Assessment Progress
TeckNexus Intelligence In collaboration with OneLayer

How Governed Are Your Cellular OT Devices, Really?

A 5-section assessment for security leaders responsible for cellular-connected OT device risk. Answer questions about your current visibility and controls — we'll benchmark your maturity and flag your most urgent security gap. Select the option that most accurately describes your current state, not your aspirational state.

5 sections · 17 questions ~5-7 minutes Personalized maturity report PDF summary included

Loading your assessment…

Retrieving your saved report. This will only take a moment.

Section 00 of 04 · About You

Tell us a bit about your environment

These questions won't affect your score — they help us tailor your results and benchmark you against similar organizations.

Question 1 of 3
What is your primary role in the organization?
Question 2 of 3
What best describes your organization's primary cellular network architecture for OT and IoT devices?
Question 3 of 3
Which best describes your current OT security program's coverage of cellular-connected devices?
Section 1 of 5
Section 01 of 04 · Device and SIM Visibility

Can you actually see everything connected to your network?

You can't defend what you can't see. This section checks how deep your device visibility goes — and whether restricted manufacturers are being tracked.

Question 1 of 3
Are you able to identify the make, model, manufacturer, and firmware version of every device connected to your cellular network, including devices behind routers or gateways?
Question 2 of 3
How do you identify devices that are connected to your cellular network but were not formally onboarded through your standard procurement process?
Question 3 of 3
How does your organization address devices from manufacturers flagged by government advisories, such as FCC-restricted manufacturers or NDAA Section 889 prohibitions?
Section 02 of 04 · Authentication, Access Control, and Zero Trust

Could a rogue device get onto your network undetected?

Device identity, segmentation, and integration with your broader security stack determine whether an unauthorized device is caught in minutes or never.

Question 1 of 4
How does your cellular network authenticate devices before granting them access?
Question 2 of 4
If a SIM were removed from an authorized device and placed into unauthorized hardware, would your security systems detect this?
Question 3 of 4
Do you have policy controls that restrict which cellular-connected devices can communicate with specific systems or segments of your OT network?
Question 4 of 4
How are your existing security tools, including firewalls, NAC, and SIEM, informed about cellular-connected devices on your network?
Section 03 of 04 · Threat Awareness and Compliance Readiness

If a device type were compromised today, how fast could you respond?

State-sponsored actors like Salt Typhoon and Volt Typhoon have proven that cellular OT infrastructure is an active target. This section checks your awareness and response speed.

Question 1 of 4
How familiar is your organization with the Salt Typhoon and Volt Typhoon threat campaigns and their relevance to cellular OT environments?
Question 2 of 4
How does your organization address regulatory compliance requirements that apply to cellular-connected OT devices, such as NERC CIP, IEC 62443, or TSA cybersecurity directives?
Question 3 of 4
Do you have continuous monitoring of whether each cellular device is operating within its intended network segment, with alerts when it deviates?
Question 4 of 4
If a specific device type or manufacturer were identified as compromised, how quickly could your team find every affected device and restrict its network access?
Section 04 of 04 · Program Maturity and Organizational Readiness

Who actually owns this risk today?

The final section looks at organizational visibility, and asks you directly where you feel the biggest gap is.

Question 1 of 3
Which stakeholders in your organization currently have visibility into the security posture of your cellular-connected device fleet?
Question 2 of 3
How integrated is your cellular device security with your broader OT security program, including SIEM monitoring, SOC coverage, and incident response workflows?
Question 3 of 3 (Select all that apply)
What is your organization's greatest current gap in managing the security of cellular-connected OT devices?
📬

Check your inbox

We've sent your results link to .
Click the link in the email to view your full report.

Can't find the email? Check your spam or junk folder.
The email comes from sales@tecknexus.com with subject line
"Your Security & Asset Management Assessment Results".

Your personalized security report is ready.

Enter your details below to access your full report — including your maturity tier, section breakdown, and your top self-identified gap. We'll also email you a link so you can come back to it anytime.

↓ Complete the form below to access your results
Security & Asset Management Assessment · Results

Your Cellular Security Maturity Report

Where You Land
Your overall score placed on the Exposed → Partial Coverage → Governed maturity spectrum.
Section Maturity Breakdown
How each section of the assessment scored, relative to its own maximum.
Recommended Action Sequence
Your Responses at a Glance
What you told us, and what it means — organized by section.
Next Step · OneLayer

Get Continuous Visibility Into Your Cellular OT Fleet

OneLayer's continuous device visibility and policy enforcement directly addresses the detection and integration gaps most organizations at your tier report.

No-cost architecture walkthrough based on your assessment results
Continuous device identification and unauthorized-device detection
Covering device visibility, policy enforcement, and SOC integration
Talk to OneLayer →

How Governed Are Your Cellular OT Devices, Really? A New Benchmark for Security Leaders

A five-section assessment reveals where visibility, authentication and incident-response gaps are most likely to sit across cellular-connected OT fleets

Industrial organisations have spent the last decade hardening the IT/OT boundary, deploying network access control, and building SOC coverage for everything that touches a switch port. Cellular-connected devices — routers, gateways, remote terminal units, sensors reporting over private or carrier cellular — have often sat outside that perimeter entirely, connected by SIM rather than cable, and consequently invisible to the tools built to police everything else.

TeckNexus has partnered with OneLayer to launch an interactive cellular OT device security assessment, designed to help private network operators and OT security leaders benchmark exactly how governed their cellular fleet actually is, rather than how governed policy assumes it to be.

Why cellular OT device visibility is the starting gap

The assessment opens where most security programmes quietly fall short: can you identify the make, model, manufacturer and firmware of every device on your cellular network, including those sitting behind routers or gateways you didn’t provision? Organisations that can only confirm a SIM or subscriber ID is active — not the hardware attached to it — are working from an inventory that describes their billing relationship with a carrier, not their actual attack surface. A valid SIM in the wrong hardware is, in that scenario, functionally invisible.

This matters more now than it did five years ago. Government advisories around FCC-restricted manufacturers and NDAA Section 889 prohibitions have turned “which vendors are physically deployed on our network” from a procurement question into a compliance one. Screening at time of purchase is a reasonable baseline, but devices get redeployed, repurposed, or arrive through channels procurement never sees — which is why the assessment treats continuous, fleet-wide monitoring as a materially stronger posture than a one-time check.

Authentication, segmentation and the rogue-device problem

The second dimension the assessment probes is whether an unauthorised device could join the network undetected. Default carrier or vendor authentication, with no additional controls layered on top, is straightforward to bypass and rarely audited. The stronger posture pairs SIM authentication with IMEI correlation and enforces it actively — because a SIM alone only confirms a subscription is valid, not that the hardware attached to it hasn’t changed. A SIM pulled from an authorised device and inserted into unauthorised hardware is one of the more quietly dangerous scenarios in cellular OT environments, and the assessment specifically checks whether organisations could detect that swap at all.

Segmentation follows the same logic. Coarse network- or APN-level grouping is common, but it means a compromised device inside an “approved” group still has broad reach. Per-device policy enforced at the cellular layer — closing the loop between authentication and access — is what separates organisations that can contain an incident from those that discover it after lateral movement has already occurred.

Threat awareness: Salt Typhoon, Volt Typhoon and the compliance blind spot

The assessment’s third section addresses something increasingly hard to ignore: state-sponsored campaigns, including Salt Typhoon and Volt Typhoon, have specifically targeted telecom and cellular infrastructure to gain persistent footholds in critical infrastructure operators. Organisations that treat cellular OT as out of scope for threat modelling — because it’s “just connectivity,” not core infrastructure — are leaving a measurable exposure unmeasured, at precisely the layer that’s been shown to be actively targeted.

The same gap shows up in compliance posture. Frameworks like NERC CIP, IEC 62443 and TSA cybersecurity directives are frequently applied thoroughly to IT and traditional OT, while cellular-connected devices sit just outside their documented scope — a distinction that tends to surface during an audit rather than before one.

Response speed and who actually owns the risk

The final sections test something more operational: if a specific device type or manufacturer were confirmed compromised today, how quickly could the organisation find every affected device and restrict its access? Responses range from hours, backed by automated inventory and enforcement, to weeks of manual correlation — a gap that determines whether a compromised device type is contained during an incident or remains active throughout the investigation.

Underneath all of this sits a governance question the assessment asks directly: who currently has visibility into cellular device security posture? When that visibility stops at the network or telecom team, security decisions about cellular-connected devices are effectively being made without security input — a pattern the assessment’s data suggests is the most common root cause behind the other gaps it identifies.

Where this leaves security leaders

None of this is an argument against cellular connectivity for OT — it’s the fastest-growing deployment model for exactly the reasons that make it attractive: no trenching, rapid rollout, flexibility across sprawling sites. The assessment’s purpose is to help organisations see clearly where their governance of that connectivity actually stands, and to sequence next steps — visibility first, then authentication and segmentation, then integration with the broader SOC — rather than treating all gaps as equally urgent.

Security leaders responsible for cellular-connected OT device risk can take the five-section assessment directly and receive a maturity report benchmarked against similar organisations.

Partner Hubs

Download content, access intelligence tools, and hear from executives.

Partner Events

  • M360 ASEAN
  • FutureNet Asia 2026
  • Network X Vienna 2026
Scroll to Top