Skip to main content

Tool

Build my OT security programme

A staged plan you can adapt. Sequence matters more than breadth: inventory and boundary work make everything else possible.

Starting point

Estate size

Primary driver

0–90 days
  • Name an accountable owner for OT security and agree how they work with engineering
  • Build a first-pass asset inventory from engineering documentation and passive discovery
  • Inventory and shut down unmanaged remote access paths, including vendor modems
  • Verify that backups of controller logic, HMI projects and configurations exist and restore
3–6 months
  • Design zones and conduits; document the intended IT/OT boundary and every crossing flow
  • Deploy passive OT network monitoring in the highest-consequence zone first
  • Stand up advisory intake and a consequence-based triage process
  • Write an OT-specific incident response plan and run a tabletop with plant staff
6–12 months
  • Enforce the boundary: deny-by-default rules, brokered remote access with MFA and approvals
  • Extend monitoring across zones and build the first baselines per protocol and peer
  • Start a hunt cadence using the playbook library and record baseline learnings
  • Measure and report: reachable OT services, KEV exposure, backup restore success, exercise findings

Tailored

Adjustments for your situation

  • Keep scope narrow: one site, one production area, prove value before scaling