R.CAUDLE · Riverman · OT/ICS Personal Sheet · 2026 Rev 01 · 2026.05.11
River Caudle  //  Houston, Texas  //  River Risk Partners

Operational sovereignty, engineered.

I'm an OT security guy from rural Alabama. Twenty years in industry — mining, oil and gas, manufacturing, both process and discrete. Forty of fifty US states, most of Canada, and adjacent work across Southeast Asia, Central America, Australia, Europe, and Africa.

I design and defend the control systems behind the things that cannot fail. The plant comes first. Availability, integrity, confidentiality — in that order — with safety underneath all of it.


Position

Doctrine

Sovereignty isn't something somebody gives you. It's something you build. It means owning the infrastructure, training your own engineers, writing your own code, and being able to audit what's running on your networks.

If you can't do it, you don't own it. And if you don't own it, it's not sovereign.

That principle scales. Digital sovereignty at the national level and operational technology independence at the plant level are the same problem at different scales. Who owns the stack? Who can see the traffic? Who do the devices call home to? Who can alter the firmware?

And underneath all of that, the substrate distinction. Control systems act on physics, not on information. The plant's substrate is governed by safety, reliability, and performance — in that order. The information layer that watches it lives under confidentiality, integrity, availability. Two governance models, one architecture. The fractal doesn't collapse at the top: same unit at every level, only scope changes.

It's not a policy problem. It's an engineering problem. That's where I work.

Practice

Current

I do industrial security consulting. The form that takes, most typically: I work with customers in their brownfield environments to come up with a security plan that works for the operating environment as it sits. The customers right now are mostly discrete manufacturing and a few automotive. Some food and bev. A little chem and pharma. Oil and gas and mining when the geography calls for it. IEC 62443 underpins everything I do.

2024 —

Chief Strategy Officer · River Risk Partners

Industrial loss prevention · nuclear, energy, critical infrastructure

Strategy and architecture for operators with high-consequence assets and zero tolerance for downtime. Programs that survive when the cloud, the WAN, and the vendor portal don't.

Strategy
2015 —

Owner / Technical Principal · Northern Shield Rugged Technologies

Industrial wireless · northeast British Columbia · −40 °C to +40 °C

Field engineering for extreme-environment industrial networks across 200+ remote sites. Where the truck is a day away and the radio either works or doesn't.

Engineering
Ongoing

Founder · Industrial Independence Alliance

industrialindependence.org

A coalition and an architectural doctrine for sovereign-per-zone industrial systems. OT and IT are distinct disciplines. Convergence is a marketing word, not an engineering one.

Coalition

Stack · what I've built

Code · Doctrine · Method

When an installation of one of the most common OT security platforms — and I won't name them — costs a hundred thousand dollars US upfront in professional services plus a minimum of fifty thousand a year in licensing, that's not tenable for the African market. And honestly, it shouldn't be palatable for the rest of us either.

So I build my own. A doctrine, a method, a platform, and the open-source tooling that the doctrine and the method imply. Each piece is small. They stack.

Note: In 2026 the original GrassMarlin picked up its first CISA advisory — ICSA-26-118-01, XXE in the PCAP parser, all versions, CVSS 5.5 — and there is nobody home to fix it. The Marlin family above is what picks up where it left off.

Writing · field notes

Archive

Forty-plus pieces, published as the Riverman. Some are essays, some are CVE analyses, some are field stories from a control room nobody was supposed to be in. A selection follows; the rest live on LinkedIn.

  1. D.01 Zero Trust in OT — a three-part series on industrial independence Series
  2. D.02 The $400 Billion Lie — how the tech industry abandoned 98% of manufacturing Essay
  3. D.03 IEC 62443 gets security levels wrong, and here's why Standards
  4. D.04 The Purdue Model isn't dead — how the industry stripped a methodology down to a cartoon Essay
  5. D.05 F5 BIG-IP & CISA ED 26-01 — a critical analysis for CISOs and operational leaders Analysis
  6. D.06 The architecture of survival — why the safest systems are built like ships Essay
  7. D.07 Riverman Tales — the Frozen Lifeline Field
  8. D.08 Why an OT security guy went to GITEX Africa Dispatch
Archive · 40+ pieces · 2024 — present Read everything on LinkedIn →

Scope

Range

Twenty years across heavy industry. The geography keeps moving; the work keeps adding up. By the way — most OT work is defending legacy. Greenfield is rare, and when it shows up you have an obligation to get it right, because the decisions lock in for decades.

Geography

40 of 50 US states · most Canadian provinces
Southeast Asia · Central America · Australia · Europe · Africa

Sectors

Mining · oil & gas · manufacturing
Both process and discrete · food & bev · chem/pharma · nuclear

Scale

Largest cloud-native SCADA of its kind:
4,600 field devices · 14-state territory
Industrial wireless across 200+ remote sites

Standards

IEC 62443 underpins the practice.
Purdue / PERA · NIST · ISA

Education

MBA · Management Information Systems
BS · Finance & Management

Elsewhere

Contact

Email gets the fastest reply. Everything else is for context. If you're thinking about advisory, strategy, an architecture review, a podcast, or any of the open-source work — write.

Project · Drawing R . CAUDLE
Drawn R.CAUDLE
Scale 1 : 1
Sheet 01 / 01
Rev. 01
Drawing no. RC · 2026 · 01
Issued · Houston, Texas 2026.05.11 All writing the author's own. The plant comes first.

Riverman · river@riverman.io · MMXXVI