Brownfield-first execution
Built for existing plants, constrained networks, and mixed vendor environments instead of greenfield assumptions.
Assessment-ready consulting and low-friction OT tooling for visibility, risk assessment, and controlled testing without production drag, heavyweight agents, or vendor lock-in.
MarlinSpike beta demand is active. Free seats are capped and fulfilled. New access requests are routed to the paid waitlist and practitioner licensing path.
Traditional IT security assumptions break down in plants, substations, mines, and remote industrial networks. River Risk applies consequence-based security so teams can act on what matters operationally.
Built for existing plants, constrained networks, and mixed vendor environments instead of greenfield assumptions.
Preserve production and safety while building visibility, evidence, and response options for operators and plant leadership.
Practical tooling and workflows for plant teams, assessors, and engineers who need results without heavy outside dependencies.
MarlinSpike is the core product. Companion tools extend visibility, flow inspection, and emulation while controlled offensive testing remains restricted to vetted engagements.
Passive OT topology mapping with Purdue level auto-classification and industrial protocol deconstruction from a single pcap. Zero external dependencies.
OpenFlow visualization for deep inspection and a complete network emulator for planning, training, and DPI testing in controlled scenarios.
MarlinSpike is built to get operators and assessors to a usable outcome quickly. Start with captured traffic, generate classification context, and move into assessment-ready outputs without heavy deployment overhead.
Upload or load a packet capture from a controlled collection workflow.
Extract vendor, protocol, service, and Purdue-level context from observed traffic.
Apply practical IEC 62443-informed assessment context in the practitioner/offline path.
Generate outputs that support assessor decisions, remediation planning, and operator follow-through.
Pricing is shown publicly to reduce noise and route serious users into the correct path: limited web access, practitioner offline licensing, or multi-site discovery.
Educational and lead-in tiers for sanitized capture uploads. No live capture, no local execution, and no assessment-ready reporting.
Full offline Docker or bare metal deployment with live capture, passive mapping, protocol deconstruction, and IEC 62443 risk asset assessment workflows.
For organizations needing multi-site rollout, training, and consulting integration. Pricing is handled by discovery to scope deployment, support, and operational constraints.
"Want to get my hands on this tool."
Recent public release generated 140+ reactions and 31 comments from industrial security and controls practitioners. Messaging is now shifting from beta demand to paid access.
River Risk also validates expertise through custom OT security training delivery and published thought-leadership, including consequence-based security framing.
Route to the correct tier: Live, Practitioner, Site, or consulting-led evaluation.
Confirm environment, use case, and whether cloud upload restrictions require offline licensing.
Deliver access path with clear boundaries, deployment guidance, and escalation support as needed.