COMING SOON [PERCH] is in final pre-launch. Be the first to know when it goes live. Get launch updates
THE PLATFORM [PERCH]
CYBERSECURITY IS COMPLEX. GETTING STARTED SHOULDN'T BE.

Start, organize, run and sustain your industrial cyber risk journey.

A self-guided journey, configured by certified specialists and supported by AI from the first question to the boardroom report. [PERCH] shows you where you stand, what to fix first and how you compare to your market — and turns every recommendation into visible, provable progress.

[PERCH] · THE GUIDED JOURNEY

"[PERCH] is the system of record for your industrial security journey: it tells you what you have, how exposed you are to what attackers are doing right now, what to do first — and proves, with auditable evidence, that you acted."

HOW IT WORKS

From first question to auditable proof.

STEP 01

The Assessment — one session, no installation

A structured questionnaire about your environment: sector, sites, shutdown criticality, OT usage, vendor and remote access, MFA, segmentation, backups, detection and response. In one session of objective questions you get the declared picture of your environment — the raw material for every priority that follows. Nothing to install, nothing touched in the plant.

  • Prioritized result and improvement roadmap, generated from your answers
  • Choose NIST as your framework and an additional maturity block opens up
  • Asset inventory declared manually or imported from CSV/XLSX
  • Unanswered items appear as "no evidence" — never as an invented score
app.perch.io/assessment
[PERCH] Overview dashboard with performance, exposure and readiness gauges
STEP 02

Dashboards & Actions — where remediation actually lives

The same data serves two conversations: the technical one, with the likely attack path and the controls that break it; and the executive one, with trend, benchmark and a report ready to present. Then every recommendation becomes a real action — with an owner, a deadline, a status and validation by evidence.

  • Overview, Performance, Cyber Risk, Frameworks, Assets & Pulse, Benchmark, Roadmap, Report, History
  • Actions born from gaps, the Improvement Plan, recommended defenses or external advisories
  • Validation requires evidence — silence never counts as proof of remediation
  • Export to PDF/PPTX for the board, at any time
app.perch.io/actions
STEP 03

Exposure & PULSE — see yourself the way attackers do

Set a protection target for each zone of your operation — in plain language, no standards jargon — and instantly see the distance between where you are and where you need to be. Alongside it, PULSE delivers the weekly reality check for your sector: which campaigns are active, which techniques they use, and what that means for your specific asset inventory. (Curious about the ISA/IEC 62443 security levels behind the targets? They're explained in our FAQ.)

  • Activity level, trend and executive insight for your sector, every week
  • Campaigns and techniques mapped to MITRE ATT&CK, with recommended defenses
  • Main actors shown as prioritization candidates — attribution always credited to CISA/FBI
  • Focus derived automatically from your assessment — e.g. remote access
CISA KEV CISA ICS Advisories NVD / NIST NIST CSF 2.0 CISA CPG 2.0 + OT Asset Inventory Guidance Internal MITRE ATT&CK/ICS knowledge
app.perch.io/exposure
STEP 04

Strategic Profiles — the one-page answer for the board

Where are we, where do we need to be, what do we do first — and who decided what. The Journal keeps the auditable diary of decisions; the Current and Target Profiles are versioned states; the Gap Analysis measures the distance, always separating "we don't know" from "we don't have it"; and the Improvement Plan ranks what comes first.

  • Journal: who decided what, when and why — referenced across the whole journey
  • Current Profile: today's state, versioned ("Revision N · updated on date")
  • Target Profile: the desired state, with priority, date and owner
  • Gap Analysis and Improvement Plan, linked to canonical actions
app.perch.io/profiles
MATURITY

One yardstick per customer — never two at once.

[PERCH] shows exactly one maturity model per customer, decided by the framework you choose in the assessment. No mixing, no double axis.

If you choose NIST

You see an estimated NIST CSF 2.0 Tier — Tier 1 Partial · Tier 2 Risk Informed · Tier 3 Repeatable · Tier 4 Adaptive — per function and aggregated, with the confidence of the estimate and the gap to the next tier written as an action: "to reach Tier 3, do this". Unanswered questions show as "no evidence" and never downgrade you.

If you don't choose NIST

You see OT maturity across five levels — Reactive · Basic · Defined · Managed · Optimized — calculated from the assessment domains, and only when there is enough evidence. With few domains answered, the product says "insufficient evidence" instead of inventing a level.

Your history is never lost

If you switch models, the old series stays in History labeled "previous model", a marker flags the methodology change, and the new series starts from there. The two never mix on the same axis — the same practice international rating platforms follow.

Maturity estimates are guided by NIST CSF 2.0 Tiers and based on self-assessment. They are never an official or certified tier.

THE MENU

Six areas, one profile underneath.

Home · [PERCH] Path · Operations · Exposure · Strategic Profiles · Administration. Work done in any area automatically counts as progress on the journey.

Home [PERCH] Path Operations Exposure Strategic Profiles Administration
Overview Performance Cyber Risk Frameworks Assets & Pulse Benchmark Roadmap Report External Threats History
[PERCH] · AI ASSISTANT AT WORK
AI Got questions? Ask me!

The built-in assistant supports the whole journey — clarifying questionnaire items while you answer, summarizing results, and explaining any number you question. And behind it, the [PERCH] engine runs on classic AI and machine learning with rules established by certified specialists — credible, explainable, defensible. Every plan includes a monthly allowance of AI queries.

THE LONG GAME

Your DNA gets deeper over time.

From day one, [PERCH] builds a living profile of your site: what's true today, where you need to get to, the distance between them and what to do first. It's born from your journey, your assessment and the evidence you provide — every line labeled with its origin and degree of confidence.

That profile is never rebuilt. As stronger evidence becomes available, the same lines gain depth — from declared, to documented, to observed. Your history, your targets and your decisions stay intact.

Available now

The complete journey, strategic profiles, threat intelligence for your sector and ISA/IEC 62443 exposure self-assessment.

Proven integration

Spreadsheet and third-party system import (CSV/XLSX), feeding the same profile. Public API on the roadmap.

Future evolution

Richer evidence sources feeding the same profile — no migration, no reconfiguration.

BUILT ON INTERNATIONALLY RECOGNIZED STANDARDS
NIST CSF 2.0 ISA/IEC 62443 CISA KEV & ICS MITRE ATT&CK/ICS
PLANS

Plans scale by size and governance.

The complete journey and complete threat intelligence are in every plan. What changes is how many sites and users you cover, and how much collaboration and governance you need.

STARTER
$299/mo
PROFESSIONAL
$799/mo
BUSINESS
$1,499/mo
ALLIANCE
Custom
See full plans & pricing