Methodology

The path we walk, in the order we walk it

This is the house sequence for an IoT control-application audit. It is not a maturity model and it is not a certificate. It is how we keep operations, IT, and the integrator looking at the same object.

Auditor working on a laptop beside industrial equipment

What is in scope on purpose

We treat as in-scope any software that can change, or authorise a change to, a process value: operator apps, HMIs in a browser, MQTT or API command topics, edge rule engines, cloud device methods, and the accounts that can reach them.

We treat as out of scope, unless you add them in writing: safety-instrumented systems that have no IoT path, corporate email, and general IT hygiene that does not touch the control application. If a finding in the control app depends on a weak plant VLAN, we will say so without turning the week into a network redesign.

Write tests

Where the engagement includes a command-path audit, we only issue a test write with a named operations person in the room, on a window they choose, on equipment they accept. If the site cannot authorise a write, we stop at observation and say so in the pack. We do not run unsolicited exploits against your plant.

What you hold at the end

A command inventory (or a tag-path dossier, depending on the service), a privilege matrix, evidence notes, and a remediation order split into “before the next vendor login” and “next planned window”. The pack is a document. You do not need our software to read it.

Book the scoping conversation

Choose an engagement type

01

Scoping conversation

A call or a visit to name the applications, the processes they can touch, and whether we may perform supervised write tests.

02

Evidence intake

Network sketch, role lists, broker or API notes, and a named operations contact. We will work from a whiteboard photo if that is what exists.

03

Path walk

On site or on a staged system, we follow commands, identities, and a sample of tags until they meet the field device or the software loop.

04

Closed findings session

Operations and IT hear the same record. We separate what can wait for a planned window from what should be constrained before the next vendor login.

05

Written pack

Command inventory, privilege matrix, evidence notes, and a remediation order. No dashboard login is required to read it.