One tool from evidence to signed-off change.
Policy management tools grade the rulebase. SegAudit checks the policy and the observed sessions together, then writes the change your client can implement.
What other offline tools don't do
Configuration auditors model what your rules could allow. SegAudit starts from what your firewall actually logged.
Proof from traffic
With a traffic log, findings are the IT-to-OT sessions your firewall logged; with a config alone, they show what the rules allow, marked not verified by traffic. Both are placed on Purdue levels and IEC 62443 zones and conduits.
A change package, not just a finding
Least-privilege replacement rules, safety gates for the traffic production depends on, CLI and rollback, then a verdict from the next traffic window.
Deliverables under your name
Audit report, executive brief, roadmap, proposal and readout slides in Word, on your firm's letterhead.
Find what is really open
Traffic-backed findings
Session logs, not rulebase review alone.
Palo Alto, FortiGate, Cisco and Check Point
Panorama, standalone PAN-OS, FortiGate, FortiAnalyzer, Cisco ASA, Cisco FTD (FMC) and Check Point evidence on the same engine, recognized by content.
Purdue and IEC 62443 hops
Zones on L0 to L5 plus the IDMZ, and every hop the model does not allow.
Priority traps
Caught before a change lets an unused rule become the new path.
Path check
Can A reach B, today and after the change plans?
Attack paths
Internet, VPN and office to crown-jewel paths, live versus latent.
Remote access
Every way in from outside, who uses it, how often, and what to do.
Asset inventory
Every address as an asset from Device-ID, object names and traffic, with criticality and exposure.
Change it safely
Change package
Least-privilege exceptions for the flows production uses and logged drops for the rest, each with a risk rating, the commands for your platform, verification and rollback.
Safety gates
A change window is blocked if it would cut production or skip a step.
Production hosts
IPs that need a jump, replica or zone move are flagged before the drop.
Multi-site
Plans per plant across a multi-site estate, pilot plant first.
Post-change verification
The next traffic log marks each plan Verified, Regressed, Not applied or No traffic.
Isolation readiness
Can each plant be cut off from IT in an incident and keep running?
Deliver it to the client
Compliance crosswalk
Supported, partial or gap for IEC 62443-3-3, NIST CSF 2.0, NIST SP 800-171 / CMMC Level 2, ISO/IEC 27001 Annex A and NIS2.
Sector frameworks
NERC CIP-005 and CIP-007, the TSA pipeline and rail directives, the EPA water checklist, US Coast Guard 33 CFR 101.650 and UK NCSC CAF 4.0, shown only for clients in those sectors.
Your own observations
Findings from site walks, interviews and documents reach the report, briefs, roadmap, proposal and crosswalk, marked as yours.
Your wording
Reword or re-rate any generated finding, with the reason. The report shows the edit; the score keeps the original severity.
62443-3-2 worksheet
Each observed conduit with its target security level and the proposed fix.
Executive brief
One printable page, or seven readout slides, for the plant manager or the board.
Roadmap and business case
Every plan in four waves, priced from your rate card, against each plant's downtime cost.
Proposal
The follow-on statement of work, built from the roadmap.
Word documents
Every document as a .docx in Word's own styles, so your firm's template applies, with your logo on every page.
Firm profile
Letterhead, logo, rate card, frameworks, naming and proposal terms set once and shared across the firm.
Deliverables pack
Every deliverable in one .zip, with the evidence SHA-256s, or as an AES-256 password-protected zip.
Encrypted engagement files
Lock the saved engagement with a passphrase: AES-256-GCM in the browser, nothing sent anywhere.
Tabletop and SOC detections
A ransomware exercise on the client's own paths, and Splunk and Sentinel queries for the SOC.

