Spreadsheets are not the problem at small scale
For a single facility with a modest number of assets, a well-maintained spreadsheet can genuinely work as a security assessment tool. Someone walks the plant, records what they find, cross-references it against a checklist derived from IEC 62443 or an internal standard, and produces a report that reflects the environment reasonably accurately. The limitation is not the spreadsheet itself. It is what happens as the environment being assessed grows in size, complexity, or rate of change.
Where the manual approach starts to break down
The first place it breaks is currency.
A spreadsheet-based assessment is a snapshot, accurate on the day it was compiled and progressively less accurate afterwards. In a single small facility this might remain broadly usable for months. Across a multi-site operation with hundreds or thousands of assets, changes happen faster than any manual process can realistically track, and the spreadsheet becomes a record of how the environment used to look rather than how it looks now.
The second is consistency.
When assessments depend on an individual assessor’s judgement, applied manually against a checklist, different assessors working across different sites tend to interpret the same criteria slightly differently. This is not a criticism of the people involved; it is an inherent property of manual, judgement-based processes repeated at scale. The result is a set of assessments that are difficult to compare directly across a portfolio of facilities, which makes it hard to answer a reasonable question like which of our ten sites carries the most risk right now.
The third is traceability.
When a spreadsheet is updated, the previous version is often overwritten or saved as a separate file with no structured link between the two. Reconstructing how a specific risk rating changed over time, or demonstrating to a regulator or auditor exactly what was known and when, becomes a matter of digging through file versions rather than querying a maintained record.
What a platform approach changes
A platform-based approach to OT security assessment does not eliminate the need for expert judgement. It changes what that judgement is applied to and how consistently it is captured. Asset data is collected once, through passive network monitoring and structured intake rather than repeated manual walk-downs, and maintained centrally rather than being re-gathered from scratch for each assessment cycle. Risk scoring is applied through a consistent, auditable methodology, so that the same criteria produce the same rating regardless of which assessor or which site is involved. Changes are tracked over time automatically, producing a genuine history rather than a series of disconnected snapshots.
This also changes what is possible at the portfolio level. An organisation with assessments spread across separate spreadsheets for each site has no straightforward way to compare risk across the portfolio without manually reconciling different formats and different assessors’ judgement calls. A platform that holds this data centrally, with a consistent structure, can surface that comparison directly, which is often the question leadership actually wants answered: where should we be spending our next security investment, and why.
This is not simply a tooling upgrade
It is worth being clear about what a platform does not solve. It does not replace the need for skilled engineers who understand both security and the industrial process being assessed. It does not remove the value of a physical walk-down, which still catches things that network monitoring alone cannot, such as an undocumented device sitting on an isolated segment or a physical access control that has been propped open. What it changes is the scale at which good practice can be sustained. The organisation moves from good assessments happening when someone has the time to build a careful spreadsheet, to good assessments happening consistently because the underlying process no longer depends entirely on manual effort.
Recognising when the transition point has arrived
There is no fixed threshold of asset count or site count at which a spreadsheet-based approach definitively stops working. The more useful signal is whether the organisation can currently answer, with confidence and without a multi-week data-gathering exercise, which assets across its OT environment carry the highest risk today. If that answer takes weeks to produce and is out of date again within a month of being delivered, the assessment process has already outgrown the tool being used to run it, whether or not that has been formally recognised yet.

