Your IT auditor has never seen a PLC. Your insurer, your regulator, and your board no longer accept that.
We audit SCADA, ICS, and building systems against NIST SP 800-82 Rev 3 without touching production: passive methods only, every tool approved by your engineers first, findings ranked by safety and downtime consequence.
Led personally by the consultant who has advised the Nuclear Power Plant of the United Arab Emirates.

The Three Reasons Plants Call Us
Nobody audits their OT for fun. One of these three is usually on fire.
Your cyber insurance renewal is asking OT questions you cannot answer
Underwriters now ask about OT segmentation, MFA on vendor remote access, and tested backups of PLC logic. A wrong answer risks claim denial. A truthful answer risks a surcharge or an OT exclusion. An SP 800-82 audit gives you defensible answers before the renewal date.
A regulator or customer gave you a deadline
TSA Security Directives require annual pipeline cybersecurity assessments. EPA and AWIA recertification waves are hitting water systems through 2026. NERC CIP-003-9 became enforceable in April 2026. NIS2 enforcement started across the EU. Large customers exercise right-to-audit clauses. All of them accept an audit mapped to NIST SP 800-82.
The board asked: could Clorox happen to us?
Clorox lost around $356 million to a help-desk social engineering attack that halted production. MKS Instruments lost about $200 million in one quarter, and its customer Applied Materials warned of a $250 million ripple. When the board asks whether your plants are exposed, only an audit produces a real answer.

What Is NIST SP 800-82?
NIST SP 800-82 Revision 3, the Guide to Operational Technology Security, is the US government's reference for securing the systems that touch the physical world. Published September 28, 2023, the 316-page guide superseded the old Industrial Control Systems edition and widened its scope: OT now explicitly covers SCADA, distributed control systems, PLC-based topologies, building automation, physical access control, environment monitoring, safety systems, and Industrial IoT.
Its core engineering insight is that OT is not IT. Rebooting is often unacceptable. Outages are planned weeks ahead. Human safety outranks confidentiality. A security measure that impairs a safety function is, in the standard's own framing, unacceptable. Auditing OT with IT tools and IT assumptions produces broken production lines and useless findings.
The heart of an audit is Appendix F: a formal OT overlay that tailors NIST SP 800-53 Rev 5 controls across 19 families at low, moderate, and high impact. That overlay, plus the Purdue-model segmentation architecture of Section 5, is the yardstick we audit against. It is guidance rather than law, but TSA directives, EPA water requirements, NERC CIP expectations, cyber insurers, and enterprise customers all accept it as the standard of evidence.


Where the Audit Looks: Every Purdue Level
From the enterprise network down to the sensors and valves, an SP 800-82 audit verifies segmentation, boundary protection, and controls at every level, with special attention to the DMZ, the dual-homed workstations that defeat it, and the safety layer attackers now target directly.

In Scope: All Six OT System Families
SCADA systems
Supervisory control across pipelines, grids, and water networks
DCS
Distributed control systems running process plants
PLC-based topologies
The controllers running your lines, skids, and machines
Building automation
HVAC, elevators, power, and access in commercial buildings and data centers
Safety systems
Safety instrumented systems that keep processes from killing people
IIoT and monitoring
Industrial IoT sensors and physical environment monitoring
What We Audit, Area by Area
Ten areas, mapped to the structure of SP 800-82 Rev 3 itself. Each finding lands against a specific overlay control, so your remediation roadmap doubles as compliance evidence.
Do you actually know every PLC, HMI, historian, drive, and safety controller you run, what firmware is on them, and which physical process each one touches? Roughly a third of operators have no centralized OT inventory at all.
Defense-in-depth across the Purdue levels, a real DMZ between IT and OT, firewall rules between zones, and no path from the internet to a controller. One dual-homed engineering workstation defeats all of it, which is exactly how the 2016 Kyiv grid attack got in.
SP 800-82 Rev 3 tailors NIST SP 800-53 Rev 5 across 19 control families at low, moderate, and high impact. We verify each applicable control, document justified deviations, and map compensating controls where the overlay expects them.
Every OEM VPN, TeamViewer install, and cellular modem inventoried, with MFA, jump hosts, session logging, and least privilege. About half of OT incidents originate from external remote access. We find the links you do not know about.
A patch process that acknowledges reality: outages planned weeks ahead, OEM certification limits, machines that cannot reboot. Where patching is infeasible, we verify compensating controls instead of writing "patch everything" like an IT auditor would.
Passive OT network monitoring, log collection from devices that can log, and compensations for the ones that cannot. Only about 13 percent of operators report full visibility across the ICS kill chain.
An IR capability that prioritizes safe process state over forensics, tested backups of PLC logic and HMI configurations, and the ability to run in manual mode. Norsk Hydro survived LockerGoga on pen and paper because it could.
Safety instrumented systems assessed separately and verified independent from basic process control, so one compromise cannot defeat both layers. Triton proved attackers target the safety layer itself.
The security of the vendors, system integrators, and software update channels that reach your OT. NotPetya entered through a trojanized vendor update and cost Merck $1.4 billion.
A named owner for OT security, OT-specific policies distinct from IT policy, and training for the engineers who actually operate the systems, so audit findings do not fall into the gap between the CISO and the plant.
The Question Every Plant Asks First: Will You Break Something?
Every OT engineer has a war story about a vulnerability scan that tripped a line. It is the single biggest reason plants refuse security assessments, and the fear is justified: legacy controllers are known to hang under unexpected traffic.
So our answer is structural, not reassuring words. We never run active IT-grade scans against live controllers. The audit is built from passive network captures, offline configuration reviews, physical walkthroughs, and interviews. Your engineers review and approve every tool and every method before anything connects to your network, and a written stop-work and rollback plan is agreed before fieldwork begins.
We also coordinate with your system integrator and OEM support channels so nothing we do jeopardizes a support contract or warranty.


Trusted Where Failure Is Not an Option
There is one environment where OT security has no margin for error, no tolerance for consultants learning on the job, and no patience for IT-grade methods: a nuclear power plant. Atlant Security's founder has consulted for the Nuclear Power Plant of the United Arab Emirates.
That work sits on top of 200+ security assessments across 14 countries since 2013, a Microsoft Security Consulting background, and a CISSP. When we say the same person who carries that experience walks your plant floor, interviews your engineers, and writes your report, that is the entire delivery model. No leverage pyramid, no juniors, no handoffs.
The OEMs will audit you to sell you their platform. The Big-4 will send people who have never seen a safety instrumented system. We have exactly one thing to sell: the audit itself.
Why Plants Choose Atlant Over the OT Establishment
The OT assessment market is enterprise platforms, automation OEMs auditing their own install base, and Big-4 leverage models. Here is the honest comparison.
| Atlant Security | Typical OT Assessment Vendor | |
|---|---|---|
| Who shows up | The founder, who has consulted for the Nuclear Power Plant of the United Arab Emirates, does the fieldwork and writes the report | A partner sells it, juniors with IT backgrounds deliver it |
| Independence | Nothing to sell you afterwards: no sensors, no platform, no managed service | OEMs and platform vendors whose findings map suspiciously well to their own products |
| Pricing | Published, fixed, and scoped before we start | No public pricing anywhere; enterprise minimums and MSA negotiations |
| Method on live systems | Passive captures and config reviews, every tool pre-approved by your engineers, written stop-work plan | IT-grade scanners that legacy PLCs are known to crash under |
| Findings | Ranked by safety and downtime consequence, scoped to what you can fix this year | A CVSS-sorted risk register telling you to patch what cannot be patched |
| Speed | Fieldwork scheduled in weeks, report 2 to 3 weeks after | Months of scheduling, then a four-month wait for the deck |
SP 800-82 Audit Pricing
Almost nobody in OT security publishes prices. We do. Effort drives the price, not the size of the standard: the same 19 overlay control families take radically different work depending on your sites, systems, and vendor connections, and sometimes 10 percent of the controls are 95 percent of the effort. That is why every engagement is scoped and fixed in writing before we start.
Remote OT Gap Assessment
The right start for a first-ever OT assessment or multi-site prioritization. No site visit required.
- Architecture and firewall configuration review
- Purdue segmentation analysis
- Guided passive captures by your team
- Policy and program review against Section 3
- Gap mapping to the Appendix F overlay
- Consequence-ranked remediation roadmap
Zero-risk: you review the report before you pay.
On-Site OT Security Audit
The full SP 800-82 Rev 3 audit, from the control room to the cabinets.
- Everything in the Remote Gap Assessment
- On-site fieldwork with safety inductions and escorts
- Physical security of control rooms and field cabinets
- Vendor and integrator remote access discovery
- Safety system independence verification
- Regulator, insurer, and customer mapping table
- Executive briefing for the board
Zero-risk: you review the report before you pay.
Multiple plants, substations, or a fleet of sites? Multi-site programs are scoped per site with volume pricing. Remediation support and an OT incident response retainer are separate, scoped add-ons.
Who Needs an SP 800-82 Audit?

How the Audit Works: 5 Steps, 2 to 3 Weeks
Scoping and system characterization
We map your sites, systems, and vendor connections, review existing inventories and network diagrams, and agree the exact scope in writing. You approve every tool and method before anything touches your network.
Architecture and segmentation review
Configuration reviews of firewalls, switches, and boundary devices against the Purdue model, plus passive traffic captures from SPAN ports where available. No active scanning of live controllers, ever.
On-site fieldwork
Control room and plant floor walkthroughs with your escorts, safety inductions and PPE, physical security checks of cabinets and field devices, and structured interviews with the engineers who run the process.
Gap analysis against the OT overlay
Every finding mapped to the SP 800-82 Rev 3 Appendix F overlay of NIST SP 800-53 Rev 5, categorized by impact level, with justified deviations documented the way an assessor or regulator expects.
Consequence-ranked roadmap
Findings prioritized by safety, downtime, and product impact rather than raw CVSS scores, with fixes your plant can actually execute given maintenance windows, staffing, and budget. Plus a mapping table for your regulator, insurer, or customer.

Audit the Plant. Keep It Running.
One strategy call. A fixed-price proposal within 24 hours. An audit your regulator, your insurer, and your board all accept, done by the consultant a nuclear power plant trusted, without a single minute of downtime.
Book Your Free OT Strategy Call