Find out what is actually on your plant floor network
Most OT environments have not been inventoried since they were commissioned. In two weeks we will hand you a passive asset inventory, a zone-and-conduit map, and a prioritized remediation plan aligned to IEC 62443 and NIST 800-82 — at no cost and with nothing scanned in production.
- Passive discovery only — no active scanning, no polling, no production risk
- Reviewed by engineers with hands-on PLC, SCADA and historian experience
- Findings mapped to IEC 62443 zones and conduits and NIST 800-82 controls
No cost · Roughly two weeks · Findings are yours to keep
What you receive
- Passive asset inventory
- Zone and conduit map
- IT/OT boundary analysis
- Framework gap analysis
The gap is rarely the firewall. It is the inventory.
Four patterns show up in almost every OT environment we assess, regardless of sector or size.
Nobody has a current asset list
The commissioning documentation is a decade old, the integrator who built the cell has moved on, and the spreadsheet everyone references has not been reconciled against reality in years.
The cell network is flat
A VLAN between IT and OT gets called segmentation. In practice a compromised engineering workstation can reach every controller on the floor because nothing enforces east-west policy.
IT compromise forces OT shutdown
Operators do not need to touch the control system to stop production. When IT is untrustworthy, plants shut OT down preemptively to protect safety — and that downtime is the leverage.
Compliance deadlines arrive first
NERC CIP, TSA directives, or a cyber insurance renewal forces the conversation before anyone has the visibility needed to answer the questionnaire honestly.
Six artifacts, delivered as documents you own
This is not a slide deck that ends in a quote. Every artifact is written so your team can act on it with or without us.
Passive asset inventory
Every device we can observe on the OT network — make, model, firmware revision, protocol, and where it sits. Built from span/tap traffic, never from active probing.
Zone and conduit map
Your current architecture drawn as IEC 62443 zones and conduits, with every crossing annotated, so the boundaries you assumed exist can be checked against the ones that do.
IT/OT boundary analysis
What actually traverses the boundary today: remote access paths, vendor tunnels, shared credentials, jump hosts, and the flat paths nobody documented.
Framework gap analysis
Findings mapped line by line to IEC 62443 and NIST 800-82, in the format auditors and cyber insurers expect to receive them.
Prioritized remediation roadmap
Phased by risk reduction per dollar, not by product catalog. Quick wins in the first 30 days, structural work sequenced behind them.
Executive summary
Two pages a plant manager, a CFO, and a board risk committee can each read and act on without a translator.
Two weeks, and about four hours of your team’s time
The assessment is designed around the reality that your engineers cannot stop running the plant to help us.
Scoping call
We establish what you run, which sites are in scope, and what you are actually worried about. No tooling is discussed.
Passive collection
A span port or tap feeds a collector. Nothing is injected into the network, no device is polled, and no control traffic is generated.
Analysis & mapping
Our OT engineers reconcile observed traffic against your documented architecture and map the deltas to framework controls.
Findings review
A working session walking your team through every finding, the roadmap, and what you should do first. Documents are handed over at the end.
They understood the unique challenges of utility OT environments and delivered a practical solution.
Not the assessment you have been offered before
The typical vendor assessment
- An active scan that risks knocking over a controller that has run untouched for nine years.
- Run by an IT security generalist reading OT protocol names off a datasheet.
- A findings deck that maps every gap to a product the vendor happens to resell.
- The report is the sales pitch, and it stops being useful the moment you say no.
- Handed off to a delivery team that was not in the room when it was scoped.
A BlackHawk OT assessment
- Passive collection only. Nothing is injected, polled, or probed on the production network.
- Run by engineers who have commissioned and troubleshot the equipment in question.
- Findings mapped to IEC 62443 and NIST 800-82 controls. Vendor-agnostic by default.
- The documents are yours to keep and act on, whether or not we ever work together.
- The engineers who assess it are the ones who would build and operate it.
Questions we get every time
It is genuinely free, and the documents are yours regardless of what happens next. The reason it works commercially is straightforward: organizations that see a credible, vendor-agnostic assessment of their OT environment frequently want help executing the roadmap. If you take the roadmap and execute it in-house, that is a fine outcome and we would rather that than no one addressing it.
Tell us what you run
A few details are enough to scope this. An OT engineer — not a sales rep — will contact you within one business day to arrange the scoping call.
- A senior OT engineer responds within one business day
- NDA signed before any collection begins
- Passive discovery only — nothing is scanned in production
- All findings and documents are yours to keep
Not ready for an assessment yet?
The technical detail behind this practice is published in full. Read it first and come back when the timing is right.
