OT Security Audit

Uw industriële omgeving is kwetsbaarder dan u denkt.

Met de OT Security Audit van OranjeRaksha beoordelen we de beveiliging van uw belangrijkste toeleveranciers – met name EMS- en elektronicafabrikanten die hardware, modules en assemblies voor u produceren.

We kijken naar governance, productieprocessen, logistiek, informatiebeveiliging, fysieke beveiliging en derde-partij risico’s. Onze ervaring komt uit audits bij leveranciers van onder andere netwerkapparatuur, automotive, navigatie-oplossingen en consumentenelektronica in Europa (Frankrijk, België, Nederland), Azië (China, Thailand, Maleisië, Singapore, Zuid-Korea) en Noord- en Zuid-Amerika (VS, Mexico, Brazilië).

OT Security Audit

Your industrial environment is more exposed than you think.

With the OT Security Audit from OranjeRaksha we systematically identify vulnerabilities in your SCADA, PLC, ICS and OT networks – without disrupting production.

We translate technical findings into concrete risks and improvement actions that make your industrial infrastructure demonstrably more secure – aligned to IEC 62443 and NIS2.

SCADA & PLC-omgevingen ICS & industriële netwerken IT/OT-integratie & NIS2 SCADA & PLC environments ICS & industrial networks IT/OT integration & NIS2

Wat is een OT Security Audit?

What is an OT Security Audit?

Een OT Security Audit beoordeelt de beveiliging van uw operationele technologie – de systemen die uw industriële processen aansturen en bewaken.

An OT Security Audit assesses the security of your operational technology – the systems that control and monitor your industrial processes.

We kijken naar beleid, processen en maatregelen bij de leverancier: hoe is security georganiseerd, hoe worden productielijnen en magazijnen beveiligd, hoe wordt omgegaan met uw tekeningen, stuklijsten, firmware, cryptomateriaal en klantdata, en hoe wordt continuïteit geborgd bij incidenten?

We look at policies, processes and controls at the supplier: how security is governed, how production lines and warehouses are protected, how your drawings, BOMs, firmware, cryptographic material and customer data are handled, and how continuity is ensured during incidents.

Het resultaat is een concreet beeld van de security-volwassenheid van uw leveranciers, inclusief verbeterpunten, risico’s per domein en praktische aanbevelingen om uw supply chain aantoonbaar veiliger te maken.

The result is a concrete view of your suppliers’ security maturity, including improvement areas, risks per domain and practical recommendations to demonstrably strengthen your supply chain.

Waarom is dit zo belangrijk?

Why does it matter?

OT-omgevingen zijn ontworpen voor beschikbaarheid en veiligheid – niet voor cybersecurity. Dat maakt ze kwetsbaar.

OT environments are designed for availability and safety – not cybersecurity. That makes them vulnerable.

In de praktijk zien we leveranciers met gedeelde accounts, beperkte fysieke beveiliging, gebrekkige incidentprocessen, onduidelijke IP-afspraken, zwakke netwerksegregatie en weinig inzicht in derde partijen die zij zelf weer inschakelen (bijvoorbeeld cloud- of 3rd tier partners).

In practice we see suppliers with shared accounts, weak physical security, immature incident processes, unclear IP arrangements, limited network segregation and poor visibility of their own third parties such as cloud or 3rd tier partners.

Voor wie
Who Is This For?

Voor wie is dit?

Who is this for?

Een OT Security Audit is relevant voor elke organisatie met industriële processen, kritieke infrastructuur of IT/OT-integratie.

An OT Security Audit is relevant for any organisation with industrial processes, critical infrastructure or IT/OT integration.

🏭
Plant Manager / OT Engineer
Plant Manager / OT Engineer

Wil inzicht in kwetsbaarheden in SCADA-, PLC- en ICS-omgevingen zonder productieverstoring.

Needs insight into vulnerabilities in SCADA, PLC and ICS environments without disrupting production.

🛡️
CISO / Security Manager
CISO / Security Manager

Wil een geïntegreerd beeld van IT én OT-risico's en een basis voor NIS2-compliance.

Wants an integrated view of IT and OT risks and a foundation for NIS2 compliance.

📋
Compliance Officer
Compliance Officer

Heeft auditwaardige documentatie nodig voor NIS2, IEC 62443 of sectorspecifieke regelgeving.

Needs audit-grade documentation for NIS2, IEC 62443 or sector-specific regulatory requirements.

Energie & Nutsbedrijven
Energy & Utilities

Opereert kritieke infrastructuur en valt direct onder NIS2-vereisten voor OT-beveiliging.

Operates critical infrastructure and falls directly under NIS2 requirements for OT security.

🔧
Maakindustrie & Productie
Manufacturing & Production

Heeft geautomatiseerde productielijnen met OT-systemen die steeds vaker aan IT gekoppeld zijn.

Has automated production lines with OT systems that are increasingly connected to IT.

🛢️
Olie, Gas & Chemie
Oil, Gas & Chemical

Heeft complexe OT-omgevingen met hoge veiligheidsrisico's bij verstoringen of aanvallen.

Has complex OT environments where disruptions or attacks carry significant safety implications.


Wat er mis kan gaan

What can go wrong

Publiek bekende OT-incidenten laten zien hoe aanvallen op industriële systemen leiden tot productiestops, schade aan installaties en veiligheidsrisico's.

Publicly known OT incidents show how attacks on industrial systems cause production stops, equipment damage and safety risks.

Case 1: Tier-1 leverancier automotive
Case 1: Tier-1 automotive supplier
Productiestop door cyberincident bij leverancier
Production halt caused by supplier incident

Een grote automotive fabrikant moest meerdere productielijnen tijdelijk stilleggen nadat een belangrijke leverancier te maken kreeg met een cyberincident. IT-systemen voor planning en logistiek vielen uit, waardoor kritieke onderdelen niet op tijd geleverd konden worden. De fabriek zelf was niet gehackt – maar werd wel direct geraakt.

A major automotive manufacturer had to stop several production lines when a key supplier suffered a cyber incident. Planning and logistics systems failed, preventing timely delivery of critical parts. The OEM plant itself was not hacked – but was immediately affected.

Case 2: Logistiek & shipping
Case 2: Logistics & shipping
Supply chain verstoring door ransomware
Supply chain disruption due to ransomware

Grote logistieke partijen en containerrederijen zijn in het verleden geraakt door ransomware-aanvallen waardoor planning, tracking en douaneafhandeling deels stil kwamen te liggen. Voor fabrikanten betekende dit vertragingen, extra kosten en noodscenario’s om leveringen alsnog bij klanten te krijgen.

Large logistics and shipping companies have been hit by ransomware in the past, disrupting planning, tracking and customs processes. For manufacturers this translated into delays, additional cost and emergency measures to keep customer deliveries going.


Scope van de OT Security Audit

Scope of the OT Security Audit

We baseren ons op IEC 62443, NIST SP 800-82 en NIS2. De audit dekt zes OT-domeinen die samen een compleet beeld geven van security in uw industriële omgeving.

We draw on IEC 62443, NIST SP 800-82 and NIS2. The audit covers six OT domains that together provide a complete picture of security across your industrial environment.

1. OT Governance & beleid

1. OT Governance & policy

Hoe is OT-security georganiseerd? We beoordelen beleid, rollen, risicomanagement en IEC 62443-compliance.

How is OT security governed? We review policies, roles, risk management and IEC 62443 compliance.

  • OT-securitybeleid, rollen & verantwoordelijkheden.
  • IEC 62443 zone & conduit model.
  • Risico-analyse en NIS2-compliance.
  • OT security policy, roles & responsibilities.
  • IEC 62443 zone & conduit model.
  • Risk assessment and NIS2 compliance.

2. Netwerksegmentatie & architectuur

2. Network segmentation & architecture

Hoe zijn IT- en OT-netwerken gescheiden? We beoordelen DMZ, firewalls, VLAN's en remote access.

How are IT and OT networks separated? We review DMZ, firewalls, VLANs and remote access controls.

  • IT/OT-scheiding en DMZ-configuratie.
  • Firewall-regels en netwerksegmentatie.
  • Remote access, VPN en jump server configuratie.
  • IT/OT separation and DMZ configuration.
  • Firewall rules and network segmentation.
  • Remote access, VPN and jump server configuration.

3. SCADA, PLC & HMI hardening

3. SCADA, PLC & HMI hardening

Hoe zijn SCADA-servers, PLC's en HMI's geconfigureerd? We beoordelen patchniveaus, wachtwoorden en firmwareversies.

How are SCADA servers, PLCs and HMIs configured? We review patch levels, passwords and firmware versions.

  • Patchniveaus en firmwareversies.
  • Standaard wachtwoorden en accounts.
  • Onnodige diensten en open poorten.
  • Patch levels and firmware versions.
  • Default passwords and accounts.
  • Unnecessary services and open ports.

4. Toegangsbeheer & identiteit

4. Access control & identity

Wie heeft toegang tot OT-systemen en hoe wordt dit beheerd? We beoordelen accounts, rechten en authenticatie.

Who has access to OT systems and how is it managed? We review accounts, privileges and authentication.

  • Gebruikersaccounts en gedeelde accounts.
  • Least privilege en role-based access.
  • Multi-factor authenticatie voor remote access.
  • User accounts and shared accounts.
  • Least privilege and role-based access.
  • Multi-factor authentication for remote access.

5. Monitoring, logging & incidentrespons

5. Monitoring, logging & incident response

Medewerkers, awareness en reactie op incidenten zijn cruciaal. We toetsen screening, training, contracten en incidentprocessen.

People, awareness and response are critical. We review screening, training, contractual controls and incident handling.

  • Pre-employment checks, NDA’s en contractuele security-clausules.
  • Security-training en awareness voor productie, IT en logistiek.
  • Incidentidentificatie, melding, respons en herstel.
  • Pre-employment checks, NDAs and contractual security clauses.
  • Security training and awareness for production, IT and logistics staff.
  • Incident identification, reporting, response and recovery.

6. Patchbeheer, back-up & continuïteit

6. Patch management, backup & continuity

Leveranciers werken zelf ook weer met cloud, 3rd tier partners en ontwikkelteams. We beoordelen hoe zij daarmee omgaan en welke eisen zij doorvertalen.

Suppliers in turn rely on cloud, 3rd tier partners and engineering teams. We assess how they manage those dependencies and propagate your security requirements.

  • Contractuele eisen richting onderaannemers en cloudproviders.
  • Secure design & development voor firmware, tools en portals.
  • Toezicht op downstream-risico’s en kwetsbaarheidsbeheer.
  • Contractual requirements for subcontractors and cloud providers.
  • Secure design & development for firmware, tools and portals.
  • Oversight of downstream risks and vulnerability management.

Onze aanpak

Our approach

Wij combineren documentaire review, technische analyse en interviews op locatie – zonder uw productie te verstoren. Elke stap is ontworpen voor industriële omgevingen waar beschikbaarheid voorop staat.

We combine document review, technical analysis and on-site interviews – without disrupting your production. Every step is designed for industrial environments where availability comes first.

1
Stap 1
Step 1
Scoping & voorbereiding
Scoping & preparation

Samen bepalen we welke systemen, netwerken en locaties in scope zijn. We stemmen af met OT-engineers, plant managers en IT.

Together we define which systems, networks and sites are in scope. We align with OT engineers, plant managers and IT.

SCADA/PLC selectieNetwerkdiagrammen
2
Stap 2
Step 2
Documentatie & architectuurreview
Documentation & architecture review

We analyseren netwerkdiagrammen, systeemarchitectuur, beleidsdocumenten en patchniveaus. We identificeren aandachtspunten voor het sitebezoek.

We analyse network diagrams, system architecture, policy documents and patch levels. We identify focus areas for the site visit.

Gap-analyseIEC 62443
3
Stap 3
Step 3
On-site audit & interviews
On-site audit & interviews

We spreken met OT-engineers, operators en IT. We lopen mee op de werkvloer en inspecteren controlekamers en kritieke netwerksegmenten.

We interview OT engineers, operators and IT. We walk the production floor and inspect control rooms and critical network segments.

Niet-verstorendVerificatie ter plaatse
4
Stap 4
Step 4
Technische & procesmatige checks
Technical & process checks

Waar mogelijk beoordelen we configuraties, wachtwoordbeleid, remote access en netwerksegmentatie passief – zonder actief te scannen.

Where possible we review configurations, password policies, remote access and network segmentation passively – without active scanning.

Passieve analyseConfiguratiecheck
5
Stap 5
Step 5
Rapportage & risicobeeld
Reporting & risk picture

U ontvangt een auditwaardig rapport met bevindingen per domein, risiconiveaus, IEC 62443-mapping en een geprioriteerde roadmap.

You receive an audit-grade report with findings per domain, risk levels, IEC 62443 mapping and a prioritised roadmap.

NIS2 mappedRoadmap
6
Stap 6
Step 6
Follow-up & begeleiding
Follow-up & guidance

We lichten bevindingen toe aan OT-, IT- en managementteams, ondersteunen bij implementatie en kunnen een re-audit uitvoeren.

We explain findings to OT, IT and management teams, support implementation and can perform a re-audit to validate improvements.

DebriefRe-audit optioneel

Gevoelige informatie wordt met de grootst mogelijke zorgvuldigheid behandeld en veilig vernietigd na de retentieperiode.

Sensitive information is handled with utmost care during the assessment and securely destroyed after the retention period.

Wat u ontvangt
What You Receive

Wat ontvangt u?

What you receive

Elke OT Security Audit levert een compleet, auditklaar pakket op – afgestemd op industriële omgevingen en OT-stakeholders.

Every OT Security Audit delivers a complete, audit-ready package – tailored to industrial environments and OT stakeholders.

📄
Managementsamenvatting
Executive Summary

Boardklaar overzicht van OT-risicopositie, kernbevindingen en aanbevolen prioriteiten.

Board-ready overview of OT risk posture, key findings and recommended priorities.

🔍
Technisch bevindingsrapport
Technical Findings Report

Gedetailleerde documentatie per bevinding: beschrijving, bewijs, risiconiveau en herstelstappen.

Detailed per-finding documentation: description, evidence, risk level and remediation steps.

📊
IEC 62443 & NIS2 mapping
IEC 62443 & NIS2 Mapping

Bevindingen gekoppeld aan IEC 62443-zones en NIS2-vereisten – direct bruikbaar voor compliance.

Findings mapped to IEC 62443 zones and NIS2 requirements – directly usable for compliance.

🗺️
Verbeteringsroadmap
Remediation Roadmap

Gefaseerd actieplan: quick wins, kortetermijnfixes en structurele verbeteringen.

Phased action plan: quick wins, short-term fixes and longer-term improvements.

🤝
Debrief & teamsessie
Debrief & Team Session

Live walkthrough met OT-, IT- en managementteams – vragen beantwoord, prioriteiten afgestemd.

Live walkthrough with OT, IT and management teams – questions answered, priorities aligned.

🔁
Optionele re-audit
Optional Re-audit

Na implementatie bevestigt een re-audit dat kritieke bevindingen effectief zijn opgelost.

After implementation, a re-audit confirms that critical findings have been effectively resolved.

Wilt u meer zekerheid over de security van uw EMS- en supply chain-partners in Europa, Azië of de Amerika’s? Deel uw industriële infrastructuur en wij helpen u de scope van een OT Security Audit te bepalen.

Share your industrial infrastructure details and we will help define the scope of a tailored OT Security Audit.

Vraag uw OT Security Audit aan Request Your OT Security Audit

Geen verplichtingen. Wij reageren doorgaans binnen 1 werkdag. No commitment. We typically respond within 1 business day.


Veelgestelde vragen
Frequently Asked Questions

Veelgestelde vragen

Frequently Asked Questions


Gerelateerde diensten
Related Services

Heeft u ook dit nodig?

You might also need

Een OT Security Audit is vaak onderdeel van een bredere securitystrategie. Deze diensten vullen elkaar goed aan.

An OT Security Audit is often part of a broader security strategy – these services complement it well.