Audit the plant. Prove resilience. Train the auditor.

Industrial security you can measure.

OT360™ combines a structured operational technology audit methodology with hands-on auditor training to help manufacturers understand what they have, what could stop production, and how well they can recover.

12 domainsGovernance through recovery
120 controlsEvidence-driven assessment
0–5 maturityConsistent scoring model
15 weeksAuditor Academy curriculum
Example OT360™ Readiness View● Evidence-based
68Overall readiness score
Asset intelligence
82
Segmentation
64
Remote access
71
Recovery
49
Two connected offerings

Assess the environment. Build the people who can assess it.

OT360™ creates a repeatable industrial assurance model: a customer-facing audit service and a disciplined training pathway for the auditors who deliver it.

01

OT360™ Industrial Security Audit

Structured assessment of cybersecurity, operational resilience, connectivity, recoverability, supportability and lifecycle risk across the plant.

02

OT360™ Auditor Academy

College-level, hands-on curriculum teaching OT principles, plant walkthroughs, evidence collection, scoring, finding development and executive reporting.

03

OT360™ Continuous

Continuous control validation, evidence refresh, remediation tracking and measurable maturity improvement between formal assessments.

OT360™ Industrial Security Audit

An OT audit designed around production reality.

The methodology is passive-first and evidence-driven. It evaluates whether controls actually reduce operational risk—not whether a policy or checkbox merely exists.

Evidence over assertion

A maturity score of 4 or 5 should be supported by objective evidence and validation, not interview statements alone.

Operational consequence

Findings are translated into production, safety, quality, recovery and business impact—not just technical severity.

Recovery is security

PLC programs, HMI projects, SCADA configurations, industrial PC images, licenses, firmware and spares are evaluated as part of resilience.

1Governance & OT Risk Management
2Asset Intelligence & Criticality
3Network Architecture & Segmentation
4Identity, Privileged & Remote Access
5Endpoint & Engineering Workstation Security
6Vulnerability, Patch & Configuration
7Monitoring, Detection & Security Operations
8Backup, Restore & Production Recovery
9Incident Response & Business Continuity
10Physical, Environmental & Supply Chain
11Safety, Change & Operational Resilience
12Lifecycle, Compliance & Improvement
1. ScopeSites, lines, assets, safety rules
2. DiscoverInterviews, evidence, walkthrough
3. ValidatePassive-first technical review
4. ScoreMaturity + contextual risk
5. RoadmapNow / next / later remediation
OT360™ Auditor Academy

Teach auditors to understand the plant before they grade the plant.

The Academy combines classroom instruction, cyber-range exercises, interviews, evidence challenges, finding-writing drills and a complete simulated manufacturing-site audit.

Weeks 1–3 — Foundations & Audit Safety START HERE

Industrial terminology, PLC/HMI/SCADA concepts, Purdue architecture, zones/conduits, scope, Rules of Engagement, evidence methods, and safe OT audit behavior.

Weeks 4–6 — Risk, Assets & Network Architecture CORE

Plant criticality, asset intelligence, authoritative inventory, passive discovery, communication baselining, segmentation, firewalls, conduits and industrial DMZ concepts.

Weeks 7–9 — Access, Endpoints & Vulnerability CONTROL

Vendor access, MFA, privileged access, engineering workstation security, Fleet/osquery evidence, patch constraints, compensating controls and OT-specific vulnerability prioritization.

Weeks 10–12 — Detection, Recovery & Incident Response RESILIENCE

Wazuh evidence, telemetry, alert context, PLC/HMI backups, restoration readiness, ransomware scenarios and safe containment decision-making.

Weeks 13–15 — Operations, Scoring & Capstone PROVE IT

Physical/supply-chain resilience, lifecycle risk, scoring calibration, report writing, 30/90/365-day roadmap, and the full Atlas Precision Manufacturing simulated OT360™ audit.

Auditor development

A certification path built around demonstrated competence.

The program emphasizes safety, evidence quality, scoring consistency and practical audit performance. Certification is an OT360™ program credential, not a certification issued by NIST, CISA or ISA.

Level 1

OT360™ Certified Auditor

  • Complete core course
  • Pass knowledge exam
  • Pass practical evidence exam
  • Pass safety gate
  • Complete capstone audit
Level 2

OT360™ Lead Auditor

  • Level 1 credential
  • Field assessment experience
  • Lead assessments under supervision
  • Advanced reporting practical
  • Score-calibration proficiency
Level 3

OT360™ Principal Auditor

  • Complex/multi-site assessments
  • Architecture and resilience depth
  • Finding approval authority
  • Auditor coaching
  • Executive presentation mastery
Standards informed

Built to speak the language of recognized OT security guidance.

OT360™ uses recognized guidance as a foundation while maintaining its own assessment, scoring, evidence and training methodology.

NIST SP 800-82 Rev. 3Operational technology security guidance emphasizing performance, reliability and safety.
NIST CSF 2.0Govern, Identify, Protect, Detect, Respond and Recover outcomes for cybersecurity risk management.
CISA CPGsHigh-impact baseline practices for critical-infrastructure cybersecurity, including OT owners.
ISA/IEC 62443Industrial automation and control system cybersecurity lifecycle, stakeholder and security concepts.
Questions

Frequently asked questions

Is OT360™ an IT penetration test?+

No. OT360™ is an industrial security and resilience assessment methodology. Technical validation is passive-first and governed by explicit Rules of Engagement.

Does an auditor need to be a controls engineer?+

No. The Academy teaches enough automation, networking, asset, recovery and process context for competent auditing while respecting where controls-engineering expertise is required.

Why are backup and recovery part of the audit?+

Because cyber resilience depends on the ability to restore PLC programs, HMI projects, industrial PCs, configurations, licenses and supporting infrastructure.

Can OT360™ support multiple sites?+

Yes. The method can be applied at one plant, multiple sites, or as an enterprise program with consolidated reporting.

How is a 4 or 5 maturity score earned?+

Higher maturity requires stronger evidence. A 4 should generally be verified through objective evidence; a 5 should demonstrate consistent measurement, governance and continuous improvement.

Is the credential issued by NIST, CISA or ISA?+

No. OT360™ certification is an independent program credential. Those organizations do not sponsor or endorse OT360™.

Bring OT360™ to your plant—or train the team that will assess it.

Use OT360.org as the commercial home for industrial security audits, auditor education, certification, academic partnerships and enterprise assessment programs.