ForgeShiftCompass
Cybersecurity and OTPractice H1

OT Network Assessment and Cyber Hygiene

An OT Network Assessment inventories every device on the shop-floor network, separates it from the office IT network, and establishes an incident response plan tested at least once a year.

  • Assessment3 questions
  • Templates3
  • Root causeISHIKAWA-6M

What world-class looks like

OT network is fully inventoried, segmented from IT, exposed protocols are secured, and an incident response plan is in place.

How mature is your operation?

These are the questions Compass asks for this practice, and the levels it scores you against.

OT asset inventory

Complete inventory of every device connected to the OT network.

Do you have a complete inventory of every device connected to your operational technology (OT) network?

Level 1 → 5World class at level 4

  1. No OT asset inventory — we don't know what is connected
  2. Rough knowledge of major machines, not documented
  3. Partial inventory of network-connected equipment
  4. Formal OT asset register with IP addresses, protocols, and firmware versionsWorld class
  5. Automated network discovery tool maintains live inventory

Network segmentation

IT/OT separation via firewall or DMZ.

Are your OT (shop floor) and IT (office) networks separated?

Level 1 → 5World class at level 4

  1. No separation — shop floor and office share the same network
  2. Some informal separation but not formally enforced
  3. Physical separation in most areas, some exceptions
  4. Formal IT/OT network segmentation with firewall or DMZWorld class
  5. Full ICS/SCADA network segmentation with monitored perimeter

Incident response plan

Tested IR plan for OT-specific scenarios.

If your OT network were attacked today, what would you do?

Level 1 → 5World class at level 4

  1. No plan — we would react as best we can
  2. Informal understanding of who to call
  3. Written contacts list for IT support
  4. Documented OT incident response plan tested at least onceWorld class
  5. Regular tabletop exercises; response plan tested and updated annually

Where to start

  • GLYPH passive OT asset discovery

    Cybersecurity · L1→L2 · Low complexityCloses · OT asset inventory
  • AI-generated OT incident response plan

    Cybersecurity · L1→L2 · Low complexityCloses · Incident response plan
Root-cause methodISHIKAWA-6M

Next steps

Scoring your operation against OT Network Assessment and Cyber Hygiene takes a few minutes and needs no account.