SegAudit
IT/OT segmentation audits

Hand over the fix, not just the findings.

Most assessments end with a list of attack paths for the firewall engineer to close. SegAudit hands over the fix: rule changes in the firewall's own syntax, checked so they don't open a new path or stop production, each with a rollback.

Which fits your work?

  • No AI in the analysis. Every finding comes from the configuration and traffic log you load.
  • Your data never leaves. Analysis runs in the browser. No upload, no account, no telemetry.
  • Runs air-gapped. One signed container on a jump host. No internet, no firewall API.
Northline (sample plant) · Change package · Window 1Change 4 of 8
CHG-07

Narrow the Level 3.5 jump host path to the Cell A controllers

Not reviewedRecommended
Level 4EnterpriseLevel 3.5DMZLevel 3OperationsLevel 2SupervisoryLevel 1ControlRule 14 reaches every Level 1 asset, on any servicenl-edge-fw01jump-hostsplc-a-01modbusplc-a-02modbushmi-a-01ethernet-ipeng-sharesmblogged anddropped+14 moreskips Level 3 and Level 2
Kept, narrowed to what was usedWhat rule 14 allowedLogged and dropped
any → 3destinations kept
2applications kept
2,786 of 2,792sessions kept

Rule 14, after the change

Destination any
plc-a-01plc-a-02hmi-a-01
Application any
modbus-baseethernet-ip
Service any
application-default
Everything else
deny, logged

The evidence, 7 days

Three hosts and three services were used in 7 days. Nothing else crossed.

plc-a-01 tcp/502 modbus1,284
plc-a-02 tcp/502 modbus1,190
hmi-a-01 tcp/44818 ethernet-ip312
eng-share tcp/445 smb6
Your decision on CHG-07 · reviewing as Sam RiveraNot reviewed
RecommendedAwaiting the client's decision. Their team approves it in the review file that comes with your handoff.

Try it: switch the view, hover a flow, open the tabs. Sample change from the built-in Northline plant.

Try it: switch the view, hover a flow, open the tabs, decide. Sample change from the built-in Northline plant.

Try it: switch the view, hover a flow, open the tabs. Sample change from the built-in Northline plant.

Pick one above, or here, to see SegAudit for your workShowing SegAudit for consultantsShowing SegAudit for plant teams

More assessments, same team.

The analysis and the write-up are the slow part of a segmentation assessment. SegAudit does both from the client's own firewall config and traffic log, so your consultants spend their days on judgment, not spreadsheets.

Chasing evidence

The client's engineer is not sure what to export, the first files come back from the wrong week, and a day goes on email before analysis starts.

The evidence request writes copy-paste export steps for their engineer, with their device names filled in.

Analysis in spreadsheets

Mapping zones, filtering sessions and matching them to rules by hand is slow, and it is hard for a second consultant to check.

Every crossing is ranked by risk with the sessions and rule behind it, in one queue a second consultant can check.

Writing it up

The report, the change plan, the executive summary and the follow-on proposal are each written from scratch, under deadline.

The brief, report, change package, roadmap and proposal come out together, in Word under your firm's template.

An engagement, start to handoff

The tool runs on your workstation or a jump host the client provides. It never connects to their firewall.

  1. 1

    Send the evidence request

    Pick the firewall and the traffic window. SegAudit writes the export steps for the client's engineer.

    Evidence5 of 5
    nl-edge-fw01 running config
    sha256 a41f…
    ✓
    nl-core-fw02 running config
    sha256 77c0…
    ✓
    nl-cell-fw03 running config
    sha256 0be9…
    ✓
    traffic 09-21 to 09-28
    sha256 9f3c…
    ✓
    FortiAnalyzer export
    sha256 c2d1…
    ✓

    The evidence screen as the client's files land.

  2. 2

    Triage the findings

    Violations ranked by risk, each with an owner, a ticket and your own wording where you disagree.

    Violations31, ranked by risk
    L3.5 → L1 jump-hosts2,792
    L4 → L2 RDP418
    L5 → L3.5 vendor96
    L3 → L1 telnet0
    L4 → L1 ICMP12
    L2 → L1 cell-b1,031

    Violations, ranked by risk.

  3. 3

    Build the change package

    Each change with firewall syntax, web steps and a rollback the client's engineer can follow.

    Level 4EnterpriseLevel 3.5DMZLevel 3OperationsLevel 2SupervisoryLevel 1ControlRule 14 reaches every Level 1 asset, on any servicenl-edge-fw01jump-hostsplc-a-01modbusplc-a-02modbushmi-a-01ethernet-ipeng-sharesmblogged anddropped+14 more

    The change package for one rule.

  4. 4

    Deliver under your letterhead

    One zip with the brief, report, change package, roadmap, proposal and crosswalk.

    lakeshore-q4-acme.zip7 files
    Executive brief.docx
    Audit report.docx
    Change package.docx
    Roadmap and proposal.docx
    Readout.pptx
    Findings workbook.xlsx
    Compliance crosswalk.docx

    The handoff zip, under your template.

What you hand the client

Every deliverable is computed from the same evidence, so the brief, the report and the proposal always agree.

See a sample deliverable

Your firm, on every engagement

Set it once. Every consultant quotes and delivers from the same card.

Firm profile
Your name, lead consultant, logo, default frameworks, rate card and proposal terms, set once and shared as a firm file.
Word under your template
Every document exports as .docx in Word's own styles, so your firm's template restyles it.
Your judgment stays visible
Observations and reworded findings are printed as yours, with the reason.
Client data locked down
Encrypt the saved engagement with a passphrase, and hand over a password-protected zip.
Firm profileShared as acme-ot.firm.json
ACME
OT
ADVISORY
Firm
Acme OT Advisory
Lead consultant
Dana Patel
Template
Acme report.dotx
Default frameworks
IEC 62443-3-3, NIST CSF 2.0
Rate card
4 roles, used by every roadmap
Proposal terms
Net 30, acceptance on verification

Know your segmentation holds, every quarter.

Run SegAudit on a jump host inside your own network. It reads your firewall config and the sessions the firewall logged, shows which paths into the plant are really in use, and writes the change window that closes them without stopping production.

Rules drift between audits

Allows added during an outage or a vendor visit stay open. A rulebase review alone can't tell which ones still carry traffic.

Every rule that touches OT is shown with its hits and last hit, so the ones nobody uses stand out.

Nobody wants to cut production

Without the sessions behind each rule, a drop is a guess, so risky allows survive another year.

Each change keeps the flows production uses, and is checked so it doesn't stop them.

Audits take weeks of spreadsheets

Exporting, mapping zones and writing up findings by hand means the review happens once a year, if that.

The analysis and write-up come straight from the exported files, so the periodic review takes an afternoon.

A quarter with SegAudit

The same steps every quarter, so the review becomes routine instead of a project.

  1. 1

    Export the files

    An engineer exports the config and a traffic log from the plant. SegAudit never connects to the firewall.

    Evidence5 of 5
    nl-edge-fw01 running config
    sha256 a41f…
    ✓
    nl-core-fw02 running config
    sha256 77c0…
    ✓
    nl-cell-fw03 running config
    sha256 0be9…
    ✓
    traffic 09-21 to 09-28
    sha256 9f3c…
    ✓
    FortiAnalyzer export
    sha256 c2d1…
    ✓

    The evidence screen as each file lands.

  2. 2

    See what is really open

    Every session that crosses a Purdue level it shouldn't, ranked by risk, with the rule that allowed it.

    Violations31, ranked by risk
    L3.5 → L1 jump-hosts2,792
    L4 → L2 RDP418
    L5 → L3.5 vendor96
    L3 → L1 telnet0
    L4 → L1 ICMP12
    L2 → L1 cell-b1,031

    Violations, ranked by risk.

  3. 3

    Change through your CAB

    Each change carries CLI, web steps, rollback and a ticket, written for the manager you already run.

    Level 4EnterpriseLevel 3.5DMZLevel 3OperationsLevel 2SupervisoryLevel 1ControlRule 14 reaches every Level 1 asset, on any servicenl-edge-fw01jump-hostsplc-a-01modbusplc-a-02modbushmi-a-01ethernet-ipeng-sharesmblogged anddropped+14 more

    The change window, ready for your CAB.

  4. 4

    Prove it worked

    Drop the next traffic log; every change comes back Verified, Regressed, Not applied or No traffic, and the quarter is saved.

    Verifytraffic 10-05 to 10-12
    CHG-03VERIFIED
    CHG-05VERIFIED
    CHG-06Not applied
    CHG-07VERIFIED
    CHG-08Regressed
    CHG-10No traffic

    Verification against the next traffic log.

Built for the whole plant team

Unlimited internal users, so everyone works from the same findings.

OT and controls engineers

See which sessions cross into Level 2 and below, and what a change would break before anyone touches a rule.

Network and firewall team

Change windows with CLI, rollback and a CAB ticket, for the Panorama, FortiGate, ASA, FMC or Check Point manager you run.

Site and OT security leads

Track maturity, attack paths and open issues per plant, and run the periodic rule review in an afternoon.

CISO and plant management

A one-page brief each quarter: where each plant stands, what changed, and what is still open.

What you get

Every plant, tracked across quarters, with the evidence your policy review asks for.

Quarterly checkpoints
Maturity tier per plant, live attack paths, open issues and program remaining, compared quarter over quarter.
Periodic rule review
Every rule that touches OT with its hits, last hit and a keep, narrow, remove or recertify recommendation, plus a sign-off sheet.
Multi-plant aware
Plans per plant across a multi-site estate, pilot plant first.
Signed review log
Approve, Hold or Accept the risk on each change, with who decided and when, signed into a log you can show an auditor.
Compliance evidence
IEC 62443-3-3, NIST CSF 2.0, CMMC Level 2, ISO/IEC 27001 and NIS2 marked supported, partial or gap.
Maturity per plantTier and live attack paths, by quarter
PlantQ1Q2Q3Q4
Northline14963
Riverside8742
Kenosha211695
Periodic rule reviewnl-edge-fw01 · Q4
RuleHits, 30 daysLast hitRecommendation
14 dmz-to-cell-any2,792Oct 1Narrow
9 legacy-telnet0NeverRemove
22 vendor-vpn-l20Aug 14Recertify
31 hist-repl5,140Oct 1Keep
Reviewed byApproved byDate

What a hits-only review misses

A rule with zero hits is often shadowed, not idle. Tighten the wrong rule first and an unused one underneath quietly becomes the new path into the plant. SegAudit calls that a priority trap, and it sequences the change so it cannot happen.

What it catchesWhat it isExample from the sample plantBacked by
Observed violationsHops IEC 62443-3-3 SR 5.1 and 5.2 would not allow, evidenced by real sessions.Jump host reached plc-a-01 on Modbus, 1,284 sessionsLogged sessions
Latent exposureRules that permit a bypass nobody has used yet, kept separate from live traffic.Rule 22 lets vendor VPN reach Level 2. No sessions yet.Rulebase, no traffic yet
Priority trapsCaught before a change opens a new path.Rule 9: zero hits, shadowed by rule 4Rulebase and traffic
Change packageCLI, web steps, XML API, pre-checks, verification and rollback for every change.CHG-07: three flows kept, the rest logged and droppedEvery finding above
Trust center

Security reviewers welcome

SegAudit was built to run in the most restricted networks. The trust center shows exactly where your files go, how each release is signed, and how to verify it before it touches a jump host.

Open the trust centerSee the data flow

Analysis
No AI in the analysis. Every finding comes from the configuration and traffic log you load.
Network
No outbound network connections. Updates and renewals are links you choose to open.
Data
Analysis runs in the browser on your workstation or jump host. No upload, no telemetry.
Firewall access
None. SegAudit reads exported files and pushes nothing.
Distribution
One signed container on a jump host. Verify each release before it runs.

Common questions

Can I pick the engagement up next quarter?
Yes. Save the engagement as a file, encrypted if you like, then load next quarter's config and log into it. Checkpoints, observations, the rate card and the letterhead carry over, and Progress shows what moved.
Can I edit the deliverables?
Yes. Every document exports as a Word .docx in Word's own styles, so it takes your firm's template, and as markdown. Findings, tickets and inventories export as CSV.
Who runs it day to day?
Usually the firewall or OT security engineer. Unlimited internal users are included, so controls engineers and auditors can review the same findings.
Can we start without buying?
Yes. The free Community edition runs the full analysis of one plant, up to 2 firewalls, with one traffic window. Paid plans add checkpoints, unlimited plants and support.
Does it connect to the firewall?
No. SegAudit only reads exported files. It has no firewall API access and pushes nothing.
Which firewalls does it support?
Palo Alto Networks Panorama and standalone PAN-OS firewalls, Fortinet FortiGate with FortiAnalyzer, Cisco ASA (ASA 9.x, including ISA 3000 and ASA 5500-X), Cisco FTD managed by FMC 7.4, and Check Point R81.10 to R82 with a Security Management Server. See firewall support for details.
Where does my data go?Where does my data go?Where does my client's data go?
Nowhere. Analysis runs in the browser on your workstation or jump host, with no upload and no telemetry. The data flow page shows the proof.
Is it a certification?
No. SegAudit produces evidence and a crosswalk for your assessor. It does not certify against IEC 62443 or any other framework.No. SegAudit produces evidence and a crosswalk for your assessor. It does not certify against IEC 62443 or any other framework.No. SegAudit produces the evidence and a crosswalk your client can hand their assessor. It does not certify against IEC 62443 or any other framework.

Start free

The Community edition is free and includes the built-in Northline sample plant, so you can see every screen before you export anything. Paid plans are priced per consultant, per engagement or per plant.

Try it on your next engagement

The 30-day Professional trial puts your letterhead on every deliverable. No call, no card. Or download the free edition and open the built-in Northline sample plant first.

Try it on one of your plants

The 30-day Plant edition trial covers every audit feature for your own plants, and you can pay by purchase order when you buy. Or download the free edition and open the built-in Northline sample plant first.