OT Security Assessment
Identifies substantive operational-technology, SCADA, ICS, and industrial-control security assessments. Topic phrases are retained for discovery; enforcement requires findings, affected assets, evidence, remediation, attack paths, firmware, segmentation, credential, or remote-access weaknesses, and high confidence additionally requires a concrete technical indicator and severe exploit consequence.
- Type
- regex
- Engine
- boost_regex
- Confidence
- medium
- Confidence justification
- Medium confidence requires assessment findings rather than a title or methodology reference. High confidence adds a concrete affected asset or vulnerability and severe exploitable consequence.
- Jurisdictions
- global
- Regulations
- Criminal Code Act 1995 (Cth), SOCI Act 2018 (Cth)
- Frameworks
- CIS Controls, ISO 27001, NIST CSF
- Data categories
- security, infrastructure
- Scope
- narrow
- Risk rating
- 10
- Platform compatibility
- Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Degraded, Netskope: Unsupported
Pattern
(?is)\b(?:OT\s+security\s+assessment|SCADA\s+security\s+assessment|ICS\s+security\s+assessment|industrial\s+control\s+security\s+assessment|control\s+system\s+vulnerability\s+assessment|(?:OT|SCADA|ICS)\s+penetration\s+test)\b
Should match
OT security assessment— Low-tier probe - assessment topic without findingsOT security assessment finding: unsupported firmware and a segmentation gap were observed; remediation action is scheduled— Medium-tier probe - substantive findings without a concrete asset or severe exploit consequenceOT security assessment finding for production PLC asset PLC-07 at 10.24.8.15: CVE-2025-12345 enables unauthenticated remote code execution; critical severity and remediation required— High-tier probe - finding with live asset, vulnerability, address, and severe exploit consequence
Should not match
Office security assessment for fire exits— Non-match 1IT security awareness training— Generic IT awareness content outside OT assessmentThe public guide explains how to scope an OT security assessment.— Public methodology guidance without findingsTraining example: OT security assessment finding for PLC-07, CVE-2025-12345, critical remote code execution— Explicit training content must not enforce
Known false positives
- Public methodologies, standards, and consulting material discuss OT assessments, vulnerabilities, CVEs, and remediation without containing an assessed organisation's findings. Mitigation: Keep assessment topics discovery-only and require finding, affected-asset, evidence, remediation, attack-path, firmware, segmentation, credential, or remote-access content.
- Training labs can include realistic asset IDs, addresses, CVEs, exploit paths, severities, and remediation actions. Mitigation: Reject explicit template, demo, tutorial, sample-data, and training-example framing from enforcing tiers.