Tool
Build my OT security programme
A staged plan you can adapt. Sequence matters more than breadth: inventory and boundary work make everything else possible.
Starting point
Estate size
Primary driver
0–90 days
- Name an accountable owner for OT security and agree how they work with engineering
- Build a first-pass asset inventory from engineering documentation and passive discovery
- Inventory and shut down unmanaged remote access paths, including vendor modems
- Verify that backups of controller logic, HMI projects and configurations exist and restore
3–6 months
- Design zones and conduits; document the intended IT/OT boundary and every crossing flow
- Deploy passive OT network monitoring in the highest-consequence zone first
- Stand up advisory intake and a consequence-based triage process
- Write an OT-specific incident response plan and run a tabletop with plant staff
6–12 months
- Enforce the boundary: deny-by-default rules, brokered remote access with MFA and approvals
- Extend monitoring across zones and build the first baselines per protocol and peer
- Start a hunt cadence using the playbook library and record baseline learnings
- Measure and report: reachable OT services, KEV exposure, backup restore success, exercise findings
Tailored
Adjustments for your situation
- Keep scope narrow: one site, one production area, prove value before scaling