OT Cyber Baseline Action Plan (Post-Audit)
A practical, prioritized action-plan template that converts OT baseline audit findings into owned tasks with risk scores, clear mitigations, verification steps, and an implementation schedule so plant teams and integrators can reduce exposure quickly and safely.
Purpose
This action plan template turns OT baseline audit findings into a concise, prioritized set of tasks plant teams can execute, verify, and track. It focuses on common exposure areas: network segmentation, asset hygiene, credentials, remote access, asset inventory, and basic monitoring.
Important safety note
Do not make live changes to control systems, networks, or devices without controlled change procedures, engineering approval, vendor coordination, and appropriate maintenance windows. This document is a remediation planning tool, not a step-by-step engineering script for immediate live changes.
How to use this template
- Record each finding from the OT Cybersecurity Basics Audit as a separate action line.
- Score risk using the Risk Scoring rubric below to produce a priority order.
- Assign an owner, ETA, and verification method for each action.
- Flag Quick Wins (low-effort, high-impact) for immediate scheduling.
- Group related actions into short, medium, and long-term workstreams for scheduling and resource planning.
Risk scoring (recommended)
Use a simple likelihood × impact model to triage items quickly.
Scoring
- Likelihood (1–5): How likely is this exposure to be exploited or cause failure? 1 = very unlikely, 5 = very likely.
- Impact (1–5): Operational or safety impact if exploited. 1 = negligible, 5 = catastrophic (major downtime, safety risk, regulatory breach).
- Risk Score = Likelihood × Impact (range 1–25).
Priority bands
- High: 15–25 — schedule immediately with dedicated resources and escalate as needed.
- Medium: 8–14 — plan as part of the 1–3 month remediation sprint.
- Low: 1–7 — include in longer-term hardening and process improvements.
Action item template (copy this for each finding)
Use this structured template to capture each remediation task:
- Finding ID / Title: (e.g., Unsegmented PLC network)
- Finding summary: Brief explanation and evidence (IP ranges, device IDs, screenshots, audit notes)
- Risk score: Likelihood x Impact = N (Priority: High/Medium/Low)
- Recommended mitigation(s): Concrete actions (see recommended mitigations below)
- Owner: Name and role (e.g., Control Systems Engineer)
- ETA / Due date: Target completion date
- Effort estimate: Hours / FTE / external support required
- Verification steps & acceptance criteria: How will you confirm the mitigation is implemented correctly? (tests, logs, screenshots, configuration exports)
- Verification evidence: Links or attachments (change ticket, test report, backup configuration)
- Status: Open / In progress / Blocked / Complete
- Notes / Dependencies: Maintenance windows, vendor coordination, safety reviews
Recommended mitigations (common categories)
Use the following guidance as starting points. Tailor to your control-system vendor, architecture, and safety constraints.
Network segmentation
- Limit traffic between IT and OT using firewalls or managed gateways; enforce least privilege routes.
- Create separate VLANs for controllers, HMIs, engineering workstations, and business networks with strictly controlled cross-zone rules.
- Document and justify any existing flat or permissive rules; replace wildcard rules with explicit allow lists.
Asset hygiene and inventory
- Build or validate an authoritative asset inventory (device type, function, IP/MAC, physical location, firmware/version, owner).
- Remove or isolate unknown devices until validated.
Credentials and access control
- Ensure unique, non-shared operator and engineering accounts where possible; remove default passwords.
- Use role-based access and minimal privileges; audit privileged accounts regularly.
Remote access
- Replace ad-hoc remote connections (open RDP/VNC, port forwarded SSH) with approved remote access gateway/service that supports MFA, logging, and session recording.
- Restrict remote access to a small set of known IPs and accounts; enforce vendor access procedures and temporary access windows.
Patching & firmware management
- Record firmware/patch levels, prioritize critical updates for devices with known exploitable vulnerabilities, and test patches in a staging environment before production deployment.
Monitoring, logging & basic detection
- Enable and centralize logs where possible (firewall, gateway, OT gateway); create basic alerts for anomalous connections and unauthorized configuration changes.
- Implement periodic snapshot/config backups for critical controllers and devices.
Backup & resilience
- Ensure backups are available and tested; confirm recovery procedures and owner responsibilities.
Implementation schedule (recommended cadence)
- Immediate (0–14 days): Quick wins and high-risk short-term controls (temporary ACLs, remove unknown devices, enforce vendor remote access policy).
- Short term (2–12 weeks): Implement segmentation changes that don't require major downtime, set up central logging, fix credential hygiene.
- Medium term (3–12 months): Firmware rollouts, architecture changes, long-lived remote access solutions, monitoring platform upgrades.
- Long term (12+ months): Programmatic changes: asset lifecycle management, formal change control integration, OT security maturity projects.
Verification & evidence checklist
For each completed action, record at least one of the following as verification evidence:
- Configuration export showing the new firewall/ACL rule
- Screenshot of segmented topology and traffic flow test
- Log excerpts showing rejected unauthorized access attempts after mitigation
- Change ticket and test report showing patch applied and validated
- Updated asset inventory record and confirmation of device removal/isolation
Quick wins checklist (examples)
- Disable unused ports and services on HMIs and engineering workstations.
- Remove default accounts and change default passwords on devices still using them.
- Restrict remote vendor accounts to time-limited access and require documented approval.
- Isolate unknown or unmanaged devices to a quarantine VLAN until validated.
Escalation & stakeholder communication
Define who to contact for high-risk findings (security lead, plant manager, vendor engineer) and a clear escalation path for items that could cause immediate safety or major production impact.
Example filled action item (illustrative)
Finding ID: OT-01 — Direct routing between corporate LAN and PLC subnet
Summary: Audit observed permissive routes and firewall rules allowing traffic from IT subnet to PLC addresses. Evidence: firewall rule snapshot (fw-rule-123.png).
Risk score: Likelihood 4 × Impact 5 = 20 (High)
Mitigation: Implement strict ACLs to block unnecessary traffic, allow only required SCADA management hosts and engineering workstation traffic; deploy an industrial firewall or DMZ gateway for IT-OT mediation.
Owner: Lead Controls Engineer
ETA: 14 days (temporary ACLs), full design and deployment 8 weeks
Verification: Configuration export showing new ACLs; connectivity tests proving only allowed hosts can reach PLCs; firewall logs showing denied unrelated traffic.
Status: Open
Next steps (team)
- Import audit findings into this template, one line per finding.
- Score and tag Quick Wins; schedule immediate remediation work in the next maintenance window.
- Assign owners and set ETAs. Add blocking issues (approvals, vendor availability) to the notes field.
- Collect verification evidence and close items only after acceptance criteria are met.
Appendix: Helpful artifacts to attach
- Network diagrams showing current and proposed segmentation
- Firewall rule exports and snapshots
- Device inventory CSV or spreadsheet extract
- Change tickets and maintenance window approvals
- Vendor service agreements and emergency contact details
Use this action plan as a living document: keep it updated during remediation sprints so leadership and engineering teams have a clear, auditable trail from findings to verified fixes.
Discussion
Comments and conversation will live here.