A full IT/OT security audit consists of five main phases
| Phase | What is examined | Typical findings (Poland 2024-2025) |
|---|---|---|
| 1. Inventory & architecture | Asset list, network diagrams, IT–OT segmentation, zones & conduits (Purdue model) | 78 % of plants still have flat network (IT directly connected to PLCs) |
| 2. Technical configuration review | Firewalls, servers, workstations, PLC/RTU/HMI, Active Directory, backups, encryption, patching | Default passwords on 65 % of OT devices, Windows XP/7 still in use |
| 3. Access control & policies | Accounts, privileges, MFA, password policy, remote access (VPN/RDP), USB policy | Shared admin accounts, no MFA on critical systems |
| 4. Physical & organisational security | Server rooms, control rooms, visitor policy, documentation, incident procedures, training | Unlocked cabinets, no visitor logs, missing or outdated procedures |
| 5. Compliance & risk assessment | Mapping to NIS2, ISO/IEC 27001, ISO/IEC 62443, KSC/UKE requirements, risk matrix | Most companies fail NIS2 readiness by 40–70 % before remediation |
Deliverables you receive
- Executive summary (for the board)
- Detailed technical report with screenshots and proof
- Risk matrix (critical / high / medium / low)
- Prioritised remediation roadmap (quick wins + long-term)
- Optional: full compliance gap analysis (NIS2, ISO 27001/62443)
After the audit my retainer clients usually fix 80–90 % of critical findings within the first 3–6 months.