SegAudit
Industries

Every industry with a control network has a line to hold.

Wherever a business network meets the systems that run a process, a few firewall rules decide what can cross. Pick an industry to see where that line usually sits, one crossing that should not be there, and the rules it answers to.

  1. ManufacturingStop one bad laptop from stopping the line.
  2. Water and wastewaterKeep the treatment plant off the office network.
  3. Oil and gasKeep the pipeline running when IT has a bad day.
  4. Electric powerSee every firewall rule into the Electronic Security Perimeter.
  5. Pharmaceuticals and life sciencesProtect the batch, not just the network.
  6. Defense manufacturingShow the shop floor is scoped, not forgotten.
  7. Ports and maritimeGet terminal segmentation ready before the Coast Guard asks.
  8. Rail and transitKeep passenger systems away from signaling.
  9. Warehousing and logisticsKeep the dock moving when the office network goes down.
Zone map, Electric power
Level 4BusinessLevel 3.5DMZLevel 3OperationsLevel 2SupervisoryLevel 1ControlCorporate ITVendor supportDMZ historianIntermediate systemEMS serversHistorianOperator HMIEngineering WSSubstation RTUProtection relaysOps workstationNo access pointDNP3, any serviceEnds at the intermediate system
Flows that belongCrossing foundDropped and logged by the fixIllustrative example

Electric power

Generation, transmission and distribution all depend on a few firewall rules holding the line between the business network and the control center. SegAudit shows which rules let traffic cross, which hosts used them, and the change that narrows each one.

What crosses the line in electric power

Each one is a finding ranked by risk, with the rule that allows it, the hosts that used it when a traffic log is loaded, and the change that closes it.

  1. Vendor access straight to the relays

    A support rule meant for one vendor laptop reaches protection relays on any service, instead of ending at an intermediate system.

  2. Corporate desktops reading the live historian

    Business users query the historian inside the perimeter instead of the copy in the DMZ.

  3. A rule with no reason left

    An access permission that no session used in the traffic log, so the evidence gives no reason to keep it unless a maintenance or outage need is on record.

  4. Engineering workstations with a way out

    Hosts inside the perimeter can reach the internet through a rule written for updates.

Illustrative examples of what an audit can find. They are not from a customer.

The rules electric power answers to

SegAudit judges the controls a firewall's evidence can speak to as supported, partial or gap, and shows each one again after the change. It helps you assess segmentation; it does not certify compliance.

RuleWhat it asks of segmentationJudged from the evidence
NERC CIP-005-7 / CIP-007-6Every routable connection into an Electronic Security Perimeter passes an identified Electronic Access Point, with a reason for each permission, plus ports, services and security event logging.10 controls
IEC 62443-3-3Zones and conduits: network segmentation (SR 5.1), zone boundary protection (SR 5.2) and least functionality.9 controls
NIST CSF 2.0Networks protected from unauthorized logical access (PR.IR-01), asset inventories and log monitoring.10 controls
NIS2 Article 21(2)Cybersecurity risk-management measures for essential and important entities in the EU.6 controls
UK NCSC CAF 4.0Secure design and access control for operators of essential services in the UK.9 controls

Control by control in the frameworks overview. Confirm the versions in force for your audit period.

Who runs the audit

The same audit either way. What differs is who approves the change.

Asset owners

Your own firewall team runs the audit on its own sites, every quarter, and approves each change through its own change process. Priced per site with the Asset Owner edition.

For asset owners

Consultants

You assess a client's sites and deliver the findings and the fix under your firm's letterhead. The client's team approves. Professional or Engagement.

For consultants

See what crosses the line on your own firewalls.

Export a firewall configuration, add a traffic log if you have one, and read the findings on your own workstation. Nothing leaves it, and SegAudit never connects to your network.

Step-by-step export guides, for customers and trial holders: Palo Alto, FortiGate, Cisco ASA, Cisco FTD, Check Point.