Service
Command-path audit
The engagement we are most often asked to run. We sit with a live or staged IoT control application and follow commands until they reach a pump, valve, drive, damper, or similar field device.
A command-path audit is a structured walk through the software that actually moves plant equipment. We start from the screens, tablets, or APIs that operators and supervisors use, then follow each write, setpoint, override, and emergency stop until it lands on a controller, gateway, or cloud function that can change a physical state.
We do not treat the mobile app, the broker, and the PLC as three separate products. The question is whether a person, a scheduled job, or a remote vendor session can change a process value, and whether that change is authenticated, authorised, logged, and reversible.
Typical work includes mapping MQTT, AMQP, REST, and vendor-proprietary write topics; listing which roles can publish to them; and checking whether “read-only dashboards” still hold retained messages or debug endpoints that accept commands. We also look at how the application fails: frozen UI, stale last-will messages, and reconnect storms that replay old setpoints.
You receive a command inventory, a privilege matrix, a set of observed gaps with evidence (screenshots, packet notes, configuration excerpts), and a remediation order that plant engineers can actually schedule. We present findings in a closed session with operations and IT, then leave a written pack suitable for internal audit or an insurer questionnaire.
This work is available as a standalone engagement or as the first phase of a wider control-application review.