What does an IT and OT (ICS) security audit involve?

A full IT/OT security audit consists of five main phases

PhaseWhat is examinedTypical findings (Poland 2024-2025)
1. Inventory & architectureAsset list, network diagrams, IT–OT segmentation, zones & conduits (Purdue model)78 % of plants still have flat network (IT directly connected to PLCs)
2. Technical configuration reviewFirewalls, servers, workstations, PLC/RTU/HMI, Active Directory, backups, encryption, patchingDefault passwords on 65 % of OT devices, Windows XP/7 still in use
3. Access control & policiesAccounts, privileges, MFA, password policy, remote access (VPN/RDP), USB policyShared admin accounts, no MFA on critical systems
4. Physical & organisational securityServer rooms, control rooms, visitor policy, documentation, incident procedures, trainingUnlocked cabinets, no visitor logs, missing or outdated procedures
5. Compliance & risk assessmentMapping to NIS2, ISO/IEC 27001, ISO/IEC 62443, KSC/UKE requirements, risk matrixMost companies fail NIS2 readiness by 40–70 % before remediation

Deliverables you receive

After the audit my retainer clients usually fix 80–90 % of critical findings within the first 3–6 months.