A factory network audit should begin with one question: if a device or connection fails at 10am on a busy production day, who notices first and how quickly can the line recover? That is the practical context for how to audit factory networks. This is not an exercise in producing a tidy IT diagram. It is a way to find the weaknesses that could stop machinery, interrupt ERP or MRP access, expose intellectual property or turn a contained cyber incident into a site-wide outage.
A worthwhile audit respects the difference between office IT and operational technology. A standard laptop can often be patched or restarted with limited consequence. A legacy PC controlling a machine, a barcode scanner feeding a warehouse process or a programmable controller linked to a production cell may have very different constraints. The goal is to improve visibility and security without making untested changes that put output at risk.
Start with production-critical processes
Before scanning networks or reviewing firewall rules, map the processes that keep the factory moving. Speak to production, engineering, warehouse, quality and finance teams, as well as IT. Ask what must be available for orders to be produced, dispatched and invoiced, and what workarounds exist when systems are unavailable.
This reveals dependencies that are easily missed in a technical review. An ERP server may be obvious, but the label printer, shared workstation, remote support connection or database integration that feeds a specific machine may be just as critical. It also helps you classify systems by operational impact rather than by age or ownership.
For each key process, record the acceptable downtime, the system owner and the supplier or internal team responsible for support. This creates accountability early. If a fault crosses the boundary between a machine vendor, software provider and IT team, uncertainty over responsibility can add hours to an outage.
Build an accurate asset and connection inventory
Most network risks begin with incomplete information. Factories commonly contain equipment added during expansions, temporary projects or machinery upgrades. Over time, switches are installed in cabinets, wireless access points are added to improve coverage, and vendor devices remain connected long after their original purpose has been forgotten.
Create an inventory that covers office, warehouse and shop-floor technology. It should include servers, PCs, industrial PCs, virtual machines, switches, firewalls, wireless access points, printers, scanners, CCTV systems, remote-access appliances, production equipment and any Internet-connected services.
For each asset, capture its location, IP address, operating system or firmware, owner, function, support status and network segment. Record how it connects: wired, wireless, cellular, VPN or third-party remote access. A simple inventory is more useful than a complicated document that nobody maintains, provided it is accurate and reviewed after changes.
Be cautious with active discovery tools around sensitive operational technology. Aggressive scanning can affect older devices or poorly documented machinery interfaces. In some environments, passive monitoring, switch data and controlled testing with the machine supplier are safer than running a broad scan during production hours.
Review whether the network is properly segregated
A flat network makes life easier for attackers and faults. If an office PC, guest device and machine controller can all communicate freely, ransomware or an accidental configuration change has more opportunity to spread. Segregation limits that exposure by separating systems according to their role and risk.
A sensible design often separates corporate IT, production systems, warehouse devices, guest Wi-Fi, CCTV and building services. The exact layout depends on the site, machinery and applications. A small engineering business may need a straightforward arrangement that is easy to support, while a multi-site operation may require more detailed zones and tightly controlled inter-site access.
The audit should examine the traffic permitted between these areas, not simply confirm that separate VLANs exist. Check whether production equipment can reach the internet, whether office users can directly access machine networks, and whether firewall rules allow only the services that are genuinely required.
Where older equipment needs access for support or data collection, a jump machine can provide a controlled route. This is often safer than allowing direct remote desktop access from ordinary office devices. The jump machine should be maintained, monitored and limited to authorised users.
How to audit factory networks for access risk
Access controls deserve close scrutiny because manufacturing environments often involve shared devices, shift workers and external suppliers. Review user accounts, administrator privileges, remote access methods and any generic logins still used on shop-floor systems.
Generic credentials are sometimes difficult to remove immediately, particularly where older software or machinery requires them. The audit should identify these exceptions, document the reason and reduce the risk around them. That might mean restricting where the account can be used, applying stronger controls to the surrounding network or agreeing a replacement plan with the vendor.
Remote access needs particular attention. Confirm who can connect, from where, using which method and whether multi-factor authentication is enforced. Accounts belonging to former staff, dormant suppliers and old support contracts should be removed. A supplier may need access to diagnose a fault, but permanent unrestricted access is rarely the right answer.
Also check physical access. Unlocked comms cabinets, exposed network ports and unattended shared terminals can undermine otherwise sound technical controls. In a busy factory, practical controls that people can follow consistently are usually more effective than policies that only work on paper.
Examine patching, legacy systems and unsupported hardware
Patching is not a simple measure of whether every device has the latest update. In a factory, an update may affect a machine interface, driver or approved application. Equally, leaving known vulnerabilities unaddressed creates an avoidable route into the network.
The audit should separate devices into three groups: those that can be patched through normal change control, those needing supplier testing before updates, and those that cannot be supported or updated. For the final group, document compensating controls such as network isolation, restricted user access, application allow-listing, enhanced monitoring and verified backups.
This provides a realistic risk picture for directors and auditors. Unsupported operating systems are not automatically a reason to replace a machine that remains commercially viable. They are a reason to understand the exposure and put suitable protection around it. Lifecycle planning can then be based on production, budget and risk rather than panic following an incident.
Test resilience, not just security
A network can be secure on paper and still be fragile. Review the points where a single failure could stop production: one firewall, one core switch, a single internet circuit, ageing uninterruptible power supplies or a server without a tested recovery process.
Check whether network equipment configurations are backed up and whether replacement hardware, licences and support information are available. If a managed switch fails, can its configuration be restored quickly? If the ERP application becomes unavailable, does the business know the recovery sequence and the people who must be involved?
Backups should be assessed for recoverability, not merely completion. Confirm that critical systems are included, protected from ransomware and tested at intervals that reflect their importance. Recovery targets should make commercial sense. Restoring a file after two days may be acceptable for one department, but not for a system that controls despatch or production scheduling.
Review Wi-Fi coverage and wireless security
Wireless networks often grow organically as warehouses expand or production layouts change. An audit should test coverage where devices are actually used, including loading bays, stock areas, workshops and external yards where appropriate. A signal that looks acceptable in an office does not guarantee reliable scanning or tablet use beside machinery and racking.
Review wireless separation too. Corporate users, operational devices and visitors should not share unrestricted access. Use secure authentication where the device supports it, remove obsolete wireless networks and ensure access points are managed and updated. Interference, poor roaming and weak coverage are operational issues as much as technical ones when they delay picking, stock movements or quality checks.
Turn findings into a practical improvement plan
The final report should not be a long list of vulnerabilities with no route to action. Prioritise issues by their likely impact on safety, production continuity, cyber exposure and compliance obligations. A clear plan normally separates immediate risks from improvements that require design work, supplier input or planned downtime.
Useful priorities include removing unneeded remote access, closing insecure firewall rules, backing up network configurations, isolating unsupported systems and documenting critical dependencies. Longer-term actions may include replacing end-of-life switches, redesigning segmentation, improving wireless coverage or introducing a tested disaster recovery process.
Assign each action an owner, target date, estimated disruption and decision required. This turns an audit into a management tool rather than a document that sits unread after the review. Re-audit after significant machinery, software or layout changes, and review the inventory routinely so it remains a trusted record.
A factory network audit is most valuable when it gives production leaders confidence that technology supports the next shift rather than becoming its biggest unknown. The right findings create a measured route to stronger security and reliability, while keeping the focus where it belongs: protecting output.
