The decision to conduct a cyber security audit in an operational technology (OT) environment is a key step toward building real resilience. It’s also, as we know, the foundation of a successful application for funding from the Cyber Security Pipeline program. But for many managers and engineers who have never participated in such a process before, it can raise a number of questions and concerns. “Won’t the auditors disrupt our systems? What exactly will they be looking for? Do we need to prepare hundreds of documents?”
The purpose of this article is to demystify the process. We want to show that a well-conducted OT audit is not a cumbersome audit, but a fascinating process of discovery and mapping of your own infrastructure that brings tremendous value and knowledge. It’s a partnership in which outside experts bring their unique expertise to work with your team to create an objective picture of the current state and plan an effective strategy for the future.
Below is a step-by-step anatomy of our auditing process, explaining what we are auditing, why we are auditing it, and what methods we use to make the entire process as valuable to you as possible while being 100% safe for your operation.
Shortcuts
- What is the overarching goal and philosophy of our audit?
- How do we start the audit, that is, the planning and interview phase?
- What does secure OT network mapping and inventory consist of?
- How do we evaluate network architecture and segmentation?
- How do we identify technical vulnerabilities?
- What role does a physical security assessment play in an audit?
- Do we verify the security of workstations and servers, and how?
- How do we evaluate processes and procedures, or the “human factor”?
- How does the audit address the requirements of NIS2 and IEC 62443?
- What is the final product of the audit?
- What do recommendations look like and why are they so valuable?
- How do we ensure the confidentiality and security of the collected data?
- Anatomy of an OT nFlo audit: key areas of investigation
- How does nFlo, with its experience, ensure the highest quality audits?
What is the overarching goal and philosophy of our audit?
Our goal is not to “catch” you off guard or give you a negative rating. Our goal is to provide objective, fact-based knowledge that will allow you to make informed decisions about risks and investments. We approach each audit like a doctor approaches a patient - our job is to make an accurate diagnosis and propose an effective treatment plan. We operate on the basis of respect for the knowledge and experience of your engineers and a full understanding of the priorities of the production environment, where physical security and business continuity are paramount.
📚 Read the complete guide: OT/ICS Security: Bezpieczeństwo systemów OT/ICS - różnice z IT, zagrożenia, praktyki
How do we start the audit, that is, the planning and interview phase?
Each audit begins with a series of meetings and workshops with key personnel from various departments - from IT, to automation and maintenance, to plant management. The purpose of these meetings is to understand your unique context: what are the key processes, what is the history of the infrastructure, what are the biggest operational pain points and what are your business goals. We also analyze all available documentation - network diagrams, policies, procedures. This phase allows us to “learn” your organization and accurately plan the technical next steps.
What does secure OT network mapping and inventory consist of?
The foundation of any audit is the creation of an accurate map and inventory of assets. As we already know, the use of active scanners from IT for this purpose is unacceptable in OT. Therefore, the basis of our work is passive monitoring technologies. We “listen” to network traffic in a secure, non-invasive way to automatically identify all the devices running in it, their roles, software versions and interconnections. This allows us to create a complete and always up-to-date picture of the network without the risk of disrupting any process.
How do we evaluate network architecture and segmentation?
Once we have a map of the network, we analyze its architecture against industry best practices, such as the Purdue Model or IEC 62443. We check whether the network is “flat” or already has some form of segmentation. We evaluate the configuration of key network devices, such as switches and firewalls. We look for “hidden bridges” and undocumented connections between IT and OT zones. The goal is to assess how well the current architecture supports risk isolation and containment of potential attacks.
How do we identify technical vulnerabilities?
Vulnerability identification is a multi-step process. First, data from the passive inventory (information about device models and software versions) is automatically correlated with global databases of known vulnerabilities (CVEs). This allows us to immediately identify systems that have publicly known vulnerabilities. Secondly, we verify the configuration of operating systems (e.g. SCADA stations) and devices for common bugs and vulnerabilities (hardening). Finally, under tightly controlled and agreed conditions, we can conduct limited, secure active tests to verify the existence of the most serious vulnerabilities.
What role does a physical security assessment play in an audit?
Cyber security in OT is inextricably linked to physical security. That’s why our audit always includes an on-site visit and physical security assessment. We check how key locations such as server rooms, control rooms and control cabinets are protected. We evaluate access control systems, video surveillance, and access management procedures for employees and outside companies. After all, a gap in physical security can just as easily lead to an incident as a gap in software.
Do we verify the security of workstations and servers, and how?
Windows and Linux operating systems are ubiquitous in OT environments, serving as operator stations (HMIs), SCADA servers or engineering stations. They are often the primary target and entry point for attackers. As part of the audit, we conduct a detailed analysis of the configuration of these systems. We check password policies, user privilege management, update status, antivirus software configuration and the presence of unnecessary risky services.
How do we evaluate processes and procedures, or the “human factor”?
Even the best technology is ineffective without the right processes and informed people. That’s why we spend a huge part of the audit analyzing existing documentation and talking to staff. We assess the maturity of processes such as change management, backup and recovery, remote access management or incident response. We also verify that basic security policies and standards are in place and adhered to within the company.
How does the audit address the requirements of NIS2 and IEC 62443?
Our audit is not a collection of random audits. Its structure and scope are strictly based on the requirements and best practices defined in key industry documents. Each of our findings and recommendations is directly referenced to specific provisions of the NIS2 directive and the international IEC 62443 standard. As a result, the report you receive is not only a technical diagnosis, but also a formal gap analysis of compliance with applicable laws and standards.
What is the final product of the audit?
The final product of our work is a detailed yet understandable audit report for managers. This report consists of several key parts. The first is a summary for management, which describes in a non-technical way the overall level of maturity and the most important risks identified. The second, the main part, is a detailed description of all identified weaknesses and vulnerabilities, along with evidence and risk assessments.
What do recommendations look like and why are they so valuable?
The most important part of the report is a prioritized roadmap of corrective actions. We do not leave you with a list of problems alone. For each identified risk, we propose specific, practical and implementable solutions. Recommendations are divided into those to be implemented immediately, those of medium priority and long-term ones. Each recommendation is also accompanied by a cost estimate, making the entire document a ready input to the investment plan and grant application.
How do we ensure the confidentiality and security of the collected data?
We understand that the information we collect during an audit is extremely sensitive. That’s why we operate under the highest standards of confidentiality. We sign a detailed non-disclosure agreement (NDA) before we begin our work. All data collected is encrypted and stored securely, and only a limited audit team has access to it. Once the project is completed and the report is handed over, all work data is securely permanently deleted from our systems.
Anatomy of an OT nFlo audit: key areas of investigation
AreaWhat do we study?TargetNetwork ArchitectureSegmentation, topology, configuration of network devices, IT/OT connections.Assess how well the architecture supports risk isolation and defense in depth.**Resources (Assets)**Inventory, configuration and vulnerabilities of PLCs, HMIs, SCADA servers.Create a complete picture of the infrastructure and identify weaknesses.Physical SecurityAccess control to control cabinets, server rooms, tamper protection.Verify that physical safeguards are adequate for digital threats.Processes and ProceduresChange management, backups, remote access, incident response.Assessing organizational maturity and emergency preparedness.ComplianceVerification of compliance with the requirements of the NIS2 directive and IEC 62443.Identify gaps in compliance with laws and best practices.
How does nFlo, with its experience, ensure the highest quality audits?
Our audit team consists of a unique combination of experts - certified cybersecurity specialists who also have years of hands-on experience working with industrial environments. We understand both advanced attack techniques and the logic behind PLCs. This dual perspective allows us to conduct audits that are not only technically in-depth, but also fully grounded in the operational realities of your plant. Our methodology, perfected over the years in cooperation with some of the largest industrial companies in Poland, is a guarantee that the report you receive will be a document of the highest quality, providing a solid foundation for further strategic decisions.
Related Terms
Learn key terms related to this article in our cybersecurity glossary:
- Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…
- Cybersecurity Incident Management — Cybersecurity incident management is the process of identifying, analyzing,…
- NIST Cybersecurity Framework — NIST Cybersecurity Framework (NIST CSF) is a set of standards and best…
- IT Security Audit — IT security audit is a systematic evaluation of an organization’s information…
- Security Audit — A security audit is a systematic, independent, and documented process for…
Learn More
Explore related articles in our knowledge base:
- RidgeBot 6.0: AWS Security Audit and Advanced Windows Testing for Enterprises
- 5G network security: What new risks and opportunities does it bring to business?
- An in-house AI chatbot in a law firm: The biggest challenge is security
- Is a firewall alone enough? 5 myths about OT security
- IT vs OT: 5 key security differences every manager needs to understand
Explore Our Services
Need cybersecurity support? Check out:
- Security Audits - comprehensive security assessment
- Penetration Testing - identify vulnerabilities in your infrastructure
- SOC as a Service - 24/7 security monitoring
Explore Our Products
Solutions mentioned in this article that can help protect your organization:
- RidgeBot — Ridge Security
Cybersecurity for Your Industry
Learn more about cybersecurity in your industry:
