OT Security Assessment for Industrial and ICS Operators

The direct answer: an OT security assessment evaluates the cyber risk of the systems that run your physical process. That means controllers, DCS, SCADA, historians, engineering workstations, HMIs, safety instrumented systems, and every network path and remote access route that reaches them. It is for manufacturers, utilities, energy operators, and other industrial companies whose safety and availability requirements make a standard IT assessment the wrong instrument. It produces a validated asset and connectivity picture, a zone and conduit view of the network, prioritized findings scored against IEC 62443 or NIST CSF 2.0, and a remediation roadmap your operations leaders can schedule around outage windows. The advisor runs the assessment, presents findings, and recommends a sequence. Your leadership decides what to fix, defer, or accept.
Status verified August 28, 2026. This page is updated when the regulatory status changes.
What an OT assessment covers that an IT assessment does not
The difference is an inverted priority order, not a longer checklist. IT security optimizes for confidentiality and treats a short outage as an acceptable cost of remediation. OT security starts from safety and availability, because a tripped process has physical consequences. NIST codified that distinction in SP 800-82 Revision 3, the Guide to Operational Technology Security, published in September 2023. Five things change in practice.
Asset inventory where active scanning is unsafe. On an IT network you discover assets by scanning them. On a plant network, an unexpected packet can hang a legacy controller. Discovery instead runs on passive capture at span ports, configuration and firewall rule exports, asset database extracts, drawings, and engineering interviews. Any active technique is a documented risk decision your operations leaders approve, scheduled inside a maintenance window.
Segmentation and the Purdue model. The assessment tests whether the levels are actually separated. What matters is not the diagram but the firewall rules, the flat VLANs nobody documented, the dual-homed engineering laptop, and the historian that replicates in both directions. IEC 62443 formalizes this as zones and conduits, and IEC 62443-3-2:2020 sets out how to partition the system under consideration and assign each zone a target security level from SL 0 through SL 4.
Remote and vendor access. Integrators and OEMs need access to keep your plant running, and that access is frequently the least governed path in the environment. The assessment maps every vendor route, who authorizes it, whether it can be disabled on demand, and whether sessions are monitored. For electric utilities that is now a compliance requirement.
Patchable versus unpatchable assets. Much of an OT estate cannot be patched on a normal cycle: vendor-validated configurations, systems past end of support, controllers whose firmware update requires a shutdown. The useful output is a defensible split between what gets patched at the next outage, what gets compensating controls, and what gets accepted with an owner and a reason.
Safety instrumented systems. Where an SIS is present, the assessment treats it as a distinct zone with its own access and change control, and no technique touches it without written approval from process safety.
Assessment scope: the domains covered
| Domain | What gets examined | Primary evidence |
|---|---|---|
| Asset and connectivity inventory | Controllers, HMIs, historians, engineering workstations, networked instruments, and what talks to what | Passive capture, asset database, drawings, walkdowns |
| Network architecture and segmentation | Purdue level separation, industrial DMZ design, zone and conduit boundaries, east to west paths | Firewall and switch configs, rule reviews, topology |
| Remote and vendor access | Every inbound path, authorization, session monitoring, ability to disable access on demand | Jump host configs, VPN and gateway logs, vendor contracts |
| Identity and privileged access | Shared operator accounts, default credentials, workstation privilege | Directory and local account review |
| Vulnerability and patch governance | Patchable versus unpatchable split, outage windows, end of support assets | Change records, vendor validation letters |
| Safety and process integrity | SIS separation, change control on safety logic, interlocks | Process safety documentation |
| Monitoring and detection | Coverage inside the control network, alert routing, who watches overnight | Sensor placement, log sources, on-call rotation |
| Backup, recovery, manual operation | Controller program backups, tested restore, running the process without the network | Restore test records, runbooks |
| Supply chain and governance | Integrator and OEM security terms, firmware provenance, who owns OT risk internally | Contracts, policies, incident response plan |
What actually triggers an assessment
A NERC CIP obligation. If you are a registered entity, two dates drive scope. CIP-003-9, which requires vendor electronic remote access security controls for low impact BES Cyber Systems, became enforceable on April 1, 2026, a date NERC states plainly in its CIP-003-11 implementation plan. Separately, FERC approved CIP-015-1 for internal network security monitoring in Order No. 907, issued June 26, 2025, with a final rule effective date of September 2, 2025. Under the NERC implementation plan, CIP-015-1 takes effect on the first day of the first calendar quarter 36 months after that order, Control Centers first, other medium impact systems with external routable connectivity 24 months later. NERC's own filing timeline puts those compliance dates at October 1, 2028 and October 1, 2030. Several vendor blogs circulate September 2 dates, which do not match the quarter-boundary language in the plan.
An insurance renewal. Carriers now ask OT-specific questions, and a report is the difference between answering from memory and from evidence.
An IT and OT convergence project. Connecting plant data to enterprise analytics, deploying industrial IoT, or standing up remote monitoring changes your exposure before the first dashboard is built. Assess before the connection.
A ransomware event at a peer. The board question after a competitor's outage is "could that happen here." Only an assessment answers it.
A customer, prime, or acquirer requirement. Industrial buyers and defense primes push security terms to suppliers, and diligence teams ask for the report.
Not sure what belongs in scope across your plants?
An advisor can walk your architecture, propose a site and zone scope that respects your outage calendar, and brief your operations leadership before you commit budget.
What you actually get
An OT assessment produces documents and decisions, not a score you can hang on a wall. Expect a validated asset and connectivity inventory, usually the most useful artifact. A zone and conduit or Purdue-aligned architecture review with segmentation gaps marked. A findings register risk-ranked by process consequence rather than by generic CVSS. A remediation roadmap sequenced against outage windows and capital cycles. A framework scorecard against IEC 62443, NIST CSF 2.0, or the CIP standards that apply to you. And an executive briefing for the people who approve the spend.
What it is not: advisory work is not certification. Z Cyber is not an accredited certification body, and this engagement does not certify, attest to, or approve your environment. Your team owns the risk decisions and the acceptance of any finding left open.
How it maps to the frameworks that matter
| Framework | Status | What the assessment produces against it |
|---|---|---|
| IEC 62443 | Voluntary international standard series | Zone and conduit partitioning with a target security level per zone |
| NIST CSF 2.0 | Voluntary, cross-sector | Maturity scoring across Govern, Identify, Protect, Detect, Respond, Recover, in OT context |
| NERC CIP | Mandatory for registered entities only | Gap view against applicable CIP standards and the evidence an audit would request |
| CISA Cross-Sector CPGs 2.0 | Voluntary baseline for critical infrastructure | A short, board-legible baseline already aligned to the CSF 2.0 functions |
CISA describes the Cross-Sector Cybersecurity Performance Goals 2.0 as a voluntary baseline for critical infrastructure, aligned with the NIST CSF 2.0 functions including Govern. It is the cheapest way to give a board a defensible floor while deeper 62443 work proceeds. For voluntary versus mandatory tracks, see our comparison of IEC 62443 and NERC CIP.
Timeline and what your team has to supply
Four phases. Scope and safety planning: agree the sites, zones, and systems in scope, with written agreement on which techniques are permitted where. Collection: passive capture, configuration exports, document review, site walkdowns. Analysis and validation: findings are drafted and then walked back through your engineers, because a finding that misreads the process loses the room. Reporting: report, roadmap, executive session.
Duration is driven by three dependencies: the number of sites, the state of your asset inventory, and access to control engineers who are also running the plant. Walkdowns and passive collection cannot be compressed the way a document review can. For reference, our NIST CSF maturity assessment is described as running six to ten weeks depending on size and scope, and a multi-site OT assessment sits at the long end of any comparable range.
What you supply: network diagrams and asset lists in whatever state they exist, firewall and switch configurations, vendor access paths, change and outage records, prior reports, and interview time with control engineers, plant IT, and process safety. Incomplete inputs are normal. Withheld inputs stretch the schedule.
Which assessment do you actually need
Buyers conflate four engagements. Pick by the question you need answered.
OT security assessment answers "what is the risk in my production environment and what do we fix first." Start here if the plant network has never been examined.
NERC CIP audit preparation answers "will my evidence survive a Regional Entity audit." It is compliance-scoped and evidence-driven rather than risk-driven, and it applies only to registered entities. See our guide to NERC CIP audit preparation and the utilities practice page.
IEC 62443 gap or readiness assessment answers "how far is this site from a defined target security level." Use it when a customer or insurer has named 62443, or when you want the zone model right before commissioning a new line.
NIST CSF 2.0 maturity assessment answers "how does our whole program score, IT and OT together." Use it when the audience is a risk committee rather than a plant manager.
For vocabulary first, our primer on what OT security is is the shorter read, and the industrials and OT practice page sets out how a dedicated security team runs the work after the assessment ends.
What to watch next
In force since April 1, 2026: CIP-003-9 vendor electronic remote access controls for low impact BES Cyber Systems. If you are a registered entity and your assessment has not tested your ability to identify, monitor, and disable vendor sessions, close that gap first.
October 1, 2028: CIP-015-1 internal network security monitoring applies to systems at Control Centers and backup Control Centers, with other medium impact systems with external routable connectivity following on October 1, 2030. Sensor placement and data retention decisions made in a 2026 assessment are what make those dates achievable.
Pending: NERC petitioned FERC on June 18, 2026 to approve CIP-015-2, which would extend internal network security monitoring to access control and physical access control systems outside the electronic security perimeter. It awaits Commission action, so treat its implementation dates as proposed rather than settled. We update this page when the status changes.
Frequently Asked Questions
What does an OT security assessment cover?
It covers the systems that run the physical process: controllers, DCS and SCADA systems, historians, engineering workstations, HMIs, safety instrumented systems, and every network path and remote access route that reaches them. A typical scope includes asset and connectivity inventory, network segmentation against the Purdue model, remote and vendor access controls, vulnerability and patch governance for assets that cannot be patched on demand, monitoring and detection coverage, and recovery and manual operation capability.
How is an OT security assessment different from an IT security assessment?
The priority order is inverted. IT assessments optimize for confidentiality and tolerate brief outages. OT assessments start from safety and availability, because a process trip has physical consequences. That changes method as well as scope. Active scanning that is routine on an IT network can knock over a legacy controller, so much of the evidence comes from passive collection, configuration exports, and engineering interviews. Patching is a scheduling problem tied to outage windows, not a monthly cycle.
Is it safe to scan an OT network during an assessment?
Not by default, and a competent assessor will not assume it is. Legacy controllers and protocols can fail on unexpected traffic, so active scanning against production control systems is treated as a risk decision your operations leaders make, not a default technique. Most of an OT assessment runs on passive network capture at span ports, configuration and firewall rule exports, asset databases, and interviews, with any active work confined to a planned maintenance window.
What triggers an OT security assessment?
Five events dominate. A NERC CIP compliance obligation or an upcoming Regional Entity audit if you are a registered entity. A cyber insurance renewal where the carrier now asks OT-specific questions. An IT and OT convergence project that connects previously isolated plant networks. A ransomware event at a peer operator that prompts a board question. A customer, prime contractor, or acquirer requiring evidence that your production environment is assessed against a recognized framework.
How long does an OT security assessment take?
Duration depends on how many sites are in scope, how current your asset inventory is, and how quickly engineering staff can be made available. Site walkdowns and passive collection cannot be compressed the way a document review can. For reference, the NIST CSF maturity assessment described on our services pages runs six to ten weeks depending on size and scope, and an OT assessment covering multiple plants sits at the longer end of any comparable range.
Subscribe for Updates
Get cybersecurity insights delivered to your inbox.


