OT Cybersecurity Baseline Checklist

A concise, non-intrusive baseline audit checklist to quickly evaluate OT network segmentation, device hygiene, remote access, asset inventory, and basic monitoring — producing observable evidence and prioritized next steps plant teams and integrators can act on.

Purpose and scope

This non-intrusive baseline audit helps plant teams and integrators rapidly identify common OT cybersecurity exposures that increase the risk of avoidable downtime, safety incidents, or ransomware impact. Use this checklist as a screening tool: observe, review configurations and documentation, and collect evidence. Do not perform intrusive testing, penetration attempts, or live configuration changes without formal change control and engineering approval.

How to use this audit

  1. Work with operations and engineering to schedule access and to avoid interfering with control systems.
  2. For each item, gather observable evidence (diagrams, screenshots, configuration snippets, logs, photos) and note the finding, risk level, and recommended immediate action.
  3. Classify findings as Low / Medium / High risk based on potential for safety, production impact, or remote compromise.
  4. Prioritize High findings for immediate mitigation, Medium for planned remediation, Low for monitoring or schedule updates.

Checklist

  1. Network segmentation and architecture
    • Verify an up-to-date network diagram exists that clearly shows IT/OT boundaries, DMZs, and remote access paths.
    • Confirm critical control networks are logically or physically segmented from corporate IT and guest networks.
    • Check for direct Internet-facing hosts on OT subnets (PLC/HMI/RTU) or open management ports accessible from the Internet.
    • Look for use of firewalls, access control lists (ACLs), and gateway devices between segments and confirm rule review dates.
    • Evidence to collect: network diagram, firewall rule excerpts, router ACLs, IP address inventory.
  2. Device hygiene: inventory, firmware, and patching
    • Confirm an asset inventory exists for OT devices (make/model, IP, firmware version, owner, location).
    • Check a sample of devices for current firmware or known vulnerable versions and whether vendor patches are tracked.
    • Note any endpoints using default or known-weak firmware/configurations.
    • Evidence to collect: asset list, device screenshots, firmware version outputs, vendor advisory references.
  3. Access control and authentication
    • Review account and password policies for OT systems: unique accounts per user, password complexity, expiration, and privilege separation.
    • Check for shared or generic operator/service accounts and whether multi-factor authentication (MFA) is required for remote/logged-in engineering access.
    • Verify privileged access is limited and reviewed regularly; confirm any remote vendor access is authorized and logged.
    • Evidence to collect: user account lists, password policy excerpts, remote access session logs, vendor access procedures.
  4. Remote access and third‑party connections
    • Identify all remote access paths (VPN, jump hosts, remote support tools) and whether they're documented and authorized.
    • Confirm vendor and third-party remote sessions are time-limited, logged, and use least-privilege practices.
    • Check that remote access does not bypass segmentation (i.e., remote sessions landed directly on OT host networks).
    • Evidence to collect: list of remote access methods, remote access logs, vendor access agreements, jump server configuration.
  5. Monitoring, logging, and basic detection
    • Confirm whether OT network traffic is monitored (IDS/IPS, flow analysis, SIEM ingestion) and whether baseline behaviors are established.
    • Check that critical events (authentication failures, configuration changes, remote sessions) are logged and retained for a defined period.
    • Verify alerting and escalation paths exist for suspicious OT events and that on‑call responders know when to involve security/engineering.
    • Evidence to collect: list of monitoring tools, relevant log extracts, alerting runbooks.
  6. Backup, recovery, and change control
    • Confirm backups exist for controllers, HMIs, PLC logic, and configuration data and that restore procedures are documented and tested.
    • Ensure change control processes cover security reviews for remote configuration and software updates to OT devices.
    • Evidence to collect: backup schedules, restore test results, change requests, and approved change logs.
  7. Physical security and removable media
    • Observe whether control cabinets, engineering stations, and network closets are physically secured and access is logged.
    • Check policies for USB/removable media use, and look for uncontrolled use of personal devices in OT areas.
    • Evidence to collect: access logs, photos of physical controls, removable media policy.

Scoring and prioritization guidance

For each finding, assign a risk level:

  • High: Exposure likely allows remote compromise or immediate safety/production impact (treat as actionable within 24–72 hours).
  • Medium: Weaknesses that enable later exploitation or increase blast radius (plan remediation within weeks).
  • Low: Minor issues, documentation gaps, or recommended improvements (schedule for routine improvement cycles).

Suggested immediate mitigations

  • Isolate any OT hosts that are directly reachable from the Internet or corporate guest networks until proper segmentation is applied.
  • Disable or remove default accounts and enforce unique, strong passwords for device and administrative accounts.
  • Temporarily restrict or require vendor access to jump hosts with session logging and MFA.
  • Ensure recent backups exist for critical controllers and verify an offsite copy is accessible for recovery.

Notes, limitations, and escalation

This checklist is a baseline screening tool, not a replacement for penetration testing, intrusive vulnerability scanning, or an engineering-led remediation program. Do not make live changes to controllers or PLC programs during the review without formal change control. Escalate High findings immediately to security, control systems engineering, and vendor support for controlled remediation.

References and further reading

  • ISA/IEC 62443 series (OT security guidance)
  • NIST Cybersecurity Framework (identify, protect, detect, respond, recover)
  • Vendor hardening guides for specific controllers, HMIs, and RTUs

Suggested evidence package: network diagram, asset inventory export, firewall/ACL excerpts, sample device firmware/version screenshots, a list of remote access methods and recent logs, and any backup/restore test results.


Discussion

Comments and conversation will live here.