Know your segmentation holds, every quarter.
Run SegAudit on a jump host inside your network. It reads your firewall config and logged sessions, shows which paths into OT are really in use, and proposes a change window for them, each change with a rollback.

Why segmentation slips
Rules drift between audits
Allows added during an outage or a vendor visit stay open. A rulebase review alone can't tell which ones still carry traffic.
Nobody wants to cut production
Without the sessions behind each rule, a drop is a guess, so risky allows survive another year.
Audits take weeks of spreadsheets
Mapping zones and writing up findings by hand means the review happens once a year, if that.
A quarter with SegAudit
Five steps every quarter, so the review is routine, not a project.
Export the files
An engineer exports the firewall config, plus a traffic log if the firewall keeps one, by web UI, CLI or the export scripts. SegAudit never connects to the firewall.
See what is really open
Each zone sits on the Purdue level you confirm. Every session on a path that skips an adjacent level is ranked by risk, with the rule that allowed it.
Plan the change window
Changes go in a safe order, and safety gates block the window if it would cut a production host.
Approve and change through your CAB
Your reviewers approve, hold or accept the risk on each change in a signed review log. Each step carries pre-checks, CLI, web steps, rollback and a ticket. Global changes go to a pilot site first.
Prove it worked
Load the next traffic log. Every plan comes back Verified, Regressed, Not applied or No traffic, and the quarter is saved as a checkpoint.

Built for the whole asset owner team
- OT and controls engineers
- See which sessions cross into Level 2 and below, which hosts depend on them, and what a change would break.
- Network and firewall team
- Ordered change windows with CLI, rollback and a CAB ticket, written for the management platform you already run.
- Site and OT security leads
- Track maturity, attack paths and open issues per site, and run the periodic rule review in an afternoon.
- CISO and site management
- A one-page brief each quarter: where each site stands, what changed and what is still open.

What you get
- Quarterly checkpoints
- Maturity tier per site, live attack paths, open issues and program remaining, compared quarter over quarter.
- Signed review log
- Each change approved, held or risk-accepted by the person who reviewed it, with the reason. Print and file it; anyone can check it.
- Periodic rule review
- Every rule that touches OT, with hits, last hit and a keep, narrow, remove or recertify recommendation, plus a sign-off sheet.
- Multi-site aware
- Plans per site across a multi-site estate, pilot site first.
- Remote access inventory
- Every way in from outside, who uses it and how often, with the jump-host change that replaces it.
- Isolation readiness
- Can each site be cut off from IT in an incident and keep running? Includes two staged isolation rules, ready to commit.
- Tabletop and SOC
- A ransomware exercise on your own paths, and Splunk and Sentinel queries so the SOC sees the next bypass.
- Asset inventory
- Every address as an asset from Device-ID, object names and traffic, with its criticality and exposure.
- Compliance evidence
- Supported, partial or gap for IEC 62443-3-3, NIST CSF 2.0, NIST SP 800-171 and CMMC Level 2, ISO/IEC 27001 and NIS2, plus NERC CIP, TSA, EPA water, Coast Guard and UK CAF when your sector answers to them.


Fits an OT environment
- Runs air-gappedA desktop install, or one signed container on a jump host. No internet, no account, no telemetry.
- Nothing on the OT networkNo agents, no span port, no firewall API. Only exported files go in.
- Your data stays putAnalysis runs on the jump host. Evidence never leaves it.
- Review it like any OT toolEvery download has a Sigstore signature and a software bill of materials to verify before installing. The trust center covers data flow, hardening and supply chain.
Priced per site
The Asset Owner edition is priced per site per year, for as few as one site. It covers unlimited internal users, quarterly re-assessment and priority support, billed by purchase order if you prefer.
Questions asset owners ask
Do we need Panorama?
No. SegAudit also reads standalone PAN-OS, FortiGate, Cisco ASA, Cisco FTD (FMC) and Check Point evidence. See firewall support for versions.
How much traffic log do we need?
A week shows what is in use. Use 30 days or more before retiring rules that look unused, so month-end jobs and vendor access show up.
Who runs it day to day?
Usually the firewall or OT security engineer. Unlimited internal users are included, so controls engineers and auditors can review the same findings.
Can we start without buying?
New trials are paused. Meanwhile, the free Quick check shows what SegAudit catches in one of your firewall exports, and the sample deliverable shows the full report from the Northline sample.
The asset owner workflow walks through a quarter step by step. Working with an outside assessor? See SegAudit for consultants and the frameworks it maps to.