// service · Assessments

Where IT/OT boundary risk sits this week

Passive capture of real IT/OT traffic for two to four weeks. Modbus, EtherNet/IP, OPC UA, and S7. Findings ranked under the QUICK framework.

Resilion Effectiveness Score Grid listing control IDs, site names, maturity scores, and effectiveness status.
Resilion · control effectiveness by site · demo data

Most IT/OT boundary assessments are theoretical. A consultant reads the firewall ruleset and writes a paragraph about least privilege. Nobody captures what crosses the boundary on a Tuesday at 1400, indirect threats from ERP, MES, or HR never get scored, and the deliverable is a stack of recommendations the plant has heard before.

RiskSpan runs the assessment on real traffic. Passive sensors and exported firewall logs capture two to four weeks of boundary activity, no taps in production paths, no active probing. We decode flows across Modbus, EtherNet/IP, OPC UA, S7, and proprietary stacks, map them to business services, and trace indirect threat paths back into OT impact.

Every finding is ranked under the QUICK framework: quality, uptime, information integrity, compliance, and key deliverables, so leadership knows what to act on first, not just what is theoretically possible.

// FAQ

Questions about RiskSpan IT/OT boundary assessment

What is RiskSpan?
RiskSpan is Hillstrong’s IT/OT boundary risk assessment run on real traffic. Passive sensors and firewall logs capture what actually crosses the boundary over two to four weeks; flows are decoded and mapped to business services, and findings are ranked under the QUICK framework, quality, uptime, information integrity, compliance, and key deliverables.
Is it safe to run in production?
Yes. RiskSpan is fully passive, sensors sit on SPAN ports and firewall log exports, with no taps in production paths and no active probing.
How is it different from a firewall ruleset review?
A ruleset review is theoretical; it never captures what crosses the boundary at 1400 on a Tuesday. RiskSpan measures real communication, surfaces indirect threats from ERP, MES, and HR systems, and ties each to the operation it puts at risk.

See this work on your sites

Book a 30-minute demo. Bring the last assessment and the sites in the first wave.