Network Architecture
Last updated: December 2025
OT Site Survey in Practice: Systematically Mapping Production Networks
Anyone tasked with segmenting or securing a production network first needs a reliable picture of the current state. This is precisely where many projects fail. Existing documentation is outdated, the original plant builders are long gone, and no one remembers why the unmanaged switch is hanging in the control cabinet. An OT Site Survey closes this gap, provided it is carried out with methodological rigour. This article describes how a site survey plays out in practice from the perspective of a network and solution architect, which organisational groundwork needs to be laid beforehand, and which technical methods have proven themselves in production environments.
Why an OT Site Survey Is Not an IT Assessment
In IT, a network can largely be inventoried remotely: active scans, agents on endpoints, queries against central directories. In OT, none of these approaches works reliably, and some are simply dangerous for production or indeed for safety. Older controllers and field devices sometimes respond to a simple port scan with a restart or a frozen communication stack. A production stoppage caused by a "harmless" discovery tool is not a theoretical risk but lived project experience for many OT teams.
On top of this, a significant proportion of the relevant information exists in no network at all. The serial connection between controller and operator panel, the USB maintenance port on the frequency converter, the machine builder's LTE modem in the control cabinet – none of this is visible to a passive sensor or a scanner. An OT Site Survey is therefore always a combination of physical walkthrough, conversations with the people on site, and technical data capture. Anyone who covers only one of these three levels ends up with an incomplete, and therefore misleading, picture. Even where the area of action, and thus "responsibility", ends at the boundary of the production machine (which may be an entire hall with numerous devices), the production area must not be disrupted. The situation must be viewed from many angles: if, for example, planning activities extend into the production area, this can restrict or entirely void the machine manufacturer's warranty.
Organisational Preparation: The Survey Begins Weeks Before the Walkthrough
The most common cause of failed or worthless site surveys is not a lack of technology, but a lack of preparation. Four points must be clarified before setting foot through the factory gate.
Defining Scope and Target Picture
A survey without a defined objective produces data graveyards. It must be clear in advance what the results will be used for: as a basis for segmentation, for a risk assessment under IEC 62443-3-2, for the risk analysis and documentation obligations under the NIS2 Implementation Act, or for network modernisation. This determines which levels are captured – only the network infrastructure, or also field level, remote maintenance access and building services – and to what depth.
Bringing the Right People to the Table
Maintenance staff, plant electricians, production management, machine manufacturers/plant builders and, where one exists, the local OT officer know things that appear in no documentation. These people need to be involved early, not merely on the day of the walkthrough. Equally important is the formal side: safety briefings, access arrangements, and, where applicable, PPE requirements and photography permissions in the hall should be clarified beforehand, not at reception. In organisations with co-determination, the works council must also be informed as soon as network traffic captures are planned, since the traffic may contain personal data.
Gathering Existing Documentation
Everything that exists should be assembled before the walkthrough: network diagrams, electrical schematics of the control cabinets, plant documentation from the machine builders, switch configurations, firewall rule sets, and maintenance contracts with remote access clauses. This documentation is almost always outdated, but the discrepancy between paper and reality is itself a key finding of the survey.
Coordinating Time Windows with Production
Control cabinets should not be opened during running shift operations without prior agreement. Gases can, for example, be ignited by electricity in power supplies, or carbon dust can destroy power supplies or electrical equipment. The walkthrough requires time windows during which a plant manager can accompany the survey team. Extracting switch configurations and setting up mirror ports should ideally be coordinated with planned maintenance windows. Anyone who improvises here risks, at best, rejection by production staff and, at worst, a production stoppage.
The Walkthrough: What You Can Only See On Site
The physical walkthrough ideally follows the signal path: from the handover point between the office and production networks, through distribution rooms and hall distributors, to the control cabinets of individual plant units. A fixed recording scheme per site has proven effective – for example, photographs of every opened cabinet (an overview shot plus detail shots of the network components). Camera quality in poor lighting conditions has a direct bearing on the quality of the documentation. Labelling and type of every active device, patching and cable routing, and any conspicuous makeshift arrangements should all be noted and, where appropriate, photographed and subsequently written up.
Particular attention should be paid to things that appear on no network diagram at all: unmanaged switches that a machine builder installed "just quickly"; media converters and serial gateways; mobile routers and DSL connections for remote maintenance that bypass the central perimeter; and Wi-Fi access points of unclear origin or directly connected programming devices. Each such finding is doubly relevant, both as a potential security risk and as evidence that the official network topology is incomplete.
Interviews run in parallel with the technical data capture. Short, structured conversations with maintenance staff and machine operators answer questions that no tool can resolve. Who accesses which plant from outside? Which plant units must under no circumstances be touched? Where have there been network problems in the past? What dependencies exist between lines? This operational perspective later forms the basis for assessing the criticality of the zones.
Technical Data Capture: Passive Before Active, and Active Only With Authorisation
A clear hierarchy of methods applies to technical inventorying in OT, ordered by depth of intervention.
Level 1: Reading Configurations and Status Data
The most productive and, at the same time, lowest-risk starting point is the existing network components themselves. MAC address tables, ARP caches, LLDP/CDP neighbour relationships, and VLAN and port configurations from managed switches already provide a remarkably complete picture of connected devices and real topology without sending a single additional packet into the network. This requires access to the components, which must be contractually clarified for plant owned by machine builders.
Level 2: Passive Capture via SPAN or TAP
At central points (typically at the transition between levels, at cell uplinks, and ahead of remote maintenance gateways), traffic is diverted via SPAN/mirror ports or network TAPs and analysed with a suitable tool. Passive OT discovery tools identify device types, firmware versions, industrial protocols in use, and above all the actual communication relationships from the captured traffic. A sufficient recording duration is essential. Some communication, such as backup jobs, recipe transfers or cyclical remote maintenance check-ins, only occurs daily or weekly. A capture lasting only a few hours produces a communication matrix that appears clean but is, in reality, riddled with gaps.
Level 3: Selective Active Queries
Active methods, including targeted protocol queries or, in exceptional cases, narrowly scoped scans, are used only where passive methods leave gaps, and exclusively with the written authorisation of the plant manager, within agreed time windows, and with a defined fallback plan. Entire fieldbus segments containing legacy devices are, as a rule, excluded entirely; here, visual inspection at the cabinet replaces scanning.
From Raw Data to Results: Inventory, Communication Matrix, Zone Model
The real value of the survey emerges during analysis. Three artefacts should result at the end.
First, the consolidated asset inventory. Every device found is relevant with its type, manufacturer, firmware version, location (down to cabinet level), network connection, responsible owner and criticality. Merging walkthrough records, configuration data and passive analysis regularly reveals devices that appear in only one of the sources. This discrepancy list belongs explicitly in the report.
Second, the communication matrix: who talks to whom, over which protocol, in which direction, and how frequently. This forms the factual basis for every subsequent firewall policy and separates justifiable connections from historically grown legacy issues such as any-any rules between the office and production networks.
Third, the derived zone model: the captured assets are mapped to levels of the Purdue model (logically) and grouped into zones and conduits in line with IEC 62443-3-2 (physically) – according to criticality, protection requirements and actual communication relationships, not according to the organisational chart. The current state is compared against the target zone model, and the discrepancies yield a prioritised list of measures. In this way, the survey is also a key building block of the risk analysis that the NIS2 Implementation Act, in force since December 2025, requires of affected organisations. Without a reliable asset inventory, it is possible neither to assess risk properly nor to report an incident correctly.
Typical Pitfalls From Practice
- Treating the survey as a one-off exercise: An inventory becomes outdated from the day it is created. Without a defined maintenance process (ideally supported by permanently installed passive sensors), the result is worthless again within a year.
- Considering only the Ethernet network: Serial links, fieldbuses, point-to-point radio links and USB maintenance ports are attack and failure paths, even if they do not speak IP.
- Unintentionally interfering with production plant: The plant builder's warranty most often ends right there.
- Underestimating remote maintenance: The question "How does the manufacturer access this plant?" reveals at least one unknown external access point in almost every survey.
- Working without the people on site: Anyone who bypasses maintenance staff will neither be shown the makeshift arrangements nor later gain acceptance for segmentation.
- Delivering results with no link to measures: A 200-page report without prioritised measures agreed with production disappears into the cabinet alongside the old network diagrams.
Conclusion
An OT site survey is not a tool deployment, but a methodology. Careful organisational preparation, a physical walkthrough with the operations personnel responsible, and technical data capture strictly following the principle of "passive before active". Then an evaluation aimed at three concrete artefacts: inventory, communication matrix and zone model. This gives you a robust foundation for segmentation and compliance with standards, and along the way you may also earn the trust of the production team. You need both for everything that follows.
Note
This article reflects the author's personal professional assessment at the time of publication. It does not replace individual consultation. Details regarding standards, deadlines, versions and manufacturer functions should be verified before making any decisions. All content is provided without guarantee.