Welcome back to the cybersecurity desk. As an editor analyzing the front lines of IT, OT, and MIoT security, I see organizations making the same fatal mistake every day: treating an Operational Technology (OT) audit like a standard IT compliance check. The stakes in industrial environments are entirely different. An IT breach might cost you data; an OT breach can cost you physical safety, environmental integrity, and millions in downtime. With the global cybersecurity spending market projected to hit USD 240 billion in 2026, and manufacturing remaining a primary target for ransomware, regulators are tightening the screws. You cannot afford to walk into an industrial audit with generic IT questions. To truly uncover the hidden risks on your factory floor or energy grid, you must probe the intersection of digital security and physical engineering. Here are the top 10 critical questions you must ask during your next OT security audit.
Top 10 Questions to Ask During an OT Audit
1. How accurate is our OT asset inventory, and does it account for shadow IoT?
You simply cannot secure an industrial environment if you do not know exactly what is connected to it. In many legacy plants, undocumented hardware and shadow Industrial IoT (IIoT) sensors are bolted onto the network without IT’s knowledge, instantly expanding the attack surface. An effective audit must question the methodology used for asset discovery-relying on manual spreadsheets is a massive red flag. You need to ask if the organization is utilizing passive, continuous network scanning tools that map PLCs, RTUs, and cellular gateways without disrupting fragile proprietary protocols. If your inventory is not 100% accurate and dynamically updated, your entire risk assessment is built on a flawed foundation.
2. Have we established Target Security Levels (SL-T) aligned with IEC 62443?
A rigorous OT audit must move beyond basic checklists and anchor itself in established industrial frameworks like IEC 62443. You need to ask if the engineering and security teams have collaboratively defined a Target Security Level (SL-T) for every distinct network zone based on the actual physical consequences of a breach. For instance, a safety instrumented system protecting a hazardous chemical process requires a much higher security level (SL-3 or SL-4) than a standard building management system (SL-1). By asking this question, you ensure that cybersecurity investments are directly correlated to process safety hazards, preventing the dangerous practice of applying blanket security controls across vastly different risk profiles.
3. Is our network micro-segmentation strictly enforcing the Purdue Model?
The era of the flat manufacturing network is over, and auditors must aggressively probe the boundaries between the enterprise IT network and the operational plant floor. Ask to see the firewall rule sets and network diagrams to verify that the Purdue Enterprise Reference Architecture is practically enforced, not just theoretically documented. You must determine if deep packet inspection (DPI) is actively preventing lateral movement by restricting traffic to only explicitly authorized industrial commands. If a compromised corporate email account can theoretically ping a Level 1 field controller, the network segmentation has failed, leaving the entire facility highly vulnerable to ransomware propagation.
4. How are we controlling and authenticating third-party remote access?
The industrial supply chain relies heavily on original equipment manufacturers (OEMs) dialing in remotely to troubleshoot automation equipment, making this one of the most critical vectors for cyber-physical attacks. During the audit, you must ask exactly how vendor access is authenticated, monitored, and restricted. Standard VPNs are unacceptable; all remote sessions must route through a dedicated industrial Demilitarized Zone (DMZ) using jump servers and phishing-resistant multi-factor authentication (MFA). Furthermore, ask if vendor access is strictly time-bound, logged, and proactively disabled when maintenance windows close, ensuring that third-party credentials cannot be exploited by adversaries long after the job is done.
5. Do our Incident Response (IR) playbooks account for OT safety and manual failovers?
If ransomware encrypts an engineering workstation, an IT-centric incident response plan will likely instruct the team to isolate the machine and wipe it-a move that could catastrophically blind plant operators to a critical physical process. Ask if the organization has developed dedicated OT incident response playbooks that incorporate process safety engineers. The audit must verify that these playbooks include explicit procedures for safely failing over to manual operations and physically disconnecting compromised network segments. If the operators on the floor have not participated in a recent tabletop exercise simulating a cyber-physical attack, your IR capabilities are purely theoretical.
6. Are we relying on legacy antivirus, or using OT-native threat monitoring?
Traditional IT antivirus software is notoriously dangerous in OT environments; a poorly timed aggressive scan or quarantine action can easily crash a legacy HMI or disrupt a time-sensitive manufacturing process. The audit must question the exact mechanisms used for intrusion detection on the factory floor. You need to verify the deployment of continuous, passive OT network monitoring solutions that analyze industrial protocols (like Modbus or DNP3) for unauthorized commands or configuration changes. These systems should leverage machine learning to establish a behavioral baseline, allowing your security operations center (SOC) to detect anomalies early in the reconnaissance phase before physical damage occurs.
7. Do we maintain immutable, offline backups of PLC logic and configurations?
While corporate IT teams obsess over backing up databases, OT environments live and die by the rapid restoration of programmable logic controller (PLC) code and SCADA configuration files. Ask where the most recent engineering backups are stored and how quickly they can be deployed to bare metal. The audit must confirm that a copy of this critical logic is stored completely offline and is mathematically immutable, ensuring that ransomware operators cannot encrypt it during a breach. Without verified, clean backups of your industrial logic, recovering from a destructive wiper malware attack could take weeks of manual reprogramming, costing millions in lost production.
8. How do we handle vulnerability management on systems requiring 24/7 uptime?
Patching is the Achilles’ heel of operational technology. Industrial control systems operate 24/7, and taking a turbine offline just to apply a Windows security update is rarely an option. During the audit, you must ask how the organization prioritizes vulnerabilities when patching is impossible. The discussion should pivot toward risk-based vulnerability management and the deployment of robust compensating controls, such as strict network isolation or virtual patching at the firewall level. Ensure the team actively monitors vendor-specific advisories and CISA alerts, proving they have a dynamic strategy to suppress risks between scheduled annual maintenance outages.
9. Are our Safety Instrumented Systems (SIS) completely isolated from the control network?
Safety Instrumented Systems are the absolute last line of defense preventing catastrophic physical disasters, explosions, or environmental releases. Adversaries specifically target these systems to blind operators before initiating a destructive attack. You must aggressively question the logical and physical isolation of the SIS from the basic process control system (BPCS). The audit should verify that safety controllers do not share underlying network infrastructure, engineering workstations, or administrative credentials with the standard control network. If an attacker compromises the primary SCADA system, the safety systems must remain completely autonomous and untainted.
10. Does our governance structure bridge the gap between IT and OT teams?
The most formidable vulnerability in industrial cybersecurity is not technical; it is the cultural divide between corporate IT personnel and facility engineering teams. An audit must evaluate the governance model overseeing OT security. Ask if there is a cross-functional security steering committee where IT brings threat intelligence and OT brings process safety context. If security policies are being dictated from the corporate office without input from the plant floor, those policies will either be ignored by engineers or they will inadvertently cause operational downtime. True resilience requires shared accountability and collaborative risk management across both domains.
Conclusion
Conducting a successful OT cybersecurity audit requires asking uncomfortable questions that challenge the status quo of legacy industrial operations. As the threat landscape evolves and adversaries increasingly target critical infrastructure, relying on superficial compliance checklists is a recipe for disaster. By focusing your audit on absolute asset visibility, strict architectural segmentation, and the unique safety requirements of physical engineering, you can transform your security posture. The goal is not just to pass an inspection; it is to forge a resilient industrial ecosystem where IT and OT teams operate in lockstep, capable of detecting and neutralizing sophisticated cyber-physical threats before they ever impact production.