OT Security Posture Scorecard 🏭🔒
Assess the security posture of Operational Technology (OT), Industrial Control Systems (ICS), and SCADA environments. Returns a detailed scorecard with risk ratings, gap analysis, and prioritized remediation steps aligned to IEC 62443 and NIST CSF frameworks.
Built by a CISSP/CISM certified security professional at ToolWeb.in
When to Use
- User asks to assess OT or ICS or SCADA security posture
- User wants to evaluate industrial control system risks
- User needs OT-IT convergence security analysis
- User asks about IEC 62443 or NIST CSF compliance for OT environments
- User mentions critical infrastructure security assessment
- User wants a security scorecard for manufacturing, energy, water, or utility systems
Prerequisites
TOOLWEB_API_KEY — Get your API key from portal.toolweb.in
curl must be available on the system
API Endpoint
POST https://portal.toolweb.in:8443/security/itotassessor
Workflow
Gather inputs from the user. Ask for the following:
Required fields:
org_name — Name of the organization (e.g., "Acme Manufacturing Corp")
sector — Industry sector (e.g., "Manufacturing", "Energy", "Water Treatment", "Oil & Gas", "Pharmaceuticals", "Transportation", "Mining")
ot_size — Size of OT environment (e.g., "Small", "Medium", "Large", "Enterprise")
integration_level — Level of IT/OT integration (e.g., "Minimal", "Partial", "Full", "Air-Gapped")
csf_scores — NIST CSF self-assessment scores (each 1-5). Ask the user to rate their maturity in each area:
identify — Asset management, risk assessment (1=none, 5=optimized)
protect — Access control, security training, data protection (1=none, 5=optimized)
detect — Monitoring, detection processes (1=none, 5=optimized)
respond — Incident response planning and execution (1=none, 5=optimized)
recover — Recovery planning and improvements (1=none, 5=optimized)
Optional fields (use if the user provides them):
ot_technologies — List of OT technologies in use (e.g., ["SCADA", "PLC", "HMI", "DCS", "RTU"])
it_tools — List of IT security tools in use (e.g., ["Firewall", "SIEM", "IDS", "EDR"])
threat_concern — Primary threat concerns (e.g., "Ransomware targeting OT networks")
compliance — Target compliance framework (e.g., "IEC 62443", "NIST CSF", "NERC CIP")
known_gaps — Known security gaps (e.g., "No OT network monitoring, shared credentials on PLCs")
team_maturity — Security team maturity level (e.g., "No dedicated OT security team")
assessment_depth — Level of detail: "standard" (default) or "detailed"
Call the API with the gathered parameters:
curl -s -X POST "https://portal.toolweb.in:8443/security/itotassessor" \
-H "Content-Type: application/json" \
-H "X-API-Key: $TOOLWEB_API_KEY" \
-d '{
"org_name": "<org_name>",
"sector": "<sector>",
"ot_size": "<ot_size>",
"integration_level": "<integration_level>",
"ot_technologies": ["<tech1>", "<tech2>"],
"it_tools": ["<tool1>", "<tool2>"],
"csf_scores": {
"identify": <1-5>,
"protect": <1-5>,
"detect": <1-5>,
"respond": <1-5>,
"recover": <1-5>
},
"threat_concern": "<threat_concern>",
"compliance": "<compliance>"
}'
Parse the response. The API returns a JSON object with:
status — "success" or error status
report — Full markdown report containing executive summary, NIST CSF function analysis, top 5 priority risks, technology stack assessment, and step-by-step remediation roadmap
overall_score — Numeric score (0-100)
csf_avg — Average CSF score across all 5 functions
risk_level — Risk rating ("Critical", "High", "Medium", "Low")
org_name — Organization name echoed back
Present results to the user in a clear, structured format:
- Lead with the overall score and risk level
- Show the executive summary from the report
- Highlight the top 5 priority risks
- Present the remediation roadmap phases
- Offer to dive deeper into any specific section
Output Format
Present the scorecard as follows:
🏭 OT/IT Convergence Security Assessment
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Organization: [org_name]
Sector: [sector]
Overall Score: [overall_score]/100 — [risk_level]
CSF Average: [csf_avg]/5.0
[Extract and present key sections from the report field:]
- Executive Summary
- Top 5 Priority Risks (with severity)
- Phase 1 Quick Wins (0-30 days)
- Recommended Technology Additions
📎 Full detailed report available — ask me to show any section
Note: The report field contains a comprehensive markdown report. Present the most actionable sections first (executive summary, top risks, quick wins) and offer to show the full report or specific sections on request.
Error Handling
- If
TOOLWEB_API_KEY is not set: Tell the user to get an API key from https://portal.toolweb.in (plans start at ₹2,999/month or ~$36/month)
- If the API returns 401: API key is invalid or expired — direct user to portal.toolweb.in to check their subscription
- If the API returns 429: Rate limit exceeded — wait and retry after 60 seconds
- If the API returns 500: Inform user of a temporary service issue and suggest retrying in a few minutes
- If curl is not available: Suggest installing curl (
apt install curl / brew install curl)
Example Interaction
User: "Assess the security of our water treatment plant's SCADA system"
Agent flow:
- Ask: "I'll need a few details to run the assessment:
- What's your organization name?
- How large is your OT environment? (Small/Medium/Large)
- How integrated are your IT and OT networks? (Minimal/Partial/Full)
- Can you rate your maturity (1-5) in these areas: Identify, Protect, Detect, Respond, Recover?"
- User responds: "WaterCo Utilities, medium size, partial integration. Identify: 3, Protect: 2, Detect: 2, Respond: 1, Recover: 1"
- Call API:
curl -s -X POST "https://portal.toolweb.in:8443/security/itotassessor" \
-H "Content-Type: application/json" \
-H "X-API-Key: $TOOLWEB_API_KEY" \
-d '{
"org_name": "WaterCo Utilities",
"sector": "Water Treatment",
"ot_size": "Medium",
"integration_level": "Partial",
"ot_technologies": ["SCADA", "PLC", "HMI"],
"csf_scores": {"identify":3,"protect":2,"detect":2,"respond":1,"recover":1}
}'
- Present the scorecard: overall score, risk level, executive summary, top risks, and quick wins
Pricing
- API access via portal.toolweb.in subscription plans
- Starter: ₹2,999/month (~$36) — 500 API calls
- Professional: ₹9,999/month (~$120) — 5,000 API calls
- Enterprise: ₹49,999/month (~$600) — Unlimited API calls
- Free trial: 10 API calls to test the skill
International Users (USA, UK, Europe): At checkout, select PayPal as your payment method to pay in USD, EUR, GBP, or 6 other international currencies. PayU processes the conversion automatically.
About
Created by ToolWeb.in — a security-focused MicroSaaS platform with 191+ security APIs, built by a CISSP & CISM certified professional. Trusted by security teams in USA, UK, and Europe.
Tips
- For the most actionable results, provide detailed descriptions of your OT environment
- Run assessments quarterly to track improvement over time
- Use the compliance mapping output directly for audit preparation
- Combine with the IT Risk Assessment Tool skill for a holistic IT+OT security view
1---2name: ot-security-posture-scorecard3description: Assess OT/ICS/SCADA security posture and generate risk scorecards with remediation guidance. Use when evaluating operational technology security, industrial control system risks, SCADA vulnerabilities, OT-IT convergence gaps, IEC 62443 compliance, or NIST CSF alignment for critical infrastructure.4---56# OT Security Posture Scorecard 🏭🔒78Assess the security posture of Operational Technology (OT), Industrial Control Systems (ICS), and SCADA environments. Returns a detailed scorecard with risk ratings, gap analysis, and prioritized remediation steps aligned to IEC 62443 and NIST CSF frameworks.910**Built by a CISSP/CISM certified security professional at [ToolWeb.in](https://toolweb.in)**1112## When to Use1314- User asks to assess OT or ICS or SCADA security posture15- User wants to evaluate industrial control system risks16- User needs OT-IT convergence security analysis17- User asks about IEC 62443 or NIST CSF compliance for OT environments18- User mentions critical infrastructure security assessment19- User wants a security scorecard for manufacturing, energy, water, or utility systems2021## Prerequisites2223- `TOOLWEB_API_KEY` — Get your API key from [portal.toolweb.in](https://portal.toolweb.in)24- `curl` must be available on the system2526## API Endpoint2728```29POST https://portal.toolweb.in:8443/security/itotassessor30```3132## Workflow33341. **Gather inputs** from the user. Ask for the following:3536 **Required fields:**37 - `org_name` — Name of the organization (e.g., "Acme Manufacturing Corp")38 - `sector` — Industry sector (e.g., "Manufacturing", "Energy", "Water Treatment", "Oil & Gas", "Pharmaceuticals", "Transportation", "Mining")39 - `ot_size` — Size of OT environment (e.g., "Small", "Medium", "Large", "Enterprise")40 - `integration_level` — Level of IT/OT integration (e.g., "Minimal", "Partial", "Full", "Air-Gapped")41 - `csf_scores` — NIST CSF self-assessment scores (each 1-5). Ask the user to rate their maturity in each area:42 - `identify` — Asset management, risk assessment (1=none, 5=optimized)43 - `protect` — Access control, security training, data protection (1=none, 5=optimized)44 - `detect` — Monitoring, detection processes (1=none, 5=optimized)45 - `respond` — Incident response planning and execution (1=none, 5=optimized)46 - `recover` — Recovery planning and improvements (1=none, 5=optimized)4748 **Optional fields (use if the user provides them):**49 - `ot_technologies` — List of OT technologies in use (e.g., ["SCADA", "PLC", "HMI", "DCS", "RTU"])50 - `it_tools` — List of IT security tools in use (e.g., ["Firewall", "SIEM", "IDS", "EDR"])51 - `threat_concern` — Primary threat concerns (e.g., "Ransomware targeting OT networks")52 - `compliance` — Target compliance framework (e.g., "IEC 62443", "NIST CSF", "NERC CIP")53 - `known_gaps` — Known security gaps (e.g., "No OT network monitoring, shared credentials on PLCs")54 - `team_maturity` — Security team maturity level (e.g., "No dedicated OT security team")55 - `assessment_depth` — Level of detail: "standard" (default) or "detailed"56572. **Call the API** with the gathered parameters:5859```bash60curl -s -X POST "https://portal.toolweb.in:8443/security/itotassessor" \61 -H "Content-Type: application/json" \62 -H "X-API-Key: $TOOLWEB_API_KEY" \63 -d '{64 "org_name": "<org_name>",65 "sector": "<sector>",66 "ot_size": "<ot_size>",67 "integration_level": "<integration_level>",68 "ot_technologies": ["<tech1>", "<tech2>"],69 "it_tools": ["<tool1>", "<tool2>"],70 "csf_scores": {71 "identify": <1-5>,72 "protect": <1-5>,73 "detect": <1-5>,74 "respond": <1-5>,75 "recover": <1-5>76 },77 "threat_concern": "<threat_concern>",78 "compliance": "<compliance>"79 }'80```81823. **Parse the response**. The API returns a JSON object with:83 - `status` — "success" or error status84 - `report` — Full markdown report containing executive summary, NIST CSF function analysis, top 5 priority risks, technology stack assessment, and step-by-step remediation roadmap85 - `overall_score` — Numeric score (0-100)86 - `csf_avg` — Average CSF score across all 5 functions87 - `risk_level` — Risk rating ("Critical", "High", "Medium", "Low")88 - `org_name` — Organization name echoed back89904. **Present results** to the user in a clear, structured format:91 - Lead with the overall score and risk level92 - Show the executive summary from the report93 - Highlight the top 5 priority risks94 - Present the remediation roadmap phases95 - Offer to dive deeper into any specific section9697## Output Format9899Present the scorecard as follows:100101```102🏭 OT/IT Convergence Security Assessment103━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━104105Organization: [org_name]106Sector: [sector]107Overall Score: [overall_score]/100 — [risk_level]108CSF Average: [csf_avg]/5.0109110[Extract and present key sections from the report field:]111- Executive Summary112- Top 5 Priority Risks (with severity)113- Phase 1 Quick Wins (0-30 days)114- Recommended Technology Additions115116📎 Full detailed report available — ask me to show any section117```118119**Note:** The `report` field contains a comprehensive markdown report. Present the most actionable sections first (executive summary, top risks, quick wins) and offer to show the full report or specific sections on request.120121## Error Handling122123- If `TOOLWEB_API_KEY` is not set: Tell the user to get an API key from https://portal.toolweb.in (plans start at ₹2,999/month or ~$36/month)124- If the API returns 401: API key is invalid or expired — direct user to portal.toolweb.in to check their subscription125- If the API returns 429: Rate limit exceeded — wait and retry after 60 seconds126- If the API returns 500: Inform user of a temporary service issue and suggest retrying in a few minutes127- If curl is not available: Suggest installing curl (`apt install curl` / `brew install curl`)128129## Example Interaction130131**User:** "Assess the security of our water treatment plant's SCADA system"132133**Agent flow:**1341. Ask: "I'll need a few details to run the assessment:135 - What's your organization name?136 - How large is your OT environment? (Small/Medium/Large)137 - How integrated are your IT and OT networks? (Minimal/Partial/Full)138 - Can you rate your maturity (1-5) in these areas: Identify, Protect, Detect, Respond, Recover?"1392. User responds: "WaterCo Utilities, medium size, partial integration. Identify: 3, Protect: 2, Detect: 2, Respond: 1, Recover: 1"1403. Call API:141```bash142curl -s -X POST "https://portal.toolweb.in:8443/security/itotassessor" \143 -H "Content-Type: application/json" \144 -H "X-API-Key: $TOOLWEB_API_KEY" \145 -d '{146 "org_name": "WaterCo Utilities",147 "sector": "Water Treatment",148 "ot_size": "Medium",149 "integration_level": "Partial",150 "ot_technologies": ["SCADA", "PLC", "HMI"],151 "csf_scores": {"identify":3,"protect":2,"detect":2,"respond":1,"recover":1}152 }'153```1544. Present the scorecard: overall score, risk level, executive summary, top risks, and quick wins155156## Pricing157158- API access via portal.toolweb.in subscription plans159- Starter: ₹2,999/month (~$36) — 500 API calls160- Professional: ₹9,999/month (~$120) — 5,000 API calls161- Enterprise: ₹49,999/month (~$600) — Unlimited API calls162- Free trial: 10 API calls to test the skill163164**International Users (USA, UK, Europe):** At checkout, select **PayPal** as your payment method to pay in USD, EUR, GBP, or 6 other international currencies. PayU processes the conversion automatically.165166## About167168Created by **ToolWeb.in** — a security-focused MicroSaaS platform with 191+ security APIs, built by a CISSP & CISM certified professional. Trusted by security teams in USA, UK, and Europe.169170- 🌐 Platform: https://toolweb.in171- 🔌 API Hub: https://portal.toolweb.in172- 📺 YouTube demos: https://youtube.com/@toolweb173- 🛒 Also on RapidAPI: https://rapidapi.com/user/mkkpro174175## Tips176177- For the most actionable results, provide detailed descriptions of your OT environment178- Run assessments quarterly to track improvement over time179- Use the compliance mapping output directly for audit preparation180- Combine with the IT Risk Assessment Tool skill for a holistic IT+OT security view