OT Cybersecurity Baseline Checklist (Segmentation, Device Hygiene)

A concise audit checklist to assess basic OT security posture: network segmentation, device updates, and access controls.

Interactive Tool

OT Cybersecurity Baseline Checklist (Segmentation, Device Hygiene)

This concise baseline audit helps you rapidly evaluate whether critical OT systems are exposed to common cyber risks. Use it during walkthroughs, shift handovers, or as a recurring check. Record a simple status for each area, capture evidence, assign an owner, set a priority, and note recommended actions. The form saves structured data so teams can track remediation and measure improvement over time.

Your full name or initials
Use YYYY-MM-DD or a local date format
Is the OT asset inventory complete and accurate?
List missing devices, recent discoveries, or where the inventory is stored
Are OT and IT properly segmented? Are zone-to-zone rules documented and enforced?
Examples: firewall rules missing, flat network segments, jump hosts not used
Are default credentials removed, unique accounts used, and password policies enforced?
Document devices with default credentials or shared service accounts
Are OT devices on an approved patch schedule? Do critical updates get applied or mitigated?
List critical unpatched systems or compensating controls in place
Is remote access restricted, logged, and using strong authentication?
Record VPN jump hosts, vendor remote access, or open RDP/SSH ports
Are OT backups taken regularly, stored offline, and tested? Is there an emergency recovery contact list?
Include emergency contacts, recent restore tests, and backup locations
Is there a documented and accessible recovery plan and contact list?
Where is the plan stored, who is on the contact list, last test date
Person or role responsible for remediation (name, team, or email)
Set a remediation priority to guide follow-up
Judgment of overall immediate cyber risk to OT operations
1.0 10.0
Short list of actions to reduce immediate exposure (what to do in the next 24-72 hours)
Examples: inventory reconciliation, firewall rule review, patch plan, vendor access policy
Links to screenshots, network diagrams, ticket numbers, or policy documents
Optional closing comments for this audit entry
You can explore this tool now. Sign in or create an account to save your responses and return to them later.
Make this tool part of your work

Save a personal copy, bring it to your team, or tailor the questions and workflow to fit what you are hungry to improve.

Member customization and team collaboration are coming soon.

Discussion

Comments and conversation will live here.