Global business advisory · Due diligence · TurnaroundWorking across time zones
Manufacturing Due Diligence

Industrial Cybersecurity Due Diligence: Protecting OT, Automation and Production Continuity

Industrial cyber risk can stop equipment, compromise safety or quality, and delay recovery long after office systems return. This diligence framework tests OT architecture, access, legacy technology, backups and response capability, then translates gaps into production, capex, liability and closing decisions.

Shree Sarada Financial Advisors5 min readManufacturing Cybersecurity

Industrial cybersecurity due diligence should determine whether a target can keep production safe and recoverable when operational technology is disrupted. Office IT controls do not tell the whole story. Programmable controllers, supervisory systems, robots, test equipment, building controls and vendor connections interact with physical processes and often run legacy technology. Investors must translate weaknesses into downtime, scrap, safety and quality risk, remediation capex, legal obligations and deal terms.

Treat OT as a production system

Operational technology has different priorities and constraints from enterprise IT. Availability, deterministic operation and physical safety can limit when equipment is scanned, patched or restarted. A control change may require vendor support, validation and a shutdown. Diligence should therefore be led jointly by cybersecurity, automation, engineering, safety and operations specialists.

Never run intrusive discovery, vulnerability scanning or penetration testing on live OT without written authorisation, a tested method, backups, plant ownership and a safe rollback plan. Start with passive evidence and architecture review; escalate testing only when competent specialists determine it is safe.

Define the OT perimeter

Create a site-by-site map from enterprise systems to the production floor. Include industrial networks, PLCs, DCS, SCADA, HMIs, robots, CNC machines, safety systems, historians, laboratory and test systems, warehouse automation, utilities, environmental controls and remote engineering workstations. Record ownership and support for each.

Reconcile network diagrams and asset inventories with switch configurations, firewall rules, vendor lists, procurement records and a physical walk-down. Identify forgotten modems, wireless access, dual-homed computers, unmanaged switches and temporary vendor devices. Asset details should include model, firmware or operating system, criticality, location, process function, responsible owner, backup status and support lifecycle.

Test governance and decision rights

Review who owns OT cyber risk and who can approve access or change. Effective governance connects plant managers, engineering, IT, security, safety, vendors and executives. Examine policy, risk assessment, exception registers, security architecture, incident roles, capital planning and board reporting.

A policy designed for laptops may be unsafe or impossible for controllers. Look for OT-specific risk acceptance with expiry, compensating controls and named accountability. Review whether acquisitions, new machines and automation projects pass security requirements before connection. Current ISA/IEC 62443 materials provide a lifecycle framework for industrial automation and control systems, including asset-owner programme requirements.

Examine pathways into production

Trace external and internal access:

  • enterprise-to-OT connections and firewall rules;
  • vendor remote support, VPNs and jump hosts;
  • shared, default and dormant accounts;
  • removable media and engineering laptops;
  • wireless, cellular and cloud connections;
  • data flows to historians, MES and analytics platforms.

Test whether access is approved, time-bound, attributable and reviewed. Multi-factor authentication may be appropriate for remote entry, but control design must reflect operational constraints. Confirm that terminated employees and expired vendors are removed. Investigate internet-exposed devices and any connection that bypasses the monitored architecture.

Network segmentation should reduce the ability of one compromise to traverse plants or reach safety- and production-critical zones. Diagrams are not proof: inspect configurations and selected traffic evidence with specialists.

Assess legacy, change and vulnerability management

Identify unsupported systems, known vulnerabilities, default credentials, unapproved software and dependencies on obsolete hardware. Patch status alone is not a maturity measure; some OT patches need testing or cannot be applied promptly. Review risk assessment, vendor advice, lab testing, maintenance windows and compensating controls such as isolation or application allow-listing.

Examine management of change for logic, firmware, recipes, setpoints and network configurations. Confirm segregation between development and production, approval, version control and recovery copies. Quality and safety implications should be assessed before changes are deployed.

Prove backup and recovery capability

A successful file backup does not prove a line can restart. Inventory the items needed to rebuild: controller logic, HMI and SCADA configuration, historian, recipes, robot programmes, licences, certificates, engineering tools, firmware, golden images and vendor documentation.

Check backup frequency, isolation, integrity, access and alignment with change management. Review restoration tests and exercises that include safe process shutdown, equipment sequencing, quality validation and manual alternatives. NIST's 2026 OT Backup Quick Start Guide emphasises regular creation, testing and integration of OT backups with change and recovery exercises.

Estimate recovery time by critical product stream, not only by server. Consider spare controllers, replacement lead times, vendor availability, obsolete licences and the need to requalify output.

Review incidents and regulatory readiness

Reconcile security tickets, antivirus or monitoring alerts, downtime, unexplained control changes, insurance notifications and legal records. Trace selected incidents from detection through containment, safe operations, evidence preservation, recovery and lessons learned. Review tabletop exercises involving plant and leadership teams.

In India, CERT-In directions cover specified reporting, points of contact, clock synchronisation and log retention for covered entities and incidents, including attacks on SCADA and OT. Applicability and current requirements should be confirmed by cyber counsel at the transaction date. Sector regulators, customers and other jurisdictions may add obligations.

Convert cyber gaps into transaction economics

For each material scenario, estimate affected lines, safe shutdown, scrap and restart, lost contribution, customer penalties, forensic and recovery cost, liability, insurance response and remediation capex. Use ranges; cyber loss is not reliably represented by one expected value.

FindingDeal implication
Shared remote vendor accountsImmediate access control and monitoring plan
Unsupported critical controllerReplacement capex, validation and shutdown
Untested OT restorationWider interruption downside and day-one exercise
Flat network across sitesSegmentation programme and integration constraint
Known incident not fully investigatedDisclosure, liability and insurance review

Depending on evidence and advice, responses may include price changes, conditions, warranties, indemnities, escrow, cyber insurance actions or ring-fenced remediation funding. Integration should not connect the target to the buyer's network until risks are understood and controlled. Shree Sarada's due diligence and strategic advisory services can help join technical findings with the investment case.

Conclusion

OT cyber diligence is production-continuity diligence. It maps the systems that control physical work, tests how access and change are governed, proves recovery where possible and makes the cash and interruption consequences visible before closing.

Frequently asked

Questions we are asked on this topic

How is OT cybersecurity due diligence different from IT diligence?
OT diligence addresses systems that control physical processes, where safety, availability, quality and deterministic operation shape acceptable controls and testing. It requires automation and plant specialists alongside cybersecurity and IT teams.
Should an acquirer vulnerability-scan a live factory network?
Not by default. Active testing can disrupt fragile or safety-critical equipment. Any scan or penetration test requires explicit authorisation, competent OT specialists, vendor and plant input, backups, a safe method and rollback planning.
What evidence proves OT recovery readiness?
A complete asset and dependency map, protected configuration and logic backups, spare and licence availability, documented safe restart, restoration tests, output validation and exercises involving operations and vendors provide stronger evidence than backup-success messages alone.
How should OT cyber findings affect the deal?
Model downtime, scrap, recovery cost, capex, liability and integration constraints under scenarios. The response may include price or contractual protections and funded remediation, but urgent safety or access risks should be controlled immediately with specialist advice.
Continue exploring
Speak with us

Can the plant recover from an OT disruption?

We can help connect technical OT findings to production scenarios, remediation funding and transaction decisions.

Discuss OT cyber diligence

Sources and further reading

Reference material consulted while preparing this article. Listing a source does not imply endorsement of, or affiliation with, this firm.