ICS/OT Security

Firewall Audits in Oil & Gas: What Auditors Miss and How to Fix It

By August 12, 2026No Comments

Firewall audits in industrial environments—particularly in oil and gas operations—often miss critical vulnerabilities that could expose operational technology (OT) systems to cyber threats. Unlike IT networks, OT environments are mission-critical, with systems that must operate continuously while managing complex industrial protocols like Modbus, DNP3, and OPC UA. Auditors frequently apply IT-centric frameworks without accounting for the unique constraints of OT networks, leading to gaps in coverage. This blog explores what auditors miss in OT firewall assessments and how to address these risks effectively.

The Hidden Complexity of OT Firewalls

OT firewalls are not just passive barriers—they are integral to maintaining the availability, safety, and integrity of industrial processes. However, auditors often overlook the intricacies of OT environments, which are governed by standards like IEC 62443 and NERC CIP. For instance, many OT systems rely on legacy protocols and devices that lack modern security features, such as encryption or authentication mechanisms. Source 5 highlights key differences between OT and IT, emphasizing that OT systems prioritize operational continuity over data protection, and changes to these systems often require extensive validation to avoid production disruptions.

Consider a typical oil and gas facility using Rockwell or Siemens controllers. These systems may communicate over Modbus TCP or DNP3, protocols that are not well understood by auditors trained in IT environments. A firewall rule that blocks a specific port used for Modbus communication could inadvertently disrupt critical control loops, leading to safety or operational issues. Auditors must be protocol-aware, as noted in Source 2, which stresses that OT monitoring requires understanding industrial protocols, low-bandwidth links, and segmented architectures.

Common Gaps in Firewall Audits

One of the most significant gaps in OT firewall audits is the lack of comprehensive asset inventory and configuration management. Source 3 emphasizes that asset inventory is a core monitoring function, yet many industrial operators struggle with incomplete network diagrams, outdated documentation, and unclear ownership between IT and OT teams. This lack of visibility can lead to misconfigured firewalls that fail to protect against threats targeting specific devices or protocols.

For example, an auditor might review firewall rules without knowing that a Schneider PLC is running firmware version 1.2, which has known vulnerabilities. Without this context, the auditor cannot assess whether the firewall rules adequately block exploits targeting that specific firmware. Similarly, legacy systems from vendors like Honeywell or ABB may not support modern firewall features, such as deep packet inspection, further complicating the audit process.

Another gap is the failure to account for behavioral baselines in OT networks. Source 3 notes that anomaly detection in OT environments must distinguish between normal operational variations and suspicious activity. A firewall audit that focuses solely on rule compliance may miss subtle changes in communication patterns that indicate a compromise, such as a sudden increase in DNP3 traffic from a normally idle device.

Beyond Rules: Understanding OT Network Behavior

Effective OT firewall audits require more than checking rule sets—they must align with the operational context of the network. This includes understanding the mission-critical nature of OT systems, as outlined in Source 5, where availability and safety are paramount. For instance, a firewall audit at a refinery might overlook the fact that a specific segment of the network is air-gapped, making traditional IT-based testing methods like scanning or pinging unsafe and potentially disruptive.

Consider the case of a Siemens S7-1200 PLC communicating with a SCADA system over OPC UA. A firewall rule that blocks certain OPC UA commands could prevent the PLC from updating its control logic, leading to operational failures. Auditors must collaborate with OT engineers to ensure that firewall policies do not interfere with legitimate operational activities, as emphasized in Source 4, which highlights the risks of testing that could disrupt production.

Furthermore, Source 3 underscores the importance of behavioral baselines. An OT firewall audit should include monitoring tools that establish normal communication patterns for devices and protocols. For example, if a Rockwell controller typically communicates with three devices every hour, a sudden drop to zero communications might indicate a compromise. Auditors must integrate this behavioral data into their assessments to avoid missing subtle threats.

Case Study: A Missed Vulnerability in a Refinery

A recent audit at a major oil refinery revealed that the OT firewall had not been updated in over two years. The auditor found that the rule set allowed unencrypted Modbus traffic between legacy devices, a violation of IEC 62443 requirements. However, the audit report did not address the operational impact of blocking this traffic, as the refinery’s engineers relied on it for real-time control. This highlights the need for auditors to balance compliance with operational continuity, as outlined in Source 3.

Human Context and Operational Knowledge

One of the most overlooked aspects of OT firewall audits is the need for human context. Source 3 explicitly states that reducing false positives requires OT analysts to understand operations well enough to differentiate between malicious activity and legitimate maintenance or commissioning work. An auditor without this context might flag a routine firmware update on a Honeywell system as a security incident, causing unnecessary disruption.

To address this, auditors should work closely with OT teams to map normal operational activities to firewall rules. For example, during a planned maintenance window, engineers might temporarily allow traffic from a third-party vendor’s device. The auditor must ensure that these exceptions are documented and time-bound, as recommended in Source 4, which emphasizes the importance of clear ownership and communication between IT and OT teams.

Compliance and the Need for Comprehensive Audits

Firewall audits in OT environments must also align with compliance frameworks like NERC CIP, IEC 62443, and NIS2. Source 3 notes that monitoring supports compliance through logging, evidence collection, and reporting. However, many audits fail to capture the full scope of these requirements. For instance, an audit might check whether firewalls are configured according to NIST SP 800-82 but overlook the need for continuous monitoring of OT network traffic for anomalies.

Another compliance challenge is the presence of third-party remote access, as noted in Source 4. Many OT systems allow remote access for maintenance, but these connections are often inadequately secured. An effective firewall audit should assess whether remote access is limited to specific, authenticated users and whether traffic is encrypted using protocols like TLS 1.2 or higher.

Best Practices for Effective OT Firewall Audits

To ensure comprehensive coverage, OT firewall audits should include the following steps:

  • Conduct an asset inventory to identify all OT devices, their firmware versions, and communication protocols.
  • Review firewall rules with OT engineers to ensure they align with operational requirements.
  • Implement behavioral baselines for OT network traffic to detect anomalies.
  • Ensure compliance with standards like IEC 62443, NERC CIP, and NIST SP 800-82.
  • Document and validate exceptions to firewall rules, such as temporary access for maintenance.

By following these steps, auditors can avoid the common pitfalls that leave OT systems vulnerable to cyber threats.

Conclusion

Firewall audits in OT environments are far more complex than their IT counterparts. They require a deep understanding of industrial protocols, operational context, and compliance requirements. Auditors who fail to account for these factors risk missing critical vulnerabilities that could compromise the safety and integrity of industrial systems.

At Red Trident, we specialize in OT cybersecurity assessments that align with the unique needs of industrial operators. Our approach ensures that firewall audits are both thorough and operationally sound, avoiding disruptions while meeting regulatory requirements.

CTA: Get a Free OT Security Assessment Consultation

Don’t let hidden vulnerabilities in your OT firewall go unnoticed. Contact Red Trident today for a free OT security assessment consultation. Our experts will help you identify gaps in your current firewall configuration, align with industry standards, and ensure operational continuity. Schedule your consultation now and take the first step toward securing your critical infrastructure.

author avatar
Emmett Moore