Comprehensive OT Security Audit
Budget / Salary₹12,500–37,500
TypeFreelance project
LocationRemote
Posted2 hours ago
I need a seasoned OT-security specialist to run an end-to-end security assessment across several plant-floor environments and to deliver a clear, actionable report that highlights every weakness and maps out the fixes.
Scope in detail
• Honeywell control systems – 2 units
• Yokogawa control systems – 2 units
• Honeywell I/O – 100 sensors
• Yokogawa I/O – 100 sensors
• Rockwell PLCs – 100 sensors
• Rice Lake Weigh-Bridge – 100 sensors
The assessment must dig into network segmentation, firmware, access controls, physical interfaces and protocol exposure, using recognised OT frameworks such as IEC 62443 and NIST CSF where relevant. Feel free to bring in tools like Nessus, Wireshark, SHODAN, SecurityCenter, or vendor-specific utilities as long as production uptime is never jeopardised.
Primary objective
Identify every weak point—configuration, architecture or behavioural—and recommend a practical remediation plan ranked by risk and effort. Compliance mapping is useful, but exploitation proof-of-concepts are only required when they add clarity.
Deliverables
1. Kick-off brief outlining methodology, stakeholder contacts and schedule.
2. Interim status snapshot (after discovery phase).
3. Final report for each technology stack containing:
– Executive summary (non-technical)
– Detailed findings with CVSS scores or equivalent risk ratings
– Root-cause analysis and step-by-step remediation guidance
– Architecture diagrams and annotated network flows
4. Presentation walkthrough with my operations team.
What to include in your proposal
• Your on-site approach and estimated timeline.
• Toolset you plan to use and why it is suitable for Honeywell, Yokogawa and Rockwell environments.
• A concise example of a past OT assessment report (sanitised).
• Any required access, outage windows or safety precautions.
All listed systems carry equal priority, so structure the work to minimise plant disruption while touching every device. If you can commit to a methodical, evidence-driven assessment and present findings that non-cyber engineers will actually act on, I’d love to review your proposal.
Scope in detail
• Honeywell control systems – 2 units
• Yokogawa control systems – 2 units
• Honeywell I/O – 100 sensors
• Yokogawa I/O – 100 sensors
• Rockwell PLCs – 100 sensors
• Rice Lake Weigh-Bridge – 100 sensors
The assessment must dig into network segmentation, firmware, access controls, physical interfaces and protocol exposure, using recognised OT frameworks such as IEC 62443 and NIST CSF where relevant. Feel free to bring in tools like Nessus, Wireshark, SHODAN, SecurityCenter, or vendor-specific utilities as long as production uptime is never jeopardised.
Primary objective
Identify every weak point—configuration, architecture or behavioural—and recommend a practical remediation plan ranked by risk and effort. Compliance mapping is useful, but exploitation proof-of-concepts are only required when they add clarity.
Deliverables
1. Kick-off brief outlining methodology, stakeholder contacts and schedule.
2. Interim status snapshot (after discovery phase).
3. Final report for each technology stack containing:
– Executive summary (non-technical)
– Detailed findings with CVSS scores or equivalent risk ratings
– Root-cause analysis and step-by-step remediation guidance
– Architecture diagrams and annotated network flows
4. Presentation walkthrough with my operations team.
What to include in your proposal
• Your on-site approach and estimated timeline.
• Toolset you plan to use and why it is suitable for Honeywell, Yokogawa and Rockwell environments.
• A concise example of a past OT assessment report (sanitised).
• Any required access, outage windows or safety precautions.
All listed systems carry equal priority, so structure the work to minimise plant disruption while touching every device. If you can commit to a methodical, evidence-driven assessment and present findings that non-cyber engineers will actually act on, I’d love to review your proposal.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.