Every industry with a control network has a line to hold.
Wherever a business network meets the systems that run a process, a few firewall rules decide what can cross. Pick an industry to see where that line usually sits, one crossing that should not be there, and the rules it answers to.
- ManufacturingStop one bad laptop from stopping the line.
- Water and wastewaterKeep the treatment plant off the office network.
- Oil and gasKeep the pipeline running when IT has a bad day.
- Electric powerSee every firewall rule into the Electronic Security Perimeter.
- Pharmaceuticals and life sciencesProtect the batch, not just the network.
- Defense manufacturingShow the shop floor is scoped, not forgotten.
- Ports and maritimeGet terminal segmentation ready before the Coast Guard asks.
- Rail and transitKeep passenger systems away from signaling.
- Warehousing and logisticsKeep the dock moving when the office network goes down.
Water and wastewater
Water and wastewater utilities run SCADA across plants, lift stations and remote sites, often on networks that grew one connection at a time. SegAudit shows where the office, remote access and the control system meet, and what to close first.
What crosses the line in water and wastewater
Each one is a finding ranked by risk, with the rule that allows it, the hosts that used it when a traffic log is loaded, and the change that closes it.
- Remote access that lands on the PLCs
A remote support tool reaches the chemical dosing controller directly instead of a jump host.
- Office and SCADA in one flat network
The same rule lets office laptops and the SCADA server talk on any port.
- Lift stations reachable from anywhere
Remote sites accept traffic from the whole business network instead of only the supervisory hosts that poll them.
- Traffic nobody logs
Rules that cross into OT without logging, so nothing shows who used them.
Illustrative examples of what an audit can find. They are not from a customer.
The rules water and wastewater answers to
SegAudit judges the controls a firewall's evidence can speak to as supported, partial or gap, and shows each one again after the change. It helps you assess segmentation; it does not certify compliance.
| Rule | What it asks of segmentation | Judged from the evidence |
|---|---|---|
| EPA water sector cybersecurity checklist | Built on CISA's Cross-Sector Cybersecurity Performance Goals, including network segmentation (2.F), no OT connections to the public internet and log collection. | 11 controls |
| IEC 62443-3-3 | Zones and conduits: network segmentation (SR 5.1), zone boundary protection (SR 5.2) and least functionality. | 9 controls |
| NIST CSF 2.0 | Networks protected from unauthorized logical access (PR.IR-01), asset inventories and log monitoring. | 10 controls |
| NIS2 Article 21(2) | Cybersecurity risk-management measures for essential and important entities in the EU. | 6 controls |
| UK NCSC CAF 4.0 | Secure design and access control for operators of essential services in the UK. | 9 controls |
Control by control in the frameworks overview. Confirm the versions in force for your audit period.
Who runs the audit
The same audit either way. What differs is who approves the change.
Asset owners
Your own firewall team runs the audit on its own sites, every quarter, and approves each change through its own change process. Priced per site with the Asset Owner edition.
For asset ownersConsultants
You assess a client's sites and deliver the findings and the fix under your firm's letterhead. The client's team approves. Professional or Engagement.
For consultantsSee what crosses the line on your own firewalls.
Export a firewall configuration, add a traffic log if you have one, and read the findings on your own workstation. Nothing leaves it, and SegAudit never connects to your network.
Step-by-step export guides, for customers and trial holders: Palo Alto, FortiGate, Cisco ASA, Cisco FTD, Check Point.