Network & Security Monitoring · 3 min self-assessment
Is your utility covered?
A quick, honest read on your monitoring and resilience posture. Answer 15 questions to see where you stand, plus the gaps worth closing first.
Start your assessment
Tell us who you are. We'll email a copy of your results to you and our team, and you can start right away.
Your readiness
-
Not started
0 of 15 answered
Your answers stay in your browser as you go.
1
Architecture & Segmentation
Your IT and OT/SCADA networks are segmented, with traffic between them tightly controlled.
Your OT/SCADA systems have no direct internet exposure. External access passes through a monitored boundary such as a firewall and DMZ.
2
Access & Credentials
Access to control systems is least-privilege, limited to only the users, devices, and functions that need it.
Business and control systems use separate credentials, with no shared or reused accounts, and MFA is in use.
Your staff receive security awareness training, since phishing and stolen passwords are common ways in.
3
Network Monitoring
A dedicated network monitoring platform is deployed and regularly polling your critical devices.
You get automated alerts when devices go offline, links degrade, or hardware starts to fail.
You have a baseline of normal activity, so capacity strain and anomalies are caught before an outage.
4
Security Monitoring (SIEM)
Logs from workstations, servers, firewalls, and cloud services are collected centrally in a SIEM.
You receive alerts on suspicious activity such as failed logins, unusual locations, malware, and configuration changes.
Both your IT and your OT environments are monitored, not just one of the two.
5
Response & Recovery
You have an incident response plan, and you know who acts when an alert fires, with 24/7 coverage from staff or a partner.
Systems and devices are patched and updated on a regular, tracked schedule.
You keep regular, tested backups, ideally with an offline or immutable copy, so you can recover without paying a ransom.
Monitoring and log data is retained for compliance and audit needs such as NERC CIP, and for post-incident forensics.
Your result
-
Not started
0 of 15 answered
Answer the questions above to see where your utility stands and which gaps to close first.
Where to start: your top gaps
No open gaps, strong work. The next move is keeping it that way: test your alerts, review access quarterly, and rehearse your incident response.