Hand over the fix, not just the findings.
Most assessments end with a list of attack paths for the firewall engineer to close. SegAudit hands over the fix: rule changes in the firewall's own syntax, checked so they don't open a new path or stop production, each with a rollback.
Which fits your work?
- No AI in the analysis. Every finding comes from the configuration and traffic log you load.
- Your data never leaves. Analysis runs in the browser. No upload, no account, no telemetry.
- Runs air-gapped. One signed container on a jump host. No internet, no firewall API.
Narrow the Level 3.5 jump host path to the Cell A controllers
Not reviewedRecommendedRule 14, after the change
- Destination
any - plc-a-01plc-a-02hmi-a-01
- Application
any - modbus-baseethernet-ip
- Service
any - application-default
- Everything else
- deny, logged
The evidence, 7 days
Three hosts and three services were used in 7 days. Nothing else crossed.
- Open Policies, then Security
The rulebase list with rule 14 highlighted.
- Clone rule 14 as l35-cell-a-eng
Destination set to the three hosts.
- Add l35-cell-a-drop below it
Action deny, log at session end.
- Disable rule 14 and commit
The commit dialog with the change summary.
Each step shows a screenshot from the firewall's own web console.
Try it: switch the view, hover a flow, open the tabs. Sample change from the built-in Northline plant.
Try it: switch the view, hover a flow, open the tabs, decide. Sample change from the built-in Northline plant.
Try it: switch the view, hover a flow, open the tabs. Sample change from the built-in Northline plant.
More assessments, same team.
The analysis and the write-up are the slow part of a segmentation assessment. SegAudit does both from the client's own firewall config and traffic log, so your consultants spend their days on judgment, not spreadsheets.
Chasing evidence
The client's engineer is not sure what to export, the first files come back from the wrong week, and a day goes on email before analysis starts.
The evidence request writes copy-paste export steps for their engineer, with their device names filled in.
Analysis in spreadsheets
Mapping zones, filtering sessions and matching them to rules by hand is slow, and it is hard for a second consultant to check.
Every crossing is ranked by risk with the sessions and rule behind it, in one queue a second consultant can check.
Writing it up
The report, the change plan, the executive summary and the follow-on proposal are each written from scratch, under deadline.
The brief, report, change package, roadmap and proposal come out together, in Word under your firm's template.
An engagement, start to handoff
The tool runs on your workstation or a jump host the client provides. It never connects to their firewall.
- 1
Send the evidence request
Pick the firewall and the traffic window. SegAudit writes the export steps for the client's engineer.
Evidence5 of 5nl-edge-fw01 running config
sha256 a41f…✓nl-core-fw02 running config
sha256 77c0…✓nl-cell-fw03 running config
sha256 0be9…✓traffic 09-21 to 09-28
sha256 9f3c…✓FortiAnalyzer export
sha256 c2d1…✓The evidence screen as the client's files land.
- 2
Triage the findings
Violations ranked by risk, each with an owner, a ticket and your own wording where you disagree.
Violations31, ranked by riskL3.5 → L1 jump-hosts2,792L4 → L2 RDP418L5 → L3.5 vendor96L3 → L1 telnet0L4 → L1 ICMP12L2 → L1 cell-b1,031Violations, ranked by risk.
- 3
Build the change package
Each change with firewall syntax, web steps and a rollback the client's engineer can follow.
The change package for one rule.
- 4
Deliver under your letterhead
One zip with the brief, report, change package, roadmap, proposal and crosswalk.
lakeshore-q4-acme.zip7 filesExecutive brief.docxAudit report.docxChange package.docxRoadmap and proposal.docxReadout.pptxFindings workbook.xlsxCompliance crosswalk.docxThe handoff zip, under your template.
What you hand the client
Every deliverable is computed from the same evidence, so the brief, the report and the proposal always agree.
Executive brief
One printable page per plant, or seven readout slides for the meeting.
Open sampleAudit report
Findings, scope notes and chain of custody with the source SHA-256s.
Open sampleChange package
Least-privilege exceptions and logged drops, each with CLI, web steps, verification and rollback.
Open sampleCompliance crosswalk
Supported, partial or gap for the frameworks the client answers to.
Open sampleYour firm, on every engagement
Set it once. Every consultant quotes and delivers from the same card.
- Firm profile
- Your name, lead consultant, logo, default frameworks, rate card and proposal terms, set once and shared as a firm file.
- Word under your template
- Every document exports as .docx in Word's own styles, so your firm's template restyles it.
- Your judgment stays visible
- Observations and reworded findings are printed as yours, with the reason.
- Client data locked down
- Encrypt the saved engagement with a passphrase, and hand over a password-protected zip.
OT
ADVISORY
- Firm
- Acme OT Advisory
- Lead consultant
- Dana Patel
- Template
- Acme report.dotx
- Default frameworks
- IEC 62443-3-3, NIST CSF 2.0
- Rate card
- 4 roles, used by every roadmap
- Proposal terms
- Net 30, acceptance on verification
Know your segmentation holds, every quarter.
Run SegAudit on a jump host inside your own network. It reads your firewall config and the sessions the firewall logged, shows which paths into the plant are really in use, and writes the change window that closes them without stopping production.
Rules drift between audits
Allows added during an outage or a vendor visit stay open. A rulebase review alone can't tell which ones still carry traffic.
Every rule that touches OT is shown with its hits and last hit, so the ones nobody uses stand out.
Nobody wants to cut production
Without the sessions behind each rule, a drop is a guess, so risky allows survive another year.
Each change keeps the flows production uses, and is checked so it doesn't stop them.
Audits take weeks of spreadsheets
Exporting, mapping zones and writing up findings by hand means the review happens once a year, if that.
The analysis and write-up come straight from the exported files, so the periodic review takes an afternoon.
A quarter with SegAudit
The same steps every quarter, so the review becomes routine instead of a project.
- 1
Export the files
An engineer exports the config and a traffic log from the plant. SegAudit never connects to the firewall.
Evidence5 of 5nl-edge-fw01 running config
sha256 a41f…✓nl-core-fw02 running config
sha256 77c0…✓nl-cell-fw03 running config
sha256 0be9…✓traffic 09-21 to 09-28
sha256 9f3c…✓FortiAnalyzer export
sha256 c2d1…✓The evidence screen as each file lands.
- 2
See what is really open
Every session that crosses a Purdue level it shouldn't, ranked by risk, with the rule that allowed it.
Violations31, ranked by riskL3.5 → L1 jump-hosts2,792L4 → L2 RDP418L5 → L3.5 vendor96L3 → L1 telnet0L4 → L1 ICMP12L2 → L1 cell-b1,031Violations, ranked by risk.
- 3
Change through your CAB
Each change carries CLI, web steps, rollback and a ticket, written for the manager you already run.
The change window, ready for your CAB.
- 4
Prove it worked
Drop the next traffic log; every change comes back Verified, Regressed, Not applied or No traffic, and the quarter is saved.
Verifytraffic 10-05 to 10-12CHG-03VERIFIEDCHG-05VERIFIEDCHG-06Not appliedCHG-07VERIFIEDCHG-08RegressedCHG-10No trafficVerification against the next traffic log.
Built for the whole plant team
Unlimited internal users, so everyone works from the same findings.
OT and controls engineers
See which sessions cross into Level 2 and below, and what a change would break before anyone touches a rule.
Network and firewall team
Change windows with CLI, rollback and a CAB ticket, for the Panorama, FortiGate, ASA, FMC or Check Point manager you run.
Site and OT security leads
Track maturity, attack paths and open issues per plant, and run the periodic rule review in an afternoon.
CISO and plant management
A one-page brief each quarter: where each plant stands, what changed, and what is still open.
What you get
Every plant, tracked across quarters, with the evidence your policy review asks for.
- Quarterly checkpoints
- Maturity tier per plant, live attack paths, open issues and program remaining, compared quarter over quarter.
- Periodic rule review
- Every rule that touches OT with its hits, last hit and a keep, narrow, remove or recertify recommendation, plus a sign-off sheet.
- Multi-plant aware
- Plans per plant across a multi-site estate, pilot plant first.
- Signed review log
- Approve, Hold or Accept the risk on each change, with who decided and when, signed into a log you can show an auditor.
- Compliance evidence
- IEC 62443-3-3, NIST CSF 2.0, CMMC Level 2, ISO/IEC 27001 and NIS2 marked supported, partial or gap.
| Plant | Q1 | Q2 | Q3 | Q4 |
|---|---|---|---|---|
| Northline | 14 | 9 | 6 | 3 |
| Riverside | 8 | 7 | 4 | 2 |
| Kenosha | 21 | 16 | 9 | 5 |
| Rule | Hits, 30 days | Last hit | Recommendation |
|---|---|---|---|
| 14 dmz-to-cell-any | 2,792 | Oct 1 | Narrow |
| 9 legacy-telnet | 0 | Never | Remove |
| 22 vendor-vpn-l2 | 0 | Aug 14 | Recertify |
| 31 hist-repl | 5,140 | Oct 1 | Keep |
What a hits-only review misses
A rule with zero hits is often shadowed, not idle. Tighten the wrong rule first and an unused one underneath quietly becomes the new path into the plant. SegAudit calls that a priority trap, and it sequences the change so it cannot happen.
| What it catches | What it is | Example from the sample plant | Backed by |
|---|---|---|---|
| Observed violations | Hops IEC 62443-3-3 SR 5.1 and 5.2 would not allow, evidenced by real sessions. | Jump host reached plc-a-01 on Modbus, 1,284 sessions | Logged sessions |
| Latent exposure | Rules that permit a bypass nobody has used yet, kept separate from live traffic. | Rule 22 lets vendor VPN reach Level 2. No sessions yet. | Rulebase, no traffic yet |
| Priority traps | Caught before a change opens a new path. | Rule 9: zero hits, shadowed by rule 4 | Rulebase and traffic |
| Change package | CLI, web steps, XML API, pre-checks, verification and rollback for every change. | CHG-07: three flows kept, the rest logged and dropped | Every finding above |
Security reviewers welcome
SegAudit was built to run in the most restricted networks. The trust center shows exactly where your files go, how each release is signed, and how to verify it before it touches a jump host.
- Analysis
- No AI in the analysis. Every finding comes from the configuration and traffic log you load.
- Network
- No outbound network connections. Updates and renewals are links you choose to open.
- Data
- Analysis runs in the browser on your workstation or jump host. No upload, no telemetry.
- Firewall access
- None. SegAudit reads exported files and pushes nothing.
- Distribution
- One signed container on a jump host. Verify each release before it runs.
Common questions
- Can I pick the engagement up next quarter?
- Yes. Save the engagement as a file, encrypted if you like, then load next quarter's config and log into it. Checkpoints, observations, the rate card and the letterhead carry over, and Progress shows what moved.
- Can I edit the deliverables?
- Yes. Every document exports as a Word .docx in Word's own styles, so it takes your firm's template, and as markdown. Findings, tickets and inventories export as CSV.
- Who runs it day to day?
- Usually the firewall or OT security engineer. Unlimited internal users are included, so controls engineers and auditors can review the same findings.
- Can we start without buying?
- Yes. The free Community edition runs the full analysis of one plant, up to 2 firewalls, with one traffic window. Paid plans add checkpoints, unlimited plants and support.
- Does it connect to the firewall?
- No. SegAudit only reads exported files. It has no firewall API access and pushes nothing.
- Which firewalls does it support?
- Palo Alto Networks Panorama and standalone PAN-OS firewalls, Fortinet FortiGate with FortiAnalyzer, Cisco ASA (ASA 9.x, including ISA 3000 and ASA 5500-X), Cisco FTD managed by FMC 7.4, and Check Point R81.10 to R82 with a Security Management Server. See firewall support for details.
- Where does my data go?Where does my data go?Where does my client's data go?
- Nowhere. Analysis runs in the browser on your workstation or jump host, with no upload and no telemetry. The data flow page shows the proof.
- Is it a certification?
- No. SegAudit produces evidence and a crosswalk for your assessor. It does not certify against IEC 62443 or any other framework.No. SegAudit produces evidence and a crosswalk for your assessor. It does not certify against IEC 62443 or any other framework.No. SegAudit produces the evidence and a crosswalk your client can hand their assessor. It does not certify against IEC 62443 or any other framework.
Start free
The Community edition is free and includes the built-in Northline sample plant, so you can see every screen before you export anything. Paid plans are priced per consultant, per engagement or per plant.
Try it on your next engagement
The 30-day Professional trial puts your letterhead on every deliverable. No call, no card. Or download the free edition and open the built-in Northline sample plant first.
Try it on one of your plants
The 30-day Plant edition trial covers every audit feature for your own plants, and you can pay by purchase order when you buy. Or download the free edition and open the built-in Northline sample plant first.