Does Your Office Network 'See' Your Production Machines? — IT/OT Network Isolation Audit
Attackers rarely target industrial machines directly. They enter through simple office Wi-Fi or a salesperson's laptop, then move into the production network. We verify whether these two worlds are safely separated.
Why typical IT firms avoid SCADA/PLC networks
A classic cyber security audit is designed for the office: servers, laptops, cloud. The production network works differently — PLCs and HMI panels run years-old firmware, there are no maintenance windows for patching, and protocols like Modbus or Profinet have no built-in authentication.
An aggressive vulnerability scan that is routine in an office can hang a controller and stop the line. That is why many IT firms either skip OT networks or — worse — treat them like office IT. We work the other way round: we start by understanding what may and may not be touched on the shop floor.
What the isolation audit looks like
Basic diagnosis
Passive traffic analysis (including Wireshark) and a network configuration review. We check whether the office or guest network can 'see' machine controllers and identify paths between the IT and OT worlds. No packets are sent to production devices.
from 6,000 PLN / 1,350 EUR
Full segmentation audit
Everything in the basic diagnosis, plus: an OT/IT network map, VLAN architecture and firewall rule recommendations, and a report in two versions — for the board and for maintenance engineers.
from 12,000 PLN / 2,700 EUR
Experience you won't find in a typical IT firm
For over a decade, running wesellmachines.com and skupmaszyn.eu, I worked with real machine parks — assessing technical condition, valuing and relocating industrial machinery for clients in Poland and the EU.
That means I know PLCs, HMI panels and production networks from the hardware side, not just from a network diagram. I know where the IT/OT weak points really are — for example in the service ports machine vendors use for remote diagnostics, often outside the IT department's control. I bring this experience to every industrial network segmentation audit.
What NIS2 says about industrial network segmentation
The NIS2 directive requires covered entities to implement network security risk-management measures — and isolating production networks from office networks is among the most commonly recommended controls for this class of environment. Our audit provides a documented picture of the current state and recommendations that can support preparation. It is not a compliance audit or certification — that requires a separate scope.
What this audit does not include
- It does not include implementing changes — VLAN and firewall configuration is carried out by the client or as a separate order.
- It does not include penetration testing of OT networks or any actions on running production.
- It does not include a NIS2 compliance audit or certification.
- It does not include a physical audit of the shop floor (cabling, physical access).
Frequently asked questions
Will the audit stop production?
No. We work passively — analysing traffic captures and network configuration, without actively scanning OT devices or touching controllers. On-site presence is limited to connecting a probe or obtaining logs.
How long does the audit take?
The basic diagnosis usually takes 3-5 working days; the full segmentation audit 2-3 weeks, depending on plant size and the number of network segments.
What exactly do we get in the report?
A list of detected connections between the office and production networks, a risk rating for each path, and prioritised recommendations. The full variant adds an OT/IT network map and VLAN and firewall recommendations in board and maintenance versions.
Related
- See all services → Services
- Test your team's resilience → Phishing Simulation
Ask about the IT/OT isolation audit
We scope the engagement after a short briefing. Tell us how many network segments your plant has — we will come back with a proposed schedule.
Marcin Białczyk, CHORS.NET operator — read about my approach.