Book a consultation

Delivery Governance

OT Network Assessment for Manufacturing Plants

A fixed-scope review of your plant network with named deliverables, built for brownfield sites where the line has to keep running.

Most plants do not know exactly what is on their network until something on it fails. Joltek provides a fixed-scope OT network assessment for manufacturing plants: we document the industrial network as it actually is, find what is threatening uptime, design segmentation that fits a running brownfield site and hand you a prioritized plan to fix it, without selling you the hardware.

Proof. At Joltek, we stabilized a packaging line where three OEM machines on Omron control fed a Rockwell cartoner, each machine behind its own address-translation appliance on a private subnet with no direct path between controllers. We mapped that topology and designed the controller-to-controller exchange across two translation boundaries, proving each path reachable before writing any logic (case study). Before founding Joltek, Vladimir Romanov led the process control and information systems scope for three new production lines at P&G Auburn, including the Stratix switch configuration that tied each line into the site’s SCADA and MES backbone (case study).

For the background, see our guides to industrial Ethernet reliability, unmanaged switches and cybersecurity, what a modern plant network requires, OT networks, Stratix switching and segmentation and DeviceNet. If the network is one part of a wider question, see IT/OT integration or a full plant systems assessment.

Why it matters

What this costs when it is left alone

The reasons this work gets deferred are usually the reasons it gets expensive.

Nobody has the current drawing

Most plant networks grew one machine at a time. The last accurate diagram predates three expansions, and the people who knew where the cables go have moved on. You cannot secure or extend what you cannot see.

Network faults look like control faults

A broadcast storm, a duplicate IP or a looped unmanaged switch shows up as dropped I/O connections, frozen HMIs and nuisance stops. Teams chase the PLC for weeks when the cause sits one layer down.

Flat networks fail all at once

When every device shares one broadcast domain, one bad port or one infected laptop can reach the whole floor. Segmentation contains the damage to one zone instead of the whole plant.

New projects inherit the mess

MES, historians, remote access and new lines all land on the existing network. Without a baseline, every project rediscovers the same problems and pays to work around them again.

Our approach

How the work runs

We run the assessment in four steps with a fixed scope agreed up front. Reliability comes first, because a network that drops the line is a bigger risk on most days than an attacker. Security follows from the same picture.

01

Walk down and inventory

  • Cabinets, switches, media converters and cable runs traced on the floor
  • Device inventory with IP and MAC addresses, firmware and location
  • Legacy islands such as DH+ and DeviceNet recorded with their gateways
02

Observe and measure

  • Passive capture and switch diagnostics, with no changes to running equipment
  • Broadcast and multicast load, port errors, duplicate IPs and loops
  • Unmanaged switches, NAT boundaries and undocumented paths flagged
03

Analyze and design

  • Current-state physical and logical diagrams
  • Zones and conduits drawn in the spirit of ISA/IEC 62443
  • Risk register ranked by impact on production and exposure
04

Plan the remediation

  • Prioritized fixes from quick wins to capital projects
  • Load validation where a change could affect real-time traffic
  • Vendor-neutral scope your integrator or IT team can quote against

What we deliver

What you end up holding

  • Current-state network diagram, physical and logical
  • Asset and device inventory with IP and MAC addresses, firmware and location
  • Traffic and health findings: broadcast storms, unmanaged switches, duplicate IPs, NAT and legacy network islands
  • Segmentation plan with zones and conduits, aligned with ISA/IEC 62443 concepts
  • Risk register ranked by production impact and exposure
  • Prioritized remediation plan, with load validation where needed

Who we support

Who this is for

Engineering and maintenance managers
who are losing hours to intermittent communication faults and need the cause found and documented, not guessed.
IT and security leaders
who have been asked to secure the plant floor and need an accurate picture of it before they touch anything.
Plant leaders planning new systems
who are about to add MES, remote access or a new line and want the network ready for it instead of discovered during commissioning.

Why Joltek

What you are actually buying

Vendor-neutral

We do not resell switches, firewalls or monitoring tools. The remediation plan recommends what the plant needs, including reusing hardware you already own.

Controls people, not only network people

We read the PLC and HMI side as well as the switch side, so we can tell a network fault from a controller fault and design segmentation that keeps the I/O running.

Brownfield by default

Our plans assume the line keeps running, legacy networks stay for now and the budget comes in phases. Every recommendation has a sequence and a reason.

Questions

Answered before you ask

What is an OT network assessment?

An OT network assessment is a structured review of the network that connects your PLCs, drives, HMIs and supervisory systems. It documents what is connected and how, finds the conditions that threaten uptime and security, and ends with a segmentation plan and a prioritized list of fixes the plant can fund and schedule.

Will the assessment disrupt production?

No. We work from walk-downs, switch diagnostics and passive traffic capture, and we do not change configurations on running equipment. Where a mirror port or temporary tap is needed, we install it with your team during a window you choose.

Do you need IT involved?

Yes, and early. IT usually owns the firewalls, the plant-to-business boundary and remote access. We work with both teams so the segmentation plan reflects how the plant actually runs and what IT can support.

Is this a cybersecurity audit?

Not in the formal sense. We use ISA/IEC 62443 concepts such as zones and conduits to structure the segmentation plan, but this is not a certification or a formal 62443 risk assessment. It gives you the accurate baseline that a formal security program needs to start from.

Our network mixes EtherNet/IP with DH+ and DeviceNet. Is that a problem?

It is common. We inventory the legacy islands and their gateways, assess the risk they carry and fold their retirement into the remediation plan so they move with your controller migrations rather than separately.

Do you travel to US plants?

Yes. We are based in Laval, near Montréal, and work with plants across Canada and the United States. The walk-down is on site; analysis and reporting are done remotely.

What happens after the assessment?

You own the deliverables and can take them to any integrator or IT provider. If you want us involved, we can write the remediation scope, review the designs and witness the changes on your side of the table.

Have a project that needs technical ownership?

Send us the situation. If it is not something we should take on, we will say so.