Find the gaps. Close them.
Rule changes in the firewall's own syntax, checked so they open no new path, each with a rollback.
Which fits your work?
Professional editionReport, change package and proposal from the client's config and traffic log, in minutes.
Asset Owner editionAudit your own sites each quarter, approve each change, keep the signed record.
- AI-free analysis
- Air-gapped
- Data stays local
- PPull
- RReview
- OOptimize
- VVerify
- EExport
An illustrative change, not from the Northline sample. Switch the view, hover a flow, open the tabs.
Close the Level 3.5 jump host path into Cell A
Not reviewedRecommendedRule 14, as found
- Destination
- any
- Application
- any
- Service
- any
- Action
- allow11,966 hits in 30 days
Rule 14, after the change
- Action
allow - disabled
- In its place
- ops-a-01ms-rdpapplication-default
- Everything else
- deny, logged
The evidence, 7 days
Three controllers and a file share were reached in 7 days, on Modbus, EtherNet/IP and SMB. Nothing else crossed.
- Open Policies, then Security
The rulebase list with rule 14 highlighted.
- Add l35-ops-eng above rule 14
Destination ops-a-01, application ms-rdp.
- Add l35-cell-a-drop below it
Action deny, log at session end.
- Disable rule 14 and commit
The commit dialog with the change summary.
Each step shows a screenshot from the firewall's own web console.
Try it: switch the view, hover a flow, open the tabs. An illustrative change, not from the Northline sample.
Try it: switch the view, hover a flow, open the tabs, decide. An illustrative change, not from the Northline sample.
Try it: switch the view, hover a flow, open the tabs. An illustrative change, not from the Northline sample.
Reads exports from
- Palo Alto NetworksPAN-OS, Panorama
- FortinetFortiGate
- CiscoASA, Firepower (FTD)
- Check PointR81.10 to R82
Maps evidence to
- IEC 62443-3-3
- NIST CSF 2.0
- NERC CIP
- NIS2
- CMMC Level 2
- ISO/IEC 27001
More assessments, same team.
Analysis and write-up are the slow part of a segmentation assessment. SegAudit does both from the client's firewall config and traffic log, so your consultants spend their days on judgment.
Chasing evidence
The client's engineer isn't sure what to export, the first files cover the wrong week, and a day goes on email before analysis starts.
The evidence request gives their engineer copy-paste export steps, with their device names filled in.
Analysis in spreadsheets
Mapping zones and matching sessions to rules by hand is slow and hard for a second consultant to check.
Every crossing ranked by risk, with its sessions and rule, in one queue a second consultant can check.
Writing it up
Report, change package, brief and follow-on proposal, each written from scratch under deadline.
The brief, report, change package, roadmap and proposal come out together, in Word under your firm's template.
An engagement, start to handoff
It runs on your workstation or a client jump host, and never connects to their firewall.
- 1
Send the evidence request
Pick the firewall and the traffic window. SegAudit writes the export steps for the client's engineer.
Evidence5 of 5nl-edge-fw01 running config
sha256 a41f…✓nl-core-fw02 running config
sha256 77c0…✓nl-cell-fw03 running config
sha256 0be9…✓traffic 2026-09-21 to 2026-09-28
sha256 9f3c…✓FortiAnalyzer export
sha256 c2d1…✓The evidence screen as the client's files land.
- 2
Triage the findings
Violations ranked by risk, each with an owner, a ticket and your own wording where you disagree.
Violations31, ranked by riskL3.5 → L1 jump-hosts2,792L4 → L2 RDP418L4 → L1 ICMP12L2 → L1 cell-b telnet/smb1,031L5 → L3.5 vendor96L3 → L3.5 historian ftp5,140L3 → L1 telnet0Violations, ranked by risk.
- 3
Build the change package
Each change with firewall syntax, web steps and a rollback the client's engineer can follow.
The change package for one rule.
- 4
Deliver under your letterhead
One zip with the brief, report, change package, roadmap, proposal and crosswalk.
lakeshore-q4-acme.zip7 filesExecutive brief.docxAudit report.docxChange package.docxRoadmap and proposal.docxReadout.pptxFindings workbook.xlsxCompliance crosswalk.docxThe handoff zip, under your template.
What you hand the client
Every deliverable comes from the same evidence, so the brief, report and proposal always agree.
Executive brief
One printable page per site, or seven readout slides for the meeting.
Open sampleAudit report
Findings, scope notes and chain of custody with the source SHA-256s.
Open sampleChange package
Least-privilege exceptions and logged drops, each with CLI, web steps, verification and rollback.
Open sampleCompliance crosswalk
Supported, partial or gap for the frameworks the client answers to.
Open sampleYour firm, on every engagement
Set it once. Every consultant quotes and delivers from the same card.
- Firm profile
- Name, lead consultant, logo, default frameworks, rate card and proposal terms. Set once, shared as a firm file.
- Word under your template
- Every document exports as .docx in Word's own styles, so your firm's template restyles it.
- Your judgment stays visible
- Observations and reworded findings are printed as yours, with the reason.
- Client data locked down
- Encrypt the saved engagement with a passphrase, and hand over a password-protected zip.
OT
ADVISORY
- Firm
- Acme OT Advisory
- Lead consultant
- Dana Patel
- Template
- Acme report.dotx
- Default frameworks
- IEC 62443-3-3, NIST CSF 2.0
- Rate card
- 4 roles, used by every roadmap
- Proposal terms
- Net 30, acceptance on verification
Know your segmentation holds, every quarter.
Run SegAudit on a jump host inside your network. It reads your firewall config and traffic log, shows which paths into OT are really in use, and proposes a change window for them, each change with a rollback.
Rules drift between audits
Allows added during an outage or a vendor visit stay open. A rulebase review alone can't tell which ones still carry traffic.
Every rule that touches OT shows its hits and last hit, so rules the traffic log never shows in use stand out.
Nobody wants to cut production
Without the sessions behind each rule, a drop is a guess, so risky allows survive another year.
Each change keeps the flows production uses, and is checked so it doesn't stop them.
Audits take weeks of spreadsheets
Exporting, mapping zones and writing up findings by hand means the review happens once a year, if that.
The analysis and write-up come straight from the exported files, so the periodic review takes an afternoon.
A quarter with SegAudit
The same steps every quarter, so the review is routine, not a project.
- 1
Export the files
An engineer exports the config and a traffic log from the site. SegAudit never connects to the firewall.
Evidence5 of 5nl-edge-fw01 running config
sha256 a41f…✓nl-core-fw02 running config
sha256 77c0…✓nl-cell-fw03 running config
sha256 0be9…✓traffic 2026-09-21 to 2026-09-28
sha256 9f3c…✓FortiAnalyzer export
sha256 c2d1…✓The evidence screen as each file lands.
- 2
See what is really open
Every session on a path that skips an adjacent Purdue level, or carries an application you restrict on that hop, ranked by risk, with the rule that allowed it.
Violations31, ranked by riskL3.5 → L1 jump-hosts2,792L4 → L2 RDP418L4 → L1 ICMP12L2 → L1 cell-b telnet/smb1,031L5 → L3.5 vendor96L3 → L3.5 historian ftp5,140L3 → L1 telnet0Violations, ranked by risk.
- 3
Change through your CAB
Each change carries CLI, web steps, rollback and a ticket, written for the manager you already run.
The change window, ready for your CAB.
- 4
Prove it worked
Drop in the next traffic log. Every change comes back Verified, Regressed, Not applied or No traffic, and the quarter is saved.
Verifytraffic 2026-10-05 to 2026-10-12CHG-03VerifiedCHG-05VerifiedCHG-06Not appliedCHG-07VerifiedCHG-08RegressedCHG-10No trafficVerification against the next traffic log.
Built for the whole asset owner team
Unlimited internal users, so everyone works from the same findings.
OT and controls engineers
See which sessions cross into Level 2 and below, and what a change would break before anyone touches a rule.
Network and firewall team
Change windows with CLI, rollback and a CAB ticket, for the Panorama, FortiGate, ASA, FMC or Check Point manager you run.
Site and OT security leads
Track maturity, attack paths and open issues per site, and run the periodic rule review in an afternoon.
CISO and site management
A one-page brief each quarter: where each site stands, what changed, and what is still open.
What you get
Every site, tracked across quarters, with the evidence your policy review asks for.
- Quarterly checkpoints
- Maturity tier per site, live attack paths, open issues and program remaining, compared quarter over quarter.
- Periodic rule review
- Every rule that touches OT with its hits, last hit and a keep, narrow, remove or recertify recommendation, plus a sign-off sheet.
- Multi-site aware
- Plans per site across a multi-site estate, pilot site first.
- Signed review log
- Approve, Hold or Accept the risk on each change. Who decided and when is signed into a log you can show an auditor.
- Compliance evidence
- IEC 62443-3-3, NIST CSF 2.0, CMMC Level 2, ISO/IEC 27001 and NIS2 marked supported, partial or gap.
| Site | Q1 | Q2 | Q3 | Q4 |
|---|---|---|---|---|
| Lakeview | 14 | 9 | 6 | 3 |
| Riverside | 8 | 7 | 4 | 2 |
| Kenosha | 21 | 16 | 9 | 5 |
| Rule | Hits, 30 days | Last hit | Recommendation |
|---|---|---|---|
| 14 dmz-to-cell-any | 11,966 | 2026-10-10 | Retired by CHG-07 |
| 9 legacy-telnet | 0 | Never | Remove |
| 22 vendor-vpn-l2 | 0 | 2026-08-19 | Recertify |
| 31 hist-repl | 5,140 | 2026-10-10 | Narrow |
What a hits-only review misses
A rule with zero hits is often shadowed, not idle. Tighten the wrong rule first and the unused one underneath becomes the new path into OT.
| What it catches | What it is | Illustrative example | Backed by |
|---|---|---|---|
| Observed violations | Paths that cut across the segmentation and zone-boundary themes of IEC 62443-3-3 (SR 5.1, 5.2), shown by real sessions. | Jump host reached plc-a-01 on Modbus, 1,284 sessions | Logged sessions |
| Latent exposure | Rules that permit a bypass nobody has used yet, kept separate from live traffic. | Rule 22 lets vendor VPN reach Level 2. No sessions yet. | Rulebase, no traffic yet |
| Priority traps | Caught before a change opens a new path. | Rule 9: zero hits, shadowed by rule 4 | Rulebase and traffic |
| Change package | Firewall commands or console steps, pre-checks, verification and rollback for every change. | CHG-07: the Level 1 path dropped; the jump hosts keep RDP into Level 3 | Every finding above |
From two exported files to a fix your team can apply.
Every screen here is the real app, running the built-in Northline sample.
Load the config and traffic log
Exports you already have. Nothing connects to the firewall.

See every crossing, ranked
Violations ranked by risk, each with the sessions and rule behind it.

Get the change package
Rule changes in the firewall's own syntax, with web steps and a rollback for each.

Verify with the next log
The next traffic window confirms each change did what it said.

Documents a change board can sign.
Every audit exports the same set, in Word and markdown, ready to forward.
- Executive brief1 page per site
- Audit reportWord, markdown
- Change packageper device group
- Compliance crosswalk10 frameworks
- Maturity by siteAsset Owner edition




Built for the most restricted networks.
Your files stay on your workstation or jump host. The trust center shows the data flow, how each release is signed, and how to verify it.
- No AI in the analysis
- Every finding comes from the configuration and traffic log you load.
- No outbound connections
- Updates and renewals are links you choose to open.
- No firewall access
- SegAudit reads exported files and pushes nothing.
- Signed releases
- Verify each release before it runs.
Common questions
- Can I pick the engagement up next quarter?
- Yes. Save the engagement as a file, encrypted if you like, and load next quarter's config and log into it. Checkpoints, observations, rate card and letterhead carry over. Progress shows what moved.
- Can I edit the deliverables?
- Yes. Every document exports as markdown and as a Word .docx that takes your firm's template. Findings, tickets and inventories export as CSV.
- Who runs it day to day?
- Usually the firewall or OT security engineer. Unlimited internal users are included, so controls engineers and auditors can review the same findings.
- Can we start without buying?
- Yes. The free Quick check reads one of your firewall configs in your browser today, and the Northline sample deliverable shows the full report. The free 30-day Asset Owner edition trial (every audit feature, your own sites' files, no call, no card) opens again soon.
- Does it connect to the firewall?
- No. SegAudit only reads exported files. It has no firewall API access and pushes nothing.
- Which firewalls does it support?
- Palo Alto Networks Panorama and standalone PAN-OS firewalls, Fortinet FortiGate with FortiAnalyzer, Cisco ASA (ASA 9.x, including ISA 3000 and ASA 5500-X), Cisco FTD managed by FMC 7.4, and Check Point R81.10 to R82 with a Security Management Server. See firewall support for details.
- Where does my data go?Where does my data go?Where does my client's data go?
- Nowhere. Analysis runs in the browser on your workstation or jump host, with no upload and no telemetry. The data flow page shows the proof.
- Is it a certification?
- No. SegAudit produces evidence and a crosswalk for your assessor. It does not certify against IEC 62443 or any other framework.No. SegAudit produces evidence and a crosswalk for your assessor. It does not certify against IEC 62443 or any other framework.No. SegAudit produces the evidence and a crosswalk your client can hand their assessor. It does not certify against IEC 62443 or any other framework.
Try it on your next engagement
New 30-day Professional trials are paused for now and open again soon. Until then, the Quick check and the Northline sample deliverable are open to everyone.
Try it on one of your sites
New 30-day Asset Owner edition trials are paused for now and open again soon. You can pay by purchase order when you buy. Until then, the Quick check reads one of your configs in your browser, and the Northline sample deliverable shows the full report.
Fix the seg fault before an attacker does.
The free Quick check reads one of your firewall configs in your browser and shows the paths it leaves open. New 30-day trials are paused for now and open again soon.