Blackbird Cyber
Menu

Home / Capabilities / OT Cyber Audit

OT Cyber Audit

Passive asset discovery, architecture review and configuration analysis mapped to IEC 62443 and the CISA cross-sector performance goals. No scans against live process.

ENGAGEMENT3–5 weeks
DELIVERYOn-site + remote
MAPPED TOIEC 62443 · CISA CPG

Scope

Everything below the enterprise boundary.

We work from the DMZ down to the process, the way an adversary would, and rank every finding by what it lets someone do to the plant.

■Passive asset inventory from network capture
■Architecture and segmentation review
■Firewall, switch and remote access configuration review
■Vendor and integrator access paths
■Findings ranked by physical consequence, not CVSS
Levels in scope
L5 / L4Enterprise
ERPEmailCorporate AD
Out of scope
L3.5Industrial DMZ
Jump hostPatch relayHistorian mirror
In scope
L3Site operations
HistorianEng. workstationDomain ctrl
In scope
L2Supervisory
SCADA serverHMIAlarm server
In scope
L1Control
PLCRTUSafety PLC
In scope
L0Process
SensorsActuatorsDrives
In scope

Engagement timeline

Five weeks, one report you can act on.

PH 1WK 1
ScopeSites, systems and rules of engagement agreed in writing.
PH 2WK 2
On sitePassive capture, config pulls, walk-down of the control network.
PH 3WK 3–4
AnalyzeAsset inventory, exposure paths, gap analysis against the standard.
PH 4WK 5
ReportFindings by consequence, a prioritized roadmap, a readout with operations.
You receiveAsset inventory, network diagram as found, ranked findings, IEC 62443 gap matrix, prioritized remediation roadmap.
We need from youA SPAN port or tap, read-only config exports, and a plant escort for one week.

Get in touch

Talk to an OT security engineer.

Engineer at a membrane skid control panel