OT Cybersecurity Audits: Why Texas Manufacturers Fail and What to Fix First

When a Texas manufacturer fails an OT cybersecurity audit, it’s usually on evidence, not effort. In practice, the plant can’t produce a current inventory of its control equipment, proof the plant network is walled off from the office, a list of who holds vendor remote access, or a written plan for machines that can’t be patched.

It usually starts with a spreadsheet. A customer’s supplier security questionnaire grows a tab for plant systems, or the insurance renewal asks who can reach the production network from outside. IT takes the office questions. Maintenance gets the rest. Answers come back as yes, partially, and blank. Mostly blank.

Filling those blanks with proof is a big part of our manufacturing IT services in Houston, and the work looks the same in Dallas-Fort Worth and San Antonio. I’m Uprite’s CTO, so I’ll say the uncomfortable part first. Plants rarely fail these reviews because nobody cares. They fail because the controls live in a controls engineer’s head, a vendor’s laptop, and a binder the last integrator left behind, and an auditor can’t grade any of those.

Texas has plenty of plants in that spot. Texas has about 983,000 manufacturing jobs, per preliminary BLS payroll data for August 2026, and the Census Bureau’s County Business Patterns for 2023 show 84% of the state’s manufacturing establishments have fewer than 50 employees. A 40-person machine shop in Pasadena doesn’t have an OT security team. It still gets the questionnaire.

OT cybersecurity audits reach Texas plants through customers, insurers, CMMC assessors, and frameworks like NIST’s draft CSF 2.0 Manufacturing Profile and ISA/IEC 62443. Plants usually fail on missing evidence, like no OT asset inventory, flat networks, open vendor access, unsupported HMIs with no exception record, and untested logic backups. CISA flagged 337 advisories on manufacturing equipment in 12 months, so patching everything isn’t a plan. Build the proof in order and save downtime for the 2 steps that need it.

What Is an OT Cybersecurity Audit for a Manufacturer?

An OT cybersecurity audit is a review of the systems that run production, meaning PLCs, HMIs, SCADA and MES servers, engineering workstations, and the networks between them, measured against a named standard or questionnaire. It grades proof, not intent. Each control needs a document, a log, or a screenshot showing it exists and works.

OT means operational technology, the equipment that makes, moves, and measures product. It isn’t a SOC 2 report. It isn’t the letter grade an outside scan gives your website, either. An IT audit rarely goes past the office switch. An OT audit starts there.

Who’s asking matters. A lot. Each reviewer grades against a different yardstick.

Who’s askingWhat triggers itWhat they grade againstWhat a failed review costs you
A customer’s supplier security teamA new contract, an annual vendor review, or a breach at another supplierTheir own questionnaire, usually built from NIST CSF, ISO/IEC 27001, or ISA/IEC 62443A corrective action plan, a delayed award, or a slide down the approved-vendor list
Your cyber insurerRenewal or a new policyUnderwriting questions on MFA, backups, remote access, and segmentationA higher premium, an exclusion, or a declined renewal
A CMMC assessment, for defense workA Department of War contract carrying the CMMC clauseNIST SP 800-171 Revision 2 and its 110 requirementsNo award on contracts that require it
An ISA/IEC 62443 assessmentA customer, a corporate parent, or a new automation project62443-2-1 for your security program, 3-2 and 3-3 for zones, conduits, and security levelsA findings list tied to each zone
Your owners or boardBudget season, a sale, or private equity diligenceOften the NIST CSF, which now has a draft manufacturing profileA written risk the owners can’t unsee

Insurers deserve a closer look. Beazley’s cyber application for companies above $250 million in revenue has a section only manufacturers and a few other industries fill out, and it asks 4 things. Is your OT segmented from IT? From the internet? Is MFA enforced for employee remote access, and for third-party remote access? Beazley’s smaller-company form skips that section. For now. Our notes on what cyber insurance applications ask cover the rest of the form.

Texas adds a wrinkle that isn’t an audit at all. Since September 1, 2025, Chapter 542 of the Business and Commerce Code shields a business with fewer than 250 employees from exemplary damages after a data breach if its security program conforms to a recognized framework, such as the NIST CSF. It covers personal information, not PLCs, but it rewards the same paper trail. Our SB 2610 checklist breaks down the tiers.

Why Do Texas Manufacturers Fail OT Cybersecurity Audits?

Plant audits keep landing on the same 7 evidence gaps, and under most of them sits one missing thing, a named owner for the plant network. Controls are often partly there. Proof isn’t.

Outside data agrees. In Dragos’s 2026 OT Cybersecurity Year in Review, 81% of its services reports found poor IT/OT segmentation, 49% carried elevated remote access findings, and in fewer than 5% could the client identify its end-of-life or unsupported assets. SANS, in its 2025 State of ICS/OT Security survey, found 31% of respondents had no centralized inventory of their OT remote access points. Neither sample is Texas-specific. Read them as direction, not a scorecard.

  • No current OT asset inventory. Commissioning spreadsheets don’t count.
  • A plant network sharing a flat address space with the office, or an air gap with a cable in it.
  • Vendor remote access nobody can list, approve, or shut off in under an hour.
  • Windows HMIs and engineering workstations past end of support, with no record of why they stay or what protects them.
  • Patching without a process. Or a process without records.
  • Controller logic and HMI project backups that have never been restored, not even once.
  • No named owner for plant cybersecurity, which is really the gap under the other 6.

Each gap maps to a document. This is what gets asked on audit day, and what gets a pass.

The gapWhat the auditor asks forWhat plants usually hand overWhat passes
Asset inventoryEvery PLC, HMI, switch, and workstation on the plant network, with firmware and OS versionsThe integrator’s spreadsheet from commissioning dayA dated inventory built from a walkdown plus passive network data, with an owner and a review date
SegmentationA current network diagram and the firewall rules between office and plantA diagram drawn before the last line expansionA current diagram, an exported rule set, and proof plant devices can’t reach the internet
Vendor remote accessEvery path in, who approved it, and whether MFA is onA shrug and whatever remote support tool the vendor installedNamed accounts, MFA, per-session approval, logging, and access that’s off by default
Unsupported systemsA list of end-of-life operating systems and firmwareSilence, or a promise to upgrade next yearAn exception register naming each system, why it stays, the compensating control, and a replacement date
Vulnerability managementHow advisories get matched to your equipment and decidedA patch report that only covers office PCsA log of advisories reviewed, the decision on each, and the window that closed it
Backup and recoveryProof you can restore controller logic and HMI projectsA backup job that says it succeededA restore test record with the date, the system, and how long it took
Ownership and responseWho owns plant cybersecurity and what happens in an incidentThe IT manager and the plant manager pointing at each otherA signed ownership memo, an OT incident plan, and a tabletop record

One honest note, though. Regulated sites in the SANS survey had roughly as many ICS and OT incidents as unregulated ones, but about half the financial losses and physical safety impacts. Passing doesn’t stop the attack. Evidence shortens the bad week.

The Inventory Is Whatever the Integrator Left Behind

Every OT audit opens with the same request. Show me the network. All of it. CISA and 8 partner agencies made that the foundation of their OT asset inventory guidance in August 2025, calling an inventory “necessary for building a modern defensible architecture.” NIST’s draft manufacturing profile puts it in the Low tier, the baseline every plant starts from, and lists what belongs on it, from PLCs, sensors, robots, and machine tools to firmware and network switches.

A walkdown with a clipboard finds the boxes. It won’t find the cellular modem a machine builder installed for remote support, or the unmanaged switch added during a line expansion. Passive network data will. You need both, plus firmware versions, because the auditor’s next question is which of those devices showed up in this year’s advisories.

Technician in white gloves plugging an Ethernet cable into a row of PLC modules with status lights inside an industrial control cabinet

The Air Gap Has a Cable in It

In April 2026, CISA, the FBI, the NSA, and 4 other agencies published advisory AA26-097A on Iranian-affiliated actors breaking into internet-exposed PLCs. Named models included Rockwell CompactLogix and Micro850, Schneider Electric Modicon M340, and Siemens S7-1200, controller families you’ll find on plenty of Texas production lines. Attackers changed project logic, including Add-On Instructions, and manipulated what HMI and SCADA screens showed. CISA says the changes “disabled critical shutdown and alarm logic.” Operators got no warning.

CISA’s named victims sat in government facilities, water, and energy. Not manufacturing. That’s luck. Luck isn’t a control. The advisory’s first mitigation, getting PLCs off the public internet, also opens CISA’s primary mitigations fact sheet for OT, followed by changing default passwords, securing remote access, segmenting IT from OT, and practicing manual operations. An auditor can check every one of those before lunch.

Vendors Still Have a Key

This is the finding I’d bet on in an unprepared plant. A robot integrator, a compressor vendor, and the MES provider each set up their own way in years ago, often with a shared login and a remote tool that never stops listening, and nobody kept the list. Sound familiar? SANS found fewer than 15% of organizations have advanced remote access controls in place, like session recording or OT-aware access, even though unauthorized external access accounted for half the incidents its respondents reported.

Read the MFA fine print. NIST’s draft manufacturing profile puts multi-factor authentication for remote access in its High tier, and asks lower tiers for written authentication policies and approval for each type of remote access. CISA’s Cybersecurity Performance Goals 2.0, released in December 2025, go further. They call for MFA on every remotely accessible OT account, vendor and maintenance accounts included, and removing remote access where MFA isn’t available. Plan for CISA’s version. Beazley’s form already asks it.

Wall-mounted firewall and network switch with yellow and blue patch cables and glowing link lights in a plant electrical room

Windows 10 Is Still Running the Press Line

Standard Windows 10 reached end of support on October 14, 2025. Microsoft’s Extended Security Updates cost $61 per device for the first year and double each year after, for 3 years at most. HMIs tend to stay on it anyway, because the HMI software was validated on that exact build, the machine builder won’t sign off on anything newer, and nobody wants to be the person who broke the line.

Check the edition first. Windows 10 IoT Enterprise LTSC 2021 is supported until January 13, 2032, and IoT Enterprise LTSC 2019 until January 9, 2029. Non-IoT Enterprise LTSC 2021 leaves mainstream support on January 12, 2027. Same version number. 3 different answers.

NIST’s SP 800-82 Revision 3 admits the bind, noting that “the lifespan of an OT system can exceed 20 years,” and asks for compensating controls where patching isn’t possible. So the real finding isn’t that you run Windows 10. It’s that nobody wrote down why, what protects it, and when it goes.

The Backup Says Success. Nobody Has Tried a Restore.

Ask who backs up the PLC programs and you’ll often get a name, not a system. It lives on an engineering laptop, a USB stick, or the integrator’s server in another city. NIST’s draft profile asks every tier to verify backups, configurations, and set points before restoring from them, and AA26-097A asks for strong, tested backups of PLC logic too.

Tested is the key word. A restore onto a spare controller, or onto the real one during a planned shutdown, with the date and result written down, beats a year of green backup reports. Office servers get the same scrutiny in our disaster recovery planning for Texas businesses.

Nobody Owns the Plant Network

IT thinks maintenance owns the plant switches. Maintenance thinks IT does. The integrator thinks the job closed out in 2019.

NIST added a Govern function when it released CSF 2.0 on February 26, 2024, and the draft manufacturing profile makes it concrete. It asks plants to name leadership roles, with the plant manager and OT and IT leads as examples, and to document how production needs shape calls like patch deferrals and remote access rules. The same SANS survey found 57% of organizations have an incident response plan written for ICS and OT. Everyone else has a playbook written for an email outage.

A one-page memo naming the owner, signed by the plant manager and whoever runs IT, does more for an audit than most tool purchases. It costs nothing. It also takes 2 people agreeing, which is why it rarely exists.

What Did 12 Months of CISA Advisories Say About Manufacturing Equipment?

CISA published 486 industrial control system advisories from September 25, 2025, through September 24, 2026, and 337 of them, or 69.3%, listed Critical Manufacturing as an affected sector. That’s about 6 a week, every week, for equipment that could be on your floor.

We counted them ourselves. Each ICS advisory is also released as a machine-readable CSAF document in CISA’s public GitHub repository, with a field naming the sectors it affects. We kept the ones tagged Critical Manufacturing, scored every vulnerability’s CVSS vector, and matched each CVE against the Known Exploited Vulnerabilities catalog as of September 27, 2026.

MeasureAdvisoriesShare
Listed Critical Manufacturing, out of 486 ICS advisories33769.3% of all ICS advisories
Held a flaw someone could exploit remotely with no login and no user action15746.6% of the 337
Top severity of CVSS 9.0 or higher8625.5%
Weaknesses included missing authentication or hard-coded credentials5516.3%
Vendor said no fix is planned or available for at least 1 flaw236.8%
Contained a CVE from CISA’s known-exploited list185.3%

Nobody expects 337 patches. Not even close.

What an auditor expects is a process that answers 4 questions. Which advisories touched equipment on your floor? What did you decide about each? Where’s that written down? Which maintenance window closed it? NIST’s draft profile puts that process in its Low baseline. Without an inventory, the honest answer to the first question is a shrug, and the audit’s over before it starts.

Those 23 no-fix advisories deserve their own lines in your binder. Schneider Electric’s advisory for EcoStruxure Power Monitoring Expert 2022 says that version has reached end of life. Mitsubishi Electric has no plans to release a fix for its MELSEC iQ-F FX5-ENET/IP Ethernet module, and Rockwell Automation reported no fix available for ArmorStart AOP. Siemens accounted for 18 of the 23, though it also filed far more advisories than anyone else, 90 of the 337. When a vendor won’t patch, the auditor wants isolation, monitoring, and a replacement date on paper.

Then the surprise. Of the 18 advisories carrying a known-exploited CVE, none pointed at controller logic. The flaws sat in general-purpose software and networking code that industrial vendors ship inside their products. Cisco IOS runs inside Rockwell’s Stratix switches. Firewall software from Fortinet and Palo Alto Networks runs on Siemens RUGGEDCOM APE1808 devices. The rest were the Linux kernel, Microsoft’s Windows Server Update Services, Chromium, MongoDB, and jQuery, plus Lantronix’s own device servers. Your IT team already knows how to handle those. They just need to know the parts are in there.

A caveat on method. CISA’s sector tags describe where a product gets deployed, not whether it’s in your plant, and one advisory can list several sectors. Treat 337 as the size of the haystack. Your inventory tells you how many needles are yours.

What Does the NIST Manufacturing Profile Expect From a Plant?

NIST’s Manufacturing Profile translates the Cybersecurity Framework for plant systems and sorts plants into Low, Moderate, and High impact levels. Its CSF 2.0 version is still an initial public draft from September 29, 2025. Revision 1, built on CSF 1.1 in October 2020, remains the final version.

Tiers track how bad a bad day gets. NIST’s examples put plastic injection molding and warehousing at Low, automotive metal stamping and semiconductors at Moderate, and petrochemical, pharmaceutical, and food and beverage plants at High. Each tier includes everything below it, so Low is the floor for everyone.

CSF 2.0 functionWhat the draft profile asks at the Low baselineEvidence an auditor will accept
GovernName leadership roles such as plant manager and OT and IT leads, and document how production needs shape patch deferrals and remote access rulesA signed ownership memo and a risk register listing deferred patches
IdentifyInventory PLCs, sensors, robots, machine tools, firmware, and network switches, plus HMI software and operating systemsA dated inventory with versions, locations, and a review date
ProtectAuthenticate users under written password and MFA policies, control vendor maintenance access, fix vulnerabilities on a set schedule, and plan for end-of-life hardwareAccount lists, remote access approvals, and a patch and exception log
DetectTurn on logging for network devices, with protocol-aware monitoring left to the High tierFirewall and switch logs sent somewhere a person actually reads them
RespondDesignate a lead for each incident and run the plan once one is declaredAn OT incident plan and a tabletop exercise record
RecoverVerify backups, configurations, and set points before restoring from themA restore test with a date, a system, and a result

When a customer’s questionnaire asks about asset inventory or remote access, this is the vocabulary sitting under the question. And the ground is shifting. NIST released an initial public draft of SP 800-82 Revision 4 on September 21, 2026, rebuilt around CSF 2.0 and its Govern function, with comments open until November 30. If an auditor leans on governance language next year, that’s why.

Which OT Audit Is Your Plant Most Likely to Face?

It depends on who you sell to. And who owns you. A defense subcontractor and a food plant can fail the same way and still face different reviewers.

If your plantExpect questions fromStart with
Machines parts for a defense prime in Dallas-Fort Worth and handles CUICMMC Level 2 self-assessment under Phase 1, plus the prime’s flowdownsScoping which systems touch CUI, then the 110 NIST SP 800-171 requirements
Fabricates for energy customers along the Houston Ship ChannelCustomer supplier reviews and insurer renewalsThe asset inventory and vendor remote access
Runs a food, beverage, or packaging line in San AntonioInsurers and retail customers, and NIST puts food and beverage in its High tierBackups with a real restore test, then segmentation
Belongs to a private equity portfolioDiligence teams and board reportingA gap assessment against the draft NIST Manufacturing Profile
Has fewer than 250 employees and holds employee or customer personal dataNobody audits Chapter 542, but a plaintiff’s lawyer would test itA written program that conforms to a named framework

Defense suppliers need a straight answer on CMMC. On July 13, 2026, the Department of War suspended CMMC Phase II, the third-party assessments that were set to begin this November. It didn’t pause the rest. “All Phase I self-assessment requirements remain firmly in place,” the announcement says, and DFARS 252.204-7012 still binds every contractor handling covered defense information. The department’s OT Top 10 for defense suppliers even asks for “a hard schedule to replace undefendable hardware.”

Our CMMC and NIST 800-171 compliance work in Texas starts by scoping which plant systems actually touch CUI. Not a defense shop? Rulebooks that non-defense plants inherit from customers are in our breakdown of manufacturing compliance requirements in Dallas, and most of it applies statewide.

How Do You Prepare for an OT Cybersecurity Audit Without Stopping the Line?

Build the evidence in the order an auditor reads it, owner first and binder last, and schedule only 2 steps into downtime, the network cutover between office and plant and the first real restore test.

  1. Name the owner. One page, 2 signatures, the plant manager and whoever runs IT.
  2. Build the inventory from a walkdown plus passive data, such as switch tables or a sensor on a mirrored port, and record firmware and OS versions as you go.
  3. List every vendor path in. Kill the ones nobody claims, then put MFA, named accounts, and per-session approval on the rest.
  4. Start the exception register, where every unsupported or unpatchable device gets a line with the reason it stays, what protects it, and a target replacement date.
  5. Set up a weekly advisory routine that matches new CISA advisories against the inventory and logs each decision.
  6. Separate the plant from the office with firewall rules you can export and explain, and do the cutover during a planned shutdown.
  7. Back up controller logic, HMI projects, and historian configurations, then restore one for real. Time it.
  8. Write the OT incident plan with operations in the room, run a 90-minute tabletop, and put everything in one binder mapped to your auditor’s framework.
Two workers in hard hats and safety vests walking an idle manufacturing plant floor during a planned shutdown, one carrying a laptop

Only steps 6 and 7 need the line down, and step 7 can often run on a spare controller. Everything else happens during production. HMI replacements on your exception register belong to the next capital cycle. That’s fine. Just write the date down. Book the cutover and the restore test the day your next shutdown gets scheduled, because the shutdown calendar, not the IT calendar, decides when you’re ready.

For the controls side in more depth, see our guide to protecting OT without stopping the line. Still arguing internally about whether any of this applies to a plant your size? What Texas manufacturers get wrong about OT security is the faster read.

What Can an MSP Handle, and When Do You Need an OT Specialist?

An MSP can own the IT layer an OT audit grades hardest, meaning identity, remote access, firewalls between office and plant, Windows hosts, backups, logging, and the paperwork. Controller logic, safety systems, and protocol-level OT monitoring belong to your controls engineers or an OT specialist.

ControlIT team or MSPPlant and controls engineeringIntegrator or machine builder
Asset inventoryBuilds and maintains itWalks the floor and confirms itSupplies firmware and version details
Office-to-plant firewallDesigns, runs, and documents itApproves cutover timingLists the ports its systems need
Vendor remote accessRuns the access gateway, MFA, and logsApproves each sessionUses named accounts only
HMI and workstation patchingPatches and keeps the exception registerPicks the maintenance windowConfirms which updates its software supports
PLC logic backupsStores copies off the engineering laptopOwns the logic and runs the restore testHands over current project files
OT incident responsePulls logs and contains the IT sideDecides on manual operationSupports on call

Fair warning. We sell part of this work, so weigh my view accordingly. Uprite Services is a managed IT and cybersecurity provider for businesses across Houston, San Antonio, Dallas, and Fort Worth, and much of our IT work for Texas manufacturers lands right on that office-to-plant boundary. We don’t write PLC logic, tune safety instrumented systems, or commission control networks, and I’d be wary of any IT provider that offers to. If you already have an OT security team and a CISO who owns the plant, you probably don’t need us for this.

What we bring is the evidence habit. A manufacturer in our manufacturing IT modernization case study had to meet its cyber insurer’s requirements while end-of-life servers failed around it, and got there without disrupting daily production. A San Antonio manufacturer with about 50 employees started with a business technology assessment before anyone touched its security. Our FTC Safeguards Rule remediation taught the same lesson in another industry. Controls existed. Nobody could prove them.

We publish our own numbers. Average response time is 5.06 minutes, and we support 2,227 users. The MSSP Security Focus plan on our published pricing starts at $40 per user per month for companies with their own IT staff, covering advanced firewall management, SIEM, SOC monitoring, and vulnerability scanning, backed by a 120-day satisfaction promise. Plants in the other metros can start from our San Antonio manufacturing IT page or Dallas manufacturing IT page, and the full menu sits on our cybersecurity services page.

What Plant Managers Ask Before an OT Audit

How long does it take to get a plant audit-ready?

A quarter, for a single plant starting from zero, and your shutdown calendar sets the pace. Inventory, remote access cleanup, the ownership memo, and the exception register all happen during production. Only the network cutover and the first restore test wait for downtime.

We passed an IT audit last year. Doesn’t that cover the plant?

Rarely. IT audits tend to stop at the office switch and never look at PLCs, HMIs, or the vendor paths into them. Ask your last auditor which plant systems were in scope.

Can we scan the plant network ourselves before the auditor shows up?

Not with an active scanner, and not without your controls engineer’s sign-off. NIST’s SP 800-82 tells OT owners to use extreme caution with active scanning on an operational network and to schedule it during planned outages whenever possible. Start with passive methods, like switch tables and a sensor on a mirrored port, which listen without sending anything to your controllers.

What if our PLC vendor says the flaw will never be fixed?

Write it down, then wall it off. In the 12 months to September 24, 2026, 23 CISA advisories covering manufacturing equipment said no fix was planned or available. Auditors accept that when your exception register names the device, the compensating control, and a replacement date.

Does Texas law require an OT cybersecurity audit?

No Texas statute orders one. Business and Commerce Code Section 521.052 does require reasonable procedures to protect sensitive personal information, with penalties of $2,000 to $50,000 per violation, and Chapter 542 rewards a framework-based program with protection from exemplary damages. Neither reaches your PLCs directly. Customers and insurers do.

Is the NIST Manufacturing Profile mandatory for Texas plants?

Voluntary. The CSF 2.0 version is still a September 2025 draft. Customers and auditors borrow its language anyway, so it’s a smart map even when nobody makes you use it.

Will an auditor fail us for running Windows 10 on our HMIs?

Only if you can’t explain it. Standard Windows 10 lost support on October 14, 2025, while Windows 10 IoT Enterprise LTSC 2021 is supported until January 13, 2032. Check the edition on each machine, then record the reason it stays, the compensating control, and the replacement date. That record is what gets graded. Windows itself is almost secondary.

Who should be in the room when the auditor comes?

The plant manager, the controls engineer, and whoever runs IT, at the same table. Auditors lose patience fast when the answer to every plant question is that someone else knows. Get your integrator on the phone if they still manage anything on the floor.

Running a plant anywhere from the Houston Ship Channel to Fort Worth? Get an assessment. We’ll walk your plant network with your controls team, build the evidence list your auditor will ask for, and tell you plainly which gaps we can close and which need an OT specialist.

Get an Assessment

About Author

Learn More