Skip to main content

service.assessment()

IT/OT Assessment

operating context

When the issue is not a single machine, but the overall design

An IT/OT assessment is needed when the plant keeps running, but dependencies, access paths, data flows and priorities are no longer readable as a shared picture.

01

IT/OT perimeter

Issue

Assets, networks, supervision, ERP and remote access are connected without a reliable map.

Solution

The assessment reconstructs assets, connections, dependencies and exposed points.

02

Decision baseline

Issue

Plant teams, IT and management work from different pictures: priorities, risks and constraints are not aligned.

Solution

It delivers one shared view to decide what to address and with what urgency.

03

Operational priorities

Issue

Integration, cybersecurity and modernization start without knowing what is really blocking evolution.

Solution

It defines the action sequence: fix first, integrate next, postpone what is not critical.

operating method

How we work: 4 phases in sequence

01

Discovery

Interviews with operations, IT and maintenance. Collection of existing documentation.

hardwareprotocolsinterfaces
02

Technical mapping

OT asset inventory, active protocols, data flows, IT-OT integrations.

OT ↔ ITremote accessintegrations
03

Gap analysis

Identification of vulnerabilities, bottlenecks and technical debt.

ISA-95IEC 62443severity
04

Prioritisation

Risk/impact matrix with operational recommendations and timeline.

risk/impacttimelineroadmap
expected output

What stays with the team afterwards

Not just a descriptive report: we deliver assets that actually help govern the next steps.

Application and infrastructure perimeter with relations across field, supervision, integration and business systems.

tech spec

Technical detail

explorer
architecture/ 2
operations/ 3
perimetro-it-ot.md
// baseline.perimeter

Real technical perimeter

analisi: IT and OT assets, supervision, networks, integrations and remote access.
criticità: Undocumented dependencies, unmanaged contact points and unclear segmentation.
output: Real perimeter map with assets, connections and exposed points.
ISA-95ERPMESSCADAPLC/DCS
// baseline.dependencies

Assets and operational dependencies

analisi: PLCs, SCADA, MES, ERP, databases, gateways, servers and intermediate services.
criticità: Fragile components, missing redundancy and implicit relations between production and business systems.
output: Asset-dependency matrix to understand what actually supports operational continuity.
asset mapdependenciescontinuity
// evidence.data_flows

Data flows and integrations

analisi: Exchanges across machines, supervision, MES, ERP, dashboards and external systems.
criticità: Duplicated flows, manual handling, latency and integrations that are not tracked or governed.
output: View of critical flows and integrations to stabilize or rationalize.
OPC-UAMQTTModbus TCPERP/MES
// evidence.exposure

Access paths and exposed surfaces

analisi: Remote access, vendors, technical accounts, segmentation and exposed services.
criticità: Ambiguous access paths, unmanaged privileges and weak separation across networks and systems.
output: List of surfaces to reduce, govern or make traceable.
IEC 62443remote accesssegmentation
// baseline.roadmap

Priorities and intervention sequence

analisi: Technical gaps, operational risk, impact, urgency and delivery complexity.
criticità: Unordered actions, disconnected investments and unclear ownership across IT, OT and management.
output: Initial roadmap with priorities, dependencies, quick wins and expected ownership.
risk/impactquick winsownership
architecture/perimetro-it-ot.md Markdown
next_step.initialize

Start with an assessment

Let us build the technical baseline for your next decisions together.