# OT Cyber Audit

> Passive asset discovery, architecture review and configuration analysis mapped to IEC 62443 and the CISA cross-sector performance goals. No scans against live process.

Canonical: https://blackbirdcyber.com/capabilities/ot-cyber-audit  
Blackbird Cyber · https://blackbirdcyber.com/ · sales@blackbirdcyber.com

## Engagement

- Engagement: 3–5 weeks
- Delivery: On-site + remote
- Mapped to: IEC 62443 · CISA CPG

## Scope — Everything below the enterprise boundary.

We work from the DMZ down to the process, the way an adversary would, and rank every finding by what it lets someone do to the plant.

- Passive asset inventory from network capture
- Architecture and segmentation review
- Firewall, switch and remote access configuration review
- Vendor and integrator access paths
- Findings ranked by physical consequence, not CVSS

## Purdue levels in scope

| Level | Name | Systems | Scope |
| --- | --- | --- | --- |
| L5 / L4 | Enterprise | ERP, Email, Corporate AD | Out of scope |
| L3.5 | Industrial DMZ | Jump host, Patch relay, Historian mirror | In scope |
| L3 | Site operations | Historian, Eng. workstation, Domain ctrl | In scope |
| L2 | Supervisory | SCADA server, HMI, Alarm server | In scope |
| L1 | Control | PLC, RTU, Safety PLC | In scope |
| L0 | Process | Sensors, Actuators, Drives | In scope |

## Engagement timeline — Five weeks, one report you can act on.

- PH 1 · WK 1 · **Scope**: Sites, systems and rules of engagement agreed in writing.
- PH 2 · WK 2 · **On site**: Passive capture, config pulls, walk-down of the control network.
- PH 3 · WK 3–4 · **Analyze**: Asset inventory, exposure paths, gap analysis against the standard.
- PH 4 · WK 5 · **Report**: Findings by consequence, a prioritized roadmap, a readout with operations.

## You receive

Asset inventory, network diagram as found, ranked findings, IEC 62443 gap matrix, prioritized remediation roadmap.

## We need from you

A SPAN port or tap, read-only config exports, and a plant escort for one week.

## Other capabilities

- [OT Cyber Consulting](https://blackbirdcyber.com/capabilities/ot-cyber-consulting): Fractional OT security leadership for operators without a full-time ICS team.
- [OT Network Architecting](https://blackbirdcyber.com/capabilities/ot-network-engineering): Segmented control networks designed and built to keep the process running.
- [OT Cyber Program Review](https://blackbirdcyber.com/capabilities/ot-cyber-program-review): An independent review of your OT security program against the standards your regulators cite.

## Scope this engagement

Use the [contact form](https://blackbirdcyber.com/contact) or email sales@blackbirdcyber.com.
