Large-Scale Facility Establishes Authoritative OT Network Baseline

Cast Study

A U.S.-based LNG production and export operator engaged Armexa to document and validate its OT network environment in preparation for formal cybersecurity risk assessment. The facility’s complex, multi-train environment had grown without systematic documentation, leaving asset inventories unreconciled, cross-zone communications uncharacterized, and legacy infrastructure untracked. Armexa delivered an authoritative “as-is” network baseline, including validated asset inventories, logical diagrams, and quantified cross-zone data flows. All providing the technical foundation needed to manage OT cyber risk with confidence. 

Challenges 

A complex OT environment where documentation, inventory, and segmentation integrity were all in question 

The operator’s multi-train LNG OT environment lacked the documentation and validated baseline needed to support effective OT cyber risk management or a formal risk assessment.  

Key challenges included: 

  • OT network documentation incomplete, outdated, or inconsistent across systems and operating areas 
  • Asset inventories never reconciled against live traffic or configuration data, leaving actual network composition unconfirmed 
  • Unidentified devices observed communicating across security zones, with segmentation effectiveness not quantified 
  • End-of-support network hardware and firmware present within critical OT zones, without a clear lifecycle plan 
  • No trusted technical baseline from which to plan remediation, assessments, or program investment 

Our Solution 

A structured baseline initiative combining on-site data collection, configuration analysis, and passive traffic analysis 

Armexa executed a two-workstream baseline engagement designed to document the current-state environment and prepare the organization for formal risk assessment: 

  • OT “As-Is” Network Documentation: Reviewed existing drawings and configuration files; extracted switch, firewall, and endpoint data on-site; performed passive PCAP analysis to validate observed network behavior against design documentation. Produced authoritative Layer 2/Layer 3 network diagrams and a validated asset inventory. 
  • OT Data Flow Analysis: Quantified unicast communications crossing security zone boundaries; mapped zone-to-zone conduits; validated segmentation against observed traffic rather than design intent alone, exposing gaps between documented architecture and operational reality. 

Outcomes & Impact 

A trusted technical baseline enabling risk assessment, remediation planning, and long-term program maturity 

The engagement delivered a defensible, evidence-based foundation for the operator’s OT cybersecurity program: 

  • Authoritative OT network diagrams and validated asset inventories directly tied to observed network behavior, an important step in replacing undocumented assumptions with confirmed fact 
  • Discovered undocumented cross-zone communications and previously unknown devices, enabling targeted remediation of segmentation gaps 
  • Identified legacy infrastructure requiring lifecycle planning before it created unmanaged risk exposure 
  • Established a strong technical foundation for subsequent risk assessments, remediation planning, and compliance documentation under USCG, TSA, and ISA/IEC 62443 requirements 
Facebook
X
LinkedIn
Industry  Energy: LNG Production & Export 
Location  United States 
Environment  Multi-train LNG facility 
Standards  ISA/IEC 62443 

USCG NVIC 01-20 / 33 CFR Part 101 

TSA Security Directives 

Services  OT Network Documentation 

Asset Inventory Validation 

Passive PCAP Analysis 

OT Data Flow Analysis 

Zone-to-Zone Segmentation Validation 

Network Diagramming 

Latest Posts

Skip to content