Why PaSBaT?
Privacy-first network security snapshot assessments for confidential OT/IT environments.
Current status: technical PoC / pilot phase with Cisco focus; additional vendors based on demand and validation.
The Problem
- Network configurations are highly sensitive: they reveal architecture, security posture, provider relationships and operational risks.
- Many organizations want security reviews but cannot or do not want to share original configuration data externally.
- Traditional tools often require live access, sensors, long integration projects or extensive customer context.
The PaSBaT Approach
PaSBaT is designed as a privacy-first assessment workflow: configuration snapshots are prepared, anonymized locally and then analyzed in a structured way. The goal is a fast, traceable view of topology, segmentation, security findings and compliance-relevant risks – without active scans and without direct connection to production systems.
- Original data and mappings remain with the customer.
- For the target workflow, PaSBaT only needs anonymized analysis bundles.
- Reports provide technical evidence, prioritization and remediation guidance.
What Makes PaSBaT Different
Customer-side anonymization
The sensitive part of the process happens before analysis, lowering the barrier for confidential assessments.
Structure-preserving evaluation
Anonymization is intended to preserve network relationships so topology, segmentation and policies remain reviewable.
Non-invasive snapshot
No live scans, no agents, no sensor rollout – PaSBaT works with prepared exports.
Audit-oriented results
Findings, evidence and recommendations are consolidated into HTML/PDF reports.
Operating Models
On-Prem Offline Assessment
For highly sensitive environments, analysis can be performed fully offline at the customer site. No data leaves the environment.
Assisted Remote Assessment
The customer anonymizes locally and provides only the anonymized bundle for analysis.
Brokered Blind Assessment
As a target model, a neutral broker can handle payment, identity and handover while PaSBaT only sees tokens and anonymized data.
Who Is It For?
- OT/IT teams with grown brownfield environments
- MSSPs and security service providers that want to scale assessments
- Organizations facing NIS2, TISAX, ISO 27001 or DORA pressure
- Organizations that do not want to share network data directly with third parties
- Training, labs and technical validation using synthetic test networks
What the Report Provides
- Topology and structure overview
- Security findings with evidence and recommendations
- Signals around segmentation, remote access, NTP/Syslog/SNMP, password/VPN/ACL topics
- Compliance-oriented mapping where useful and covered by scope
- Clear limitations: what was checked, what was not and what input quality was available
Honest Limitations
- PaSBaT does not replace a full penetration test or ISMS.
- Result quality depends on completeness and quality of the provided configuration snapshots.
- Vendor support is expanded step by step and must be validated per vendor.
- Legal, tax and data protection operating models will be reviewed separately before platform scaling.
Roadmap
- Vendor framework and expansion beyond Cisco
- Anonymization Validation Report proving that no mapping data is exposed
- Snapshot Request Kit for customers and service providers
- Token/workspace model for repeatable self-service runs
- Partner/broker model for particularly confidential assessments
Start a Pilot or Review
I am looking for pilot partners and technical reviewers to validate PaSBaT against realistic requirements – initially with clear scope, transparency and no production access.