building high-performing teams, driving disciplined portfolio execution, and delivering measurable business outcomes, including significant growth in program portfolios and team capacity over time. He holds a B.Sc.(Hons.) in Electrical and Electronics Engineering from the University of Newcastle-Upon-Type in the UK, a B.Sc. in Computer Science from the University of Calgary, completed Georgetown University’s Director’s Program, is a Professional Engineer in Alberta, and a Project Management Professional.

Gerrit Nel

CISSP, CISM – Vice President of OT Infrastructure and Cyber Security Services

Read Bio

Tobias (Gerrit) Nel, CISSP, CISM, is Vice President of OT Infrastructure and Cyber Security Services at Dexcent, leading the development and delivery of practical services and solutions that integrate, complement, or replace OT infrastructure and protect OT assets from cyber threats. He is known for building resilient security frameworks, governance processes, and integrated solutions that reduce risk and support compliance across diverse industries. Gerrit has over 40 years of relevant IT/OT experience and has built and delivered highly skilled and high-performance delivery teams. His strengths include Cyber Security roadmaps, security architecture, incident response, and alignment to standards such as IEC 62443, NIST, and NERC CIP. Furthermore, he has deep foundational technical experience in Networking and OT infrastructure systems architectures that he leverages in building and leading successful delivery teams. Gerrit holds a B.Sc. in Computer Science from the University of Johannesburg and brings deep cross-sector experience supporting clients in oil and gas, mining, chemical, healthcare, financial, and government environments.

Jaydeep Deshpande

P.Eng. – Chief Strategy Officer (CSO)

Read Bio
Jaydeep Deshpande, P.Eng., is Chief Strategy Officer at Dexcent, where he helps shape the company’s future by connecting strategy, innovation, and execution. Having led Dexcent as President for six years, he combines 28 years of experience with a deep understanding of what it takes to scale a business while staying true to its culture and purpose.
 
Known for his people-first leadership and ability to navigate complex transformation, Jaydeep plays a central role in advancing Dexcent’s strategic priorities, strengthening key relationships, and unlocking new growth opportunities. He brings a disciplined yet human approach to change, aligning teams, accelerating growth, and ensuring the organization evolves with clarity and intent. He is passionate about building strong teams, fostering a culture grounded in integrity, care, and excellence, and positioning Dexcent to create lasting value for its customers, people, and partners.
 
He holds a Bachelor of Science in Engineering from the University of Alberta, is a Prosci Certified Change Practitioner and a Project Management Professional (PMP), and completed the CMA Accelerated Accounting Program, complemented with more than 20 years of financial management expertise.

Karim Amarshi

Chairman of the Board

Read Bio

Karim Amarshi is Chair of Dexcent’s Board of Directors, providing governance leadership and strategic oversight to support the company’s long-term strategy and executive team. With nearly 40 years as an entrepreneur and owner-operator, he is recognized for building high-performance organizations and forging strategic alliances across Information Technology, government, health care, education, and energy. He is the former co-owner and Chief Executive Officer of one of Canada’s leading enterprise Information Technology solution providers, where he led the organization through three successful mergers and helped scale long-term client and vendor partnerships. Karim remains active across a diverse business portfolio, serving as a founding principal, officer, and advisor to organizations spanning Information Technology, hospitality, manufacturing, retail, and real estate in Canada and internationally.

Yasmin Jivraj

FCIPS, I.S.P. | Board Member

Read Bio

Yasmin Jivraj, FCIPS, I.S.P., is a Board Member at Dexcent, providing executive guidance and strategic oversight to support corporate management and long-term business direction. Over a 35-year career, she has held senior leadership roles across private, public, and non-profit organizations, with a track record of building operating foundations and driving profitable growth. Following a 15-year tenure as a co-owner and President of one of Canada’s leading strategic Information Technology solution providers, she expanded her governance leadership through active board service in post-secondary education and community-focused organizations. She is recognized for decisive, purpose-led leadership, clear communication, and deep expertise in technology, business models, and methodologies that help enterprise organizations advance digital transformation.

Nadir Jivraj

CEO, Board Member

Read Bio

As Chief Executive Officer, Nadir is accountable for providing overall leadership and Dexcent’s Industrial operational performance. Nadir has been involved as an executive sponsor with Oil & Gas and Mining companies for over 35 years, and through the years has developed a strong working relationship with the Executive leadership team of many Fortune 500 companies.

Nadir is known for recognizing value and superior investment opportunities in the technology services sector. His pursuit of highly prospective technology companies around the world has resulted in numerous company start-ups. Prior to starting Dexcent, Nadir had led companies through highly profitable business transactions, including the merger of Atlas Systems Group with CompCanada (later renamed Acrodex) in 2000 and later as Chairman of the Board of Axcend Pvt – an engineering solutions provider – based in Bangalore, India from 2004 – 2014. Acrodex and Axcend were sold in 2015