Performing Ot Network Security Assessment
Overview
Cybersecurity skill for performing ot network security assessment. Follows industry best practices and security standards.
When to Use
Trigger phrases:
"performing ot network security assessment"
"This skill covers conducting comprehensive security assessments of Operational T"
When conducting an initial security baseline of an OT/ICS environment for a new client
When evaluating the security posture of a facility after an IT/OT convergence initiative
When preparing for IEC 62443 or NERC CIP compliance audits
When assessing risk following a merger or acquisition involving industrial facilities
When investigating whether an OT network has been compromised or has unmonitored pathways to corporate IT
Do not use for IT-only network assessments without OT components, for application-layer vulnerability scanning of IT web applications (see performing-web-app-penetration-test), or for active exploitation of live OT systems without explicit authorization and safety controls in place.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Written authorization from the asset owner and operations management for all assessment activities
- Understanding of the Purdue Reference Model and IEC 62443 zone/conduit architecture
- Passive network monitoring tools (Nozomi Guardian, Dragos Platform, or Wireshark with industrial protocol dissectors)
- Access to network diagrams, firewall rule sets, and asset inventories (or the ability to perform passive discovery)
- Safety briefing on the physical processes controlled by the OT systems under assessment
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Plan Operations — Define objectives, scope, and success criteria for ot network security assessment operations.
- Prepare Environment — Set up tools, access, and data sources required for ot network security assessment.
- Execute Core Workflow — Perform the ot network security assessment operations following established procedures.
- Validate Results — Verify that results meet quality standards and objectives.
- Report Findings — Document results, observations, and recommendations.
- Follow Up — Track remediation actions and verify fixes where applicable.
Tools
- Analysis Platform — Data processing and visualization
- Collaboration Tools — Team coordination and knowledge sharing
Process
- Reconnaissance — Gather target information, identify attack surface, enumerate services
- Analysis/Exploitation — Execute the technique, analyze results, document findings
- Reporting — Document IOCs, write findings, provide remediation recommendations
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: performing-ot-network-security-assessment3description: Use when this skill covers conducting comprehensive security assessments of Operational Technology (OT) networks including SCADA systems, DCS architectures, and industrial control system communication paths. It addresses the Purdue Reference Model layers, identifies IT/OT convergence risks, evaluates firewall rules between zones, and maps industrial protocol traffic (Modbus, DNP3, OPC UA, EtherNet/IP) to detect misconfigurations, unauthorized connections, and attack surfaces in critical infra...4license: Apache-2.05---67# Performing Ot Network Security Assessment89## Overview1011Cybersecurity skill for performing ot network security assessment. Follows industry best practices and security standards.1213## When to Use14**Trigger phrases:**15- "performing ot network security assessment"16- "This skill covers conducting comprehensive security assessments of Operational T"171819- When conducting an initial security baseline of an OT/ICS environment for a new client20- When evaluating the security posture of a facility after an IT/OT convergence initiative21- When preparing for IEC 62443 or NERC CIP compliance audits22- When assessing risk following a merger or acquisition involving industrial facilities23- When investigating whether an OT network has been compromised or has unmonitored pathways to corporate IT2425**Do not use** for IT-only network assessments without OT components, for application-layer vulnerability scanning of IT web applications (see performing-web-app-penetration-test), or for active exploitation of live OT systems without explicit authorization and safety controls in place.262728## When NOT to Use2930- When you lack proper authorization for testing31- For production systems without change management32- When the task requires legal or compliance expertise beyond technical scope333435## Prerequisites3637- Written authorization from the asset owner and operations management for all assessment activities38- Understanding of the Purdue Reference Model and IEC 62443 zone/conduit architecture39- Passive network monitoring tools (Nozomi Guardian, Dragos Platform, or Wireshark with industrial protocol dissectors)40- Access to network diagrams, firewall rule sets, and asset inventories (or the ability to perform passive discovery)41- Safety briefing on the physical processes controlled by the OT systems under assessment4243## Workflow4445```python46# Example: IOC detection47import re4849IOC_PATTERNS = {50 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",51 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",52 "hash_md5": r"\b[a-f0-9]{32}\b",53 "hash_sha256": r"\b[a-f0-9]{64}\b",54}5556def extract_iocs(text: str) -> dict:57 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}58```59601. **Plan Operations** — Define objectives, scope, and success criteria for ot network security assessment operations.612. **Prepare Environment** — Set up tools, access, and data sources required for ot network security assessment.623. **Execute Core Workflow** — Perform the ot network security assessment operations following established procedures.634. **Validate Results** — Verify that results meet quality standards and objectives.645. **Report Findings** — Document results, observations, and recommendations.656. **Follow Up** — Track remediation actions and verify fixes where applicable.6667## Tools6869- **Analysis Platform** — Data processing and visualization70- **Collaboration Tools** — Team coordination and knowledge sharing717273## Process74751. **Reconnaissance** — Gather target information, identify attack surface, enumerate services761. **Analysis/Exploitation** — Execute the technique, analyze results, document findings771. **Reporting** — Document IOCs, write findings, provide remediation recommendations7879## Verification8081- [ ] All ot network security assessment procedures executed completely and documented82- [ ] Findings validated against multiple data sources83- [ ] False positives identified and filtered84- [ ] Results documented with evidence and timestamps85- [ ] Recommendations provided with risk-based prioritization8687## Anti-Rationalization Table8889| Rationalization | Reality |90|---|---|91| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |92| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |93| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |