Skip to main content

Tool

OT security maturity

Score each capability honestly. The value is in the gaps, not the number.

Asset inventory

Do you know every OT asset, its function and its criticality?

Not started

Network architecture

Are zones, conduits and an industrial DMZ defined and enforced?

Not started

Access control

Named accounts, MFA, least privilege and managed vendor access.

Not started

Remote access

Brokered, approved, time-bound and logged sessions only.

Not started

Monitoring & detection

Passive OT visibility with protocol-aware detection.

Not started

Vulnerability management

Advisory intake, applicability, consequence-based decisions.

Not started

Backup & recovery

Tested, offline backups of logic, projects and configurations.

Not started

Incident response

OT-specific plan, exercised with operations.

Not started

Threat hunting

Baselines exist and structured hunts run on a cadence.

Not started

Governance & culture

Ownership, budget, metrics and engineering partnership.

Not started

Overall

1.0

Reactive

Focus next on

  • Asset inventory
  • Network architecture
  • Access control

Nothing is sent anywhere — this runs entirely in your browser.