SegAudit
For asset owners

Know your segmentation holds, every quarter.

Run SegAudit on a jump host inside your network. It reads your firewall config and logged sessions, shows which paths into OT are really in use, and proposes a change window for them, each change with a rollback.

Zone map of the Northline sample on Purdue levels, with the paths into OT

Why segmentation slips

Rules drift between audits

Allows added during an outage or a vendor visit stay open. A rulebase review alone can't tell which ones still carry traffic.

Nobody wants to cut production

Without the sessions behind each rule, a drop is a guess, so risky allows survive another year.

Audits take weeks of spreadsheets

Mapping zones and writing up findings by hand means the review happens once a year, if that.

A quarter with SegAudit

Five steps every quarter, so the review is routine, not a project.

  1. Export the files

    An engineer exports the firewall config, plus a traffic log if the firewall keeps one, by web UI, CLI or the export scripts. SegAudit never connects to the firewall.

  2. See what is really open

    Each zone sits on the Purdue level you confirm. Every session on a path that skips an adjacent level is ranked by risk, with the rule that allowed it.

  3. Plan the change window

    Changes go in a safe order, and safety gates block the window if it would cut a production host.

  4. Approve and change through your CAB

    Your reviewers approve, hold or accept the risk on each change in a signed review log. Each step carries pre-checks, CLI, web steps, rollback and a ticket. Global changes go to a pilot site first.

  5. Prove it worked

    Load the next traffic log. Every plan comes back Verified, Regressed, Not applied or No traffic, and the quarter is saved as a checkpoint.

Change windows for each finding, with the safety checks blurred
The change window, with its safety checks, ready for your CAB.

Built for the whole asset owner team

OT and controls engineers
See which sessions cross into Level 2 and below, which hosts depend on them, and what a change would break.
Network and firewall team
Ordered change windows with CLI, rollback and a CAB ticket, written for the management platform you already run.
Site and OT security leads
Track maturity, attack paths and open issues per site, and run the periodic rule review in an afternoon.
CISO and site management
A one-page brief each quarter: where each site stands, what changed and what is still open.
Post-change verification of each plan against the next traffic log
Verification against the next traffic log.

What you get

Quarterly checkpoints
Maturity tier per site, live attack paths, open issues and program remaining, compared quarter over quarter.
Signed review log
Each change approved, held or risk-accepted by the person who reviewed it, with the reason. Print and file it; anyone can check it.
Periodic rule review
Every rule that touches OT, with hits, last hit and a keep, narrow, remove or recertify recommendation, plus a sign-off sheet.
Multi-site aware
Plans per site across a multi-site estate, pilot site first.
Remote access inventory
Every way in from outside, who uses it and how often, with the jump-host change that replaces it.
Isolation readiness
Can each site be cut off from IT in an incident and keep running? Includes two staged isolation rules, ready to commit.
Tabletop and SOC
A ransomware exercise on your own paths, and Splunk and Sentinel queries so the SOC sees the next bypass.
Asset inventory
Every address as an asset from Device-ID, object names and traffic, with its criticality and exposure.
Compliance evidence
Supported, partial or gap for IEC 62443-3-3, NIST CSF 2.0, NIST SP 800-171 and CMMC Level 2, ISO/IEC 27001 and NIS2, plus NERC CIP, TSA, EPA water, Coast Guard and UK CAF when your sector answers to them.
Segmentation maturity tier per site
Maturity per site, tracked across quarters.
Attack paths from the internet, VPN and office to crown-jewel zones
Live and latent attack paths into OT.

Fits an OT environment

  • Runs air-gappedA desktop install, or one signed container on a jump host. No internet, no account, no telemetry.
  • Nothing on the OT networkNo agents, no span port, no firewall API. Only exported files go in.
  • Your data stays putAnalysis runs on the jump host. Evidence never leaves it.
  • Review it like any OT toolEvery download has a Sigstore signature and a software bill of materials to verify before installing. The trust center covers data flow, hardening and supply chain.

Priced per site

The Asset Owner edition is priced per site per year, for as few as one site. It covers unlimited internal users, quarterly re-assessment and priority support, billed by purchase order if you prefer.

Questions asset owners ask

Do we need Panorama?

No. SegAudit also reads standalone PAN⁠-⁠OS, FortiGate, Cisco ASA, Cisco FTD (FMC) and Check Point evidence. See firewall support for versions.

How much traffic log do we need?

A week shows what is in use. Use 30 days or more before retiring rules that look unused, so month-end jobs and vendor access show up.

Who runs it day to day?

Usually the firewall or OT security engineer. Unlimited internal users are included, so controls engineers and auditors can review the same findings.

Can we start without buying?

New trials are paused. Meanwhile, the free Quick check shows what SegAudit catches in one of your firewall exports, and the sample deliverable shows the full report from the Northline sample.

The asset owner workflow walks through a quarter step by step. Working with an outside assessor? See SegAudit for consultants and the frameworks it maps to.