OT environment security maturity · Operational technology
Your industrial environments placed on a maturity scale, with a costed trajectory to move them forward.
10 themes, a 5-level scale. And the action that moves each level to the next.
The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.
OT environment security maturity · Operational technology
10 themes, 5-level scale.
Nordhavn Industries
53 / 100
They measure their maturity with Datamensio
An example
This could be your situation.
Take one company as an example: three sites, three spreadsheets, no shared answer.
Nobody can consolidate.
Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.
Three weeks, a single base.
One OT security maturity framework, based on IEC 62443 principles and NIST SP 800-82 assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.
Two costs avoided before being committed.
A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.
What it saved them
- 3sites measured on the same base, instead of three questionnaires to reconcile
- 2duplicate actions caught before the spend
- 1committee report, with no manual rework
These figures are an example. They could be yours.
The standard imposes processes. Datamensio says where you stand.
01
The framework is already written
Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.
02
The score lands the same day
Online, by self-assessment link or in interview. Theme by theme, comparable over time.
03
The gap becomes a costed plan
Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.
04
Progress can be demonstrated
Campaign after campaign, against your target and against your own past. That is what your board asks for.
The maturity scale
One level, the next, and the action that links the two.
This mechanism, a level, a level above, and the action that connects the two, is what turns a finding into a trajectory.
Are suppliers’ remote maintenance accesses controlled and logged?
- N1
No control identified. Remote accesses were set up project by project, with no register and no monitoring.
- N2
The main accesses are known and a rule exists, but its application depends on the site and the supplier concerned.
- N3
Accesses are registered, pass through a controlled entry point and are opened on request for an identified intervention.
- N4
Every session is logged and linked to a named individual, rights are reviewed periodically and unused accesses are closed.
- N5
Sessions are supervised, deviations are escalated to security, and requirements are built into maintenance contracts and checked at every renewal.
Action to move from L2 to L3
Work with maintenance to register all remote accesses site by site, converge them onto a single entry point opened on request, and add the validation of requests to the agenda of the weekly maintenance meeting.
« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »

Director, CCI 94CCI Île-de-France
« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »

Maja SucekChief Operating Officer, Interreg Danube
Rarely on its own
Frameworks combine. Put several together to cover your business, or have the AI write yours.
Take your first measurementon OT.
What this framework covers
OT security concerns the systems that drive physical processes: programmable logic controllers, SCADA, DCS, sensors, field networks, engineering workstations, remote maintenance access. Its priorities differ from those of business IT. Process availability and integrity come before confidentiality, equipment lifecycles run for decades, and updates cannot simply be pushed out on a Tuesday evening. The frameworks that shape the field, IEC 62443 on the industrial side and NIST SP 800-82 as an implementation guide, describe segmentation into zones and conduits, access management, monitoring and incident response.
In practice, oversight runs into three simple questions that are rarely settled. Is the inventory of connected equipment complete, or reconstructed from memory by the maintenance team? Is the industrial network genuinely segmented from the office network, or merely separated by a firewall whose rules nobody reviews any more? Are suppliers’ remote maintenance accesses logged and revoked, or left open permanently since the line was commissioned? On top of this sits the split of responsibilities between industrial management, maintenance and IT, which is often left implicit.
IT/OT convergence has changed the picture. Connected industry projects, production data flowing to the cloud and predictive maintenance have opened up environments designed to be isolated. A recurring confusion is applying the standard IT security baseline straight to the plant floor. Antivirus on a supervision workstation running an obsolete operating system, monthly patching on a controller running continuously, strong authentication on a console shared by three shift teams: none of these measures transfer without trade-offs against production.
The maturity assessment answers a different question from a technical audit. An audit identifies a vulnerability on a given piece of equipment at a given moment. The assessment positions your practices on a progressive scale, theme by theme, and indicates which action moves you to the next level. It also makes sites comparable with each other: a recently built plant and a site acquired through acquisition do not start from the same point, and the action plan cannot be the same.
In Datamensio, the framework is ready to use and you keep control of it. The AI adjusts the themes, questions and levels to your industrial context, or builds a variant from your policies and engineering standards. Across a fleet of several sites, it groups gaps into a prioritised roadmap rather than a site by site list of actions.
Reference standard: OT security maturity framework, based on IEC 62443 principles and NIST SP 800-82
The themes assessed
OT governance and responsibilities
Security policy applicable to industrial environments, division of roles between production, maintenance and IT, handling of exceptions, dedicated resources.
Industrial asset inventory
Register of controllers, supervision systems, engineering workstations and network equipment, criticality to the process, firmware versions, upkeep of the inventory.
Network architecture and segmentation
Division into zones and conduits, separation between industrial and office networks, controlled crossing points, flow mapping, management of wireless equipment.
Access and account management
Shared accounts on consoles, vendor accounts and default passwords, integrator rights, periodic review of permissions.
Remote access and supplier interventions
Remote maintenance arrangements, activation on request, session traceability, security clauses in maintenance contracts, management of removable media.
Vulnerability and patch management
Monitoring of equipment in service, update windows compatible with production, compensating measures on systems that cannot be patched, testing before deployment.
Detection and monitoring
Logging of industrial equipment, network supervision probes, detection of changes to controller programmes, escalation to security monitoring.
Incident response and recovery
Procedures adapted to the process, degraded mode operation, backups of programmes and configurations, restoration tests, exercises involving both production and security.
Security in projects and the lifecycle
Security requirements in specifications, acceptance of new installations, management of equipment at end of support, decommissioning.
Culture and skills
Awareness for shift teams, training for automation engineers, contractors’ knowledge of instructions, lessons learned after incidents.
A short version of the framework is available for the online self-assessment.
Frequently asked questions
How does this assessment differ from a technical audit of my facilities?
A technical audit identifies vulnerabilities on specific equipment at a given moment. The assessment measures the maturity of your practices: inventory, segmentation, access management, incident response. The two complement each other, with the assessment indicating which areas to invest resources in.
Does production need to stop to carry out the assessment?
No. The assessment relies on questions about practices and organisation, answered by the teams in place. No connection to industrial systems is required, and no network scan is carried out.
Does this framework prepare us for IEC 62443 certification?
Datamensio measures maturity and prepares you, it does not certify. The assessment draws on the field’s structuring principles, notably the zones and conduits logic and access management, and positions you before you engage in a formal process with a certification body.
How long does the assessment take?
The short version can be completed in a single working session. The full version, run collaboratively with maintenance, automation and IT, generally spans one to two weeks, with most of the time spent gathering input from sites.
Can several plants be compared with each other?
Yes. The same framework is rolled out to every site and scores are comparable by theme, as well as over time against your own previous assessments. A cross site roadmap consolidates the audits into a single plan rather than a list per site.
Can the framework be adapted to our sector?
Yes. You can modify the questions, levels and themes, add the specifics of your processes, or start from your own engineering standards. The AI then builds a variant from your documents, which you validate before publishing.
Who should answer the questions?
The questions concern practices, not configurations. A maintenance manager, an automation engineer or a security contact can answer them. The collaborative mode allows each question to be assigned to the person who holds the information.
Where is the data hosted?
In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.





