SegAudit
IT/OT segmentation audits

Find the gaps. Close them.

Rule changes in the firewall's own syntax, checked so they open no new path, each with a rollback.

Which fits your work?

Professional editionReport, change package and proposal from the client's config and traffic log, in minutes.

Asset Owner editionAudit your own sites each quarter, approve each change, keep the signed record.

  • AI-free analysis
  • Air-gapped
  • Data stays local
  1. PPull
  2. RReview
  3. OOptimize
  4. VVerify
  5. EExport

An illustrative change, not from the Northline sample. Switch the view, hover a flow, open the tabs.

Illustrative change package · Window 1Change 4 of 8
CHG-07

Close the Level 3.5 jump host path into Cell A

Not reviewedRecommended
Level 4EnterpriseLevel 3.5DMZLevel 3OperationsLevel 2SupervisoryLevel 1ControlRule 14 reaches every Level 1 asset, on any servicelogged anddroppednl-edge-fw01jump-hostsops-a-01ms-rdpplc-a-01modbusplc-a-02modbusplc-a-03ethernet-ipeng-sharesmb+14 moreskips Level 3and Level 2
Kept: one path, into Level 3What rule 14 allowedLogged and dropped
What rule 14 allowedSessions seen, 7 days
anyLevel 1 destinations
4Level 1 hosts reached
2,792sessions in 7 days
any → 0Level 1 destinations
1path kept, into Level 3
2,792sessions logged and dropped

Rule 14, as found

Destination
any
Application
any
Service
any
Action
allow11,966 hits in 30 days

Rule 14, after the change

Action allow
disabled
In its place
ops-a-01ms-rdpapplication-default
Everything else
deny, logged

The evidence, 7 days

Three controllers and a file share were reached in 7 days, on Modbus, EtherNet/IP and SMB. Nothing else crossed.

plc-a-01 tcp/502 modbus1,284
plc-a-02 tcp/502 modbus1,190
plc-a-03 tcp/44818 ethernet-ip312
eng-share tcp/445 smb6
Your decision on CHG-07 · reviewing as Sam RiveraNot reviewed
RecommendedAwaiting the client's decision. Their team approves it in the review file in your handoff.

Try it: switch the view, hover a flow, open the tabs. An illustrative change, not from the Northline sample.

Try it: switch the view, hover a flow, open the tabs, decide. An illustrative change, not from the Northline sample.

Try it: switch the view, hover a flow, open the tabs. An illustrative change, not from the Northline sample.

Reads exports from

  • Palo Alto NetworksPAN⁠-⁠OS, Panorama
  • FortinetFortiGate
  • CiscoASA, Firepower (FTD)
  • Check PointR81.10 to R82

Maps evidence to

  • IEC 62443-3-3
  • NIST CSF 2.0
  • NERC CIP
  • NIS2
  • CMMC Level 2
  • ISO/IEC 27001
Pick one to see SegAudit for your workShowing SegAudit for consultantsShowing SegAudit for asset owners

More assessments, same team.

Analysis and write-up are the slow part of a segmentation assessment. SegAudit does both from the client's firewall config and traffic log, so your consultants spend their days on judgment.

Chasing evidence

The client's engineer isn't sure what to export, the first files cover the wrong week, and a day goes on email before analysis starts.

The evidence request gives their engineer copy-paste export steps, with their device names filled in.

Analysis in spreadsheets

Mapping zones and matching sessions to rules by hand is slow and hard for a second consultant to check.

Every crossing ranked by risk, with its sessions and rule, in one queue a second consultant can check.

Writing it up

Report, change package, brief and follow-on proposal, each written from scratch under deadline.

The brief, report, change package, roadmap and proposal come out together, in Word under your firm's template.

An engagement, start to handoff

It runs on your workstation or a client jump host, and never connects to their firewall.

  1. 1

    Send the evidence request

    Pick the firewall and the traffic window. SegAudit writes the export steps for the client's engineer.

    Evidence5 of 5
    nl-edge-fw01 running config
    sha256 a41f…
    ✓
    nl-core-fw02 running config
    sha256 77c0…
    ✓
    nl-cell-fw03 running config
    sha256 0be9…
    ✓
    traffic 2026-09-21 to 2026-09-28
    sha256 9f3c…
    ✓
    FortiAnalyzer export
    sha256 c2d1…
    ✓

    The evidence screen as the client's files land.

  2. 2

    Triage the findings

    Violations ranked by risk, each with an owner, a ticket and your own wording where you disagree.

    Violations31, ranked by risk
    L3.5 → L1 jump-hosts2,792
    L4 → L2 RDP418
    L4 → L1 ICMP12
    L2 → L1 cell-b telnet/smb1,031
    L5 → L3.5 vendor96
    L3 → L3.5 historian ftp5,140
    L3 → L1 telnet0

    Violations, ranked by risk.

  3. 3

    Build the change package

    Each change with firewall syntax, web steps and a rollback the client's engineer can follow.

    Level 4EnterpriseLevel 3.5DMZLevel 3OperationsLevel 2SupervisoryLevel 1ControlRule 14 reaches every Level 1 asset, on any servicelogged anddroppednl-edge-fw01jump-hostsops-a-01ms-rdpplc-a-01modbusplc-a-02modbusplc-a-03ethernet-ipeng-sharesmb+14 more

    The change package for one rule.

  4. 4

    Deliver under your letterhead

    One zip with the brief, report, change package, roadmap, proposal and crosswalk.

    lakeshore-q4-acme.zip7 files
    Executive brief.docx
    Audit report.docx
    Change package.docx
    Roadmap and proposal.docx
    Readout.pptx
    Findings workbook.xlsx
    Compliance crosswalk.docx

    The handoff zip, under your template.

What you hand the client

Every deliverable comes from the same evidence, so the brief, report and proposal always agree.

See a sample deliverable

Your firm, on every engagement

Set it once. Every consultant quotes and delivers from the same card.

Firm profile
Name, lead consultant, logo, default frameworks, rate card and proposal terms. Set once, shared as a firm file.
Word under your template
Every document exports as .docx in Word's own styles, so your firm's template restyles it.
Your judgment stays visible
Observations and reworded findings are printed as yours, with the reason.
Client data locked down
Encrypt the saved engagement with a passphrase, and hand over a password-protected zip.
Firm profileShared as acme-ot.firm.json
ACME
OT
ADVISORY
Firm
Acme OT Advisory
Lead consultant
Dana Patel
Template
Acme report.dotx
Default frameworks
IEC 62443-3-3, NIST CSF 2.0
Rate card
4 roles, used by every roadmap
Proposal terms
Net 30, acceptance on verification

Know your segmentation holds, every quarter.

Run SegAudit on a jump host inside your network. It reads your firewall config and traffic log, shows which paths into OT are really in use, and proposes a change window for them, each change with a rollback.

Rules drift between audits

Allows added during an outage or a vendor visit stay open. A rulebase review alone can't tell which ones still carry traffic.

Every rule that touches OT shows its hits and last hit, so rules the traffic log never shows in use stand out.

Nobody wants to cut production

Without the sessions behind each rule, a drop is a guess, so risky allows survive another year.

Each change keeps the flows production uses, and is checked so it doesn't stop them.

Audits take weeks of spreadsheets

Exporting, mapping zones and writing up findings by hand means the review happens once a year, if that.

The analysis and write-up come straight from the exported files, so the periodic review takes an afternoon.

A quarter with SegAudit

The same steps every quarter, so the review is routine, not a project.

  1. 1

    Export the files

    An engineer exports the config and a traffic log from the site. SegAudit never connects to the firewall.

    Evidence5 of 5
    nl-edge-fw01 running config
    sha256 a41f…
    ✓
    nl-core-fw02 running config
    sha256 77c0…
    ✓
    nl-cell-fw03 running config
    sha256 0be9…
    ✓
    traffic 2026-09-21 to 2026-09-28
    sha256 9f3c…
    ✓
    FortiAnalyzer export
    sha256 c2d1…
    ✓

    The evidence screen as each file lands.

  2. 2

    See what is really open

    Every session on a path that skips an adjacent Purdue level, or carries an application you restrict on that hop, ranked by risk, with the rule that allowed it.

    Violations31, ranked by risk
    L3.5 → L1 jump-hosts2,792
    L4 → L2 RDP418
    L4 → L1 ICMP12
    L2 → L1 cell-b telnet/smb1,031
    L5 → L3.5 vendor96
    L3 → L3.5 historian ftp5,140
    L3 → L1 telnet0

    Violations, ranked by risk.

  3. 3

    Change through your CAB

    Each change carries CLI, web steps, rollback and a ticket, written for the manager you already run.

    Level 4EnterpriseLevel 3.5DMZLevel 3OperationsLevel 2SupervisoryLevel 1ControlRule 14 reaches every Level 1 asset, on any servicelogged anddroppednl-edge-fw01jump-hostsops-a-01ms-rdpplc-a-01modbusplc-a-02modbusplc-a-03ethernet-ipeng-sharesmb+14 more

    The change window, ready for your CAB.

  4. 4

    Prove it worked

    Drop in the next traffic log. Every change comes back Verified, Regressed, Not applied or No traffic, and the quarter is saved.

    Verifytraffic 2026-10-05 to 2026-10-12
    CHG-03Verified
    CHG-05Verified
    CHG-06Not applied
    CHG-07Verified
    CHG-08Regressed
    CHG-10No traffic

    Verification against the next traffic log.

Built for the whole asset owner team

Unlimited internal users, so everyone works from the same findings.

OT and controls engineers

See which sessions cross into Level 2 and below, and what a change would break before anyone touches a rule.

Network and firewall team

Change windows with CLI, rollback and a CAB ticket, for the Panorama, FortiGate, ASA, FMC or Check Point manager you run.

Site and OT security leads

Track maturity, attack paths and open issues per site, and run the periodic rule review in an afternoon.

CISO and site management

A one-page brief each quarter: where each site stands, what changed, and what is still open.

What you get

Every site, tracked across quarters, with the evidence your policy review asks for.

Quarterly checkpoints
Maturity tier per site, live attack paths, open issues and program remaining, compared quarter over quarter.
Periodic rule review
Every rule that touches OT with its hits, last hit and a keep, narrow, remove or recertify recommendation, plus a sign-off sheet.
Multi-site aware
Plans per site across a multi-site estate, pilot site first.
Signed review log
Approve, Hold or Accept the risk on each change. Who decided and when is signed into a log you can show an auditor.
Compliance evidence
IEC 62443-3-3, NIST CSF 2.0, CMMC Level 2, ISO/IEC 27001 and NIS2 marked supported, partial or gap.
Maturity per siteTier and live attack paths, by quarter · illustrative
SiteQ1Q2Q3Q4
Lakeview14963
Riverside8742
Kenosha211695
Periodic rule reviewnl-edge-fw01 · Q4
RuleHits, 30 daysLast hitRecommendation
14 dmz-to-cell-any11,9662026-10-10Retired by CHG-07
9 legacy-telnet0NeverRemove
22 vendor-vpn-l202026-08-19Recertify
31 hist-repl5,1402026-10-10Narrow
Reviewed byApproved byDate
00 What it catches

What a hits-only review misses

A rule with zero hits is often shadowed, not idle. Tighten the wrong rule first and the unused one underneath becomes the new path into OT.

What it catchesWhat it isIllustrative exampleBacked by
Observed violationsPaths that cut across the segmentation and zone-boundary themes of IEC 62443-3-3 (SR 5.1, 5.2), shown by real sessions.Jump host reached plc-a-01 on Modbus, 1,284 sessionsLogged sessions
Latent exposureRules that permit a bypass nobody has used yet, kept separate from live traffic.Rule 22 lets vendor VPN reach Level 2. No sessions yet.Rulebase, no traffic yet
Priority trapsCaught before a change opens a new path.Rule 9: zero hits, shadowed by rule 4Rulebase and traffic
Change packageFirewall commands or console steps, pre-checks, verification and rollback for every change.CHG-07: the Level 1 path dropped; the jump hosts keep RDP into Level 3Every finding above
01 How it works

From two exported files to a fix your team can apply.

Every screen here is the real app, running the built-in Northline sample.

  1. Load the config and traffic log

    Exports you already have. Nothing connects to the firewall.

    The audit overview after loading the config and traffic log.
  2. See every crossing, ranked

    Violations ranked by risk, each with the sessions and rule behind it.

    Violations ranked by risk.
  3. Get the change package

    Rule changes in the firewall's own syntax, with web steps and a rollback for each.

    The change package with one change opened.
  4. Verify with the next log

    The next traffic window confirms each change did what it said.

    Verification against the next traffic log.
SegAudit · Northline sample · Change package The audit overview after loading the config and traffic log. Violations ranked by risk. The change package in SegAudit: a list of changes on the left and one change opened on the right with its risk assessment. Verification against the next traffic log.
02 What you hand over

Documents a change board can sign.

Every audit exports the same set, in Word and markdown, ready to forward.

  • Executive brief1 page per site
  • Audit reportWord, markdown
  • Change packageper device group
  • Compliance crosswalk10 frameworks
  • Maturity by siteAsset Owner edition
Maturity by site
Maturity
Audit report
Audit report
Compliance crosswalk
Crosswalk
Executive brief for the Northline sample
Executive brief
03 Trust center

Built for the most restricted networks.

Your files stay on your workstation or jump host. The trust center shows the data flow, how each release is signed, and how to verify it.

No AI in the analysis
Every finding comes from the configuration and traffic log you load.
No outbound connections
Updates and renewals are links you choose to open.
No firewall access
SegAudit reads exported files and pushes nothing.
Signed releases
Verify each release before it runs.

Open the trust centerSee the data flow

Your workstation or jump host report · change packageworkbook · review log Config export Traffic log Internet nothing goes out Firewall no API, nothing pushed

Common questions

Can I pick the engagement up next quarter?
Yes. Save the engagement as a file, encrypted if you like, and load next quarter's config and log into it. Checkpoints, observations, rate card and letterhead carry over. Progress shows what moved.
Can I edit the deliverables?
Yes. Every document exports as markdown and as a Word .docx that takes your firm's template. Findings, tickets and inventories export as CSV.
Who runs it day to day?
Usually the firewall or OT security engineer. Unlimited internal users are included, so controls engineers and auditors can review the same findings.
Can we start without buying?
Yes. The free Quick check reads one of your firewall configs in your browser today, and the Northline sample deliverable shows the full report. The free 30-day Asset Owner edition trial (every audit feature, your own sites' files, no call, no card) opens again soon.
Does it connect to the firewall?
No. SegAudit only reads exported files. It has no firewall API access and pushes nothing.
Which firewalls does it support?
Palo Alto Networks Panorama and standalone PAN⁠-⁠OS firewalls, Fortinet FortiGate with FortiAnalyzer, Cisco ASA (ASA 9.x, including ISA 3000 and ASA 5500-X), Cisco FTD managed by FMC 7.4, and Check Point R81.10 to R82 with a Security Management Server. See firewall support for details.
Where does my data go?Where does my data go?Where does my client's data go?
Nowhere. Analysis runs in the browser on your workstation or jump host, with no upload and no telemetry. The data flow page shows the proof.
Is it a certification?
No. SegAudit produces evidence and a crosswalk for your assessor. It does not certify against IEC 62443 or any other framework.No. SegAudit produces evidence and a crosswalk for your assessor. It does not certify against IEC 62443 or any other framework.No. SegAudit produces the evidence and a crosswalk your client can hand their assessor. It does not certify against IEC 62443 or any other framework.

Try it on your next engagement

New 30-day Professional trials are paused for now and open again soon. Until then, the Quick check and the Northline sample deliverable are open to everyone.

Try it on one of your sites

New 30-day Asset Owner edition trials are paused for now and open again soon. You can pay by purchase order when you buy. Until then, the Quick check reads one of your configs in your browser, and the Northline sample deliverable shows the full report.

Fix the seg fault before an attacker does.

The free Quick check reads one of your firewall configs in your browser and shows the paths it leaves open. New 30-day trials are paused for now and open again soon.