ICS Cyber Security For MSPs And
MSSPs — And Their Clients
Deliver scalable ICS security services aligned with Israel’s Ministry of Environmental Protection requirements using Cynomi’s AI-powered vCISO platform. Automate risk assessments, build required documentation, and help facilities that handle hazardous materials protect the systems that keep people safe.


What is ICS Cyber Security and Why
Does It Matter for MSPs and MSSPs?

ICS Cyber Security is a mandatory Israeli regulatory framework issued by the Ministry of Environmental Protection. It sets cybersecurity requirements for the industrial control systems (ICS) and operational technology (OT) used in facilities that store or use hazardous materials, as a condition of the facility’s Toxins Permit. The goal is to prevent cyberattacks on control systems from triggering hazardous materials incidents that endanger public safety and the environment.
For MSPs and MSSPs, this framework opens a clear service opportunity in Israel’s industrial sector. Most facilities that handle hazardous materials run lean IT teams with little or no OT security expertise, yet they must demonstrate compliance to keep their permit. Providers can deliver the required risk surveys, network segmentation plans, policies, and ongoing oversight as structured, recurring services.
What Organizations Does
ICS Cyber Security Apply To?
The framework applies to facilities in Israel that store or use hazardous materials under a Toxins Permit. It is especially relevant for:
Chemical Manufacturing and Processing Plants
Hazardous Materials Storage and Logistics Facilities
Energy, Fuel, and Gas Infrastructure
Water and Wastewater Treatment Facilities
Pharmaceutical and Food Production Plants
MSPs and MSSPs Serving Industrial Clients in Israel
ICS Cyber Security Core Components
The framework focuses on protecting the operational systems that control hazardous processes. Core requirement areas include:
Governance and Accountability
Appoint a responsible owner for ICS cybersecurity and define clear organizational policies.
Cyber Risk Survey
Conduct periodic risk assessments covering the facility’s control systems and hazardous processes.
Network Segmentation
Separate operational (OT) networks from IT networks and the internet to contain threats.
Access Control and Secure Remote Access
Restrict physical and logical access to control systems, with tight governance of remote and vendor connections.
Monitoring and Incident Response
Detect anomalies in control environments, respond to cyber incidents, and report significant events.
Backup and Recovery
Maintain tested backups and continuity plans to restore safe operations quickly after an incident.
Why MSPs and MSSPs
Should Align With ICS Cyber Security
Aligning with the Ministry of Environmental Protection’s requirements enables providers to serve a regulated, underserved market where compliance is tied directly to the client’s license to operate.
Deliver structured, regulation-aligned ICS security services to industrial clients
Build recurring value through risk surveys, documentation, and ongoing oversight tied to permit conditions
Help clients protect permit eligibility and avoid costly operational shutdowns
Position as a long-term partner for OT security and broader compliance frameworks
How MSPs and MSSPs Can Comply with
ICS Cyber Security and Help Clients Do the Same
Cynomi guides you step by step through managing cybersecurity and compliance.
Assess & Identify
Launch ICS-Focused Risk Assessments Mapped to Ministry Requirements
- Conduct automated assessments across governance, segmentation, access control, and incident response requirements
- Document the client’s OT environment and the hazardous processes it controls
- Generate gap analyses and risk scores that support the required cyber risk survey
Establish and Plan
Build Policies and Remediation Plans for Control System Environments
- Auto-generate required policies, including remote access, segmentation, and incident response
- Map remediation owners, timelines, and priorities based on safety impact
- Prepare documentation aligned with the facility’s permit conditions
Optimize and Track Progress
Maintain Compliance and Program Maturity Over Time
- Track progress by requirement area across all industrial clients in one dashboard
- Maintain evidence libraries and documentation for regulator reviews and permit renewals
- Monitor posture continuously so compliance doesn’t reset every year
Framework FAQs
Yes. Facilities in Israel that store or use hazardous materials under a Toxins Permit must meet the Ministry of Environmental Protection’s cybersecurity requirements as a condition of their permit.
Industrial control systems and operational technology — including SCADA systems, PLCs, and safety systems — that monitor or control processes involving hazardous materials.
Core requirements include appointing a responsible owner for ICS cybersecurity, conducting a cyber risk survey, segmenting OT from IT networks, controlling physical and remote access, monitoring for incidents, and maintaining response and recovery capabilities.
Yes. Most facilities that handle hazardous materials lack in-house OT security expertise, making external providers the natural path to compliance — from the initial risk survey through ongoing program management.
Cynomi automates control assessments, generates required policies, assigns and tracks remediation tasks, and maintains audit-ready documentation — enabling MSPs and MSSPs to deliver ICS compliance services to industrial clients at scale.