Offensive security for industrial and OT environments.
On the factory floor the risk is not a data leak: it is a stopped line, a lost batch and the safety of people. We test the IT/OT boundary on the premise that production cannot stop.
The boundary that became the weak point
For decades the industrial environment was protected by physical isolation. That separation has effectively disappeared: vendor remote maintenance, data collection for production metrics and ERP integration have opened permanent paths between the corporate network and the plant floor. Attackers almost never enter through the controller — they enter through the office and walk to it.
- Vendor remote access tends to be permanent, broad and lightly monitored.
- Industrial controllers were designed for reliability, not for authentication.
- Maintenance windows for patching are rare and contested against production.
- An incident can have physical consequences, not only financial or reputational ones.
What we test in an industrial environment
The focus is the path between the administrative world and the world that controls machinery — and how narrow it really is.
We test whether the network layers genuinely isolate: what a foothold in the corporate environment reaches towards the control zone.
Maintenance tunnels, jump hosts and integrator shared credentials — a recurring vector and the most frequently underestimated one.
Operator stations and supervisory servers: authentication, patching, interface exposure and the integrity of what the operator is shown.
Data flow from the plant floor to ERP and dashboards, including connectors that cross the boundary in both directions.
Coverage, authentication and isolation of networks used by handhelds, forklifts and mobile devices inside the plant.
Shared administrative accounts, access control to technical rooms and doors that lead straight to equipment.
Technical reference and legal duty
We use references specific to industrial environments, not only the corporate IT framework.
- IEC 62443
- We work with the zones and conduits model, the consolidated reference for segmenting automation environments, and report findings in that vocabulary.
- Safety of people
- Any finding capable of affecting a safety instrumented system is handled separately, communicated immediately, outside the normal reporting flow.
- NIS2 for manufacturing
- Manufacturing and energy operators fall within scope for risk management and supply chain security duties. Findings are framed against them.
- Operational continuity
- We translate technical findings into downtime and batch loss risk, the language in which industrial leadership decides on investment.
How we run without stopping production
Ground rule agreed up front
Nothing that directly touches a controller or a safety instrumented system undergoes active testing. This is agreed in writing before any activity begins.
Attack from the IT side
The engagement normally starts in the corporate environment and measures how far we advance towards OT. That is the real scenario in most incidents.
Passive observation inside OT
Within the control zone we favour passive analysis and configuration review, without injecting traffic that could confuse a controller.
Remediation fit to maintenance
The plan separates what can be fixed without stopping the line from what needs a maintenance window, so recommendations are actually executable.
What you receive
- Executive report in downtime risk
- Reproducible technical report
- Map of observed zones and conduits
- Vendor remote access analysis
- Justified CVSS scoring
- Remediation plan by maintenance window
- Retest of remediated findings
- Attestation letter for the engagement
Sector FAQ
Is there a risk that testing stops the production line?
+
The engagement is designed so that there is not. Controllers and safety instrumented systems are excluded from active testing by rule, agreed in writing before we start. Inside the control zone we use passive analysis and configuration review. Active testing happens on the corporate side, which is where the real attack begins.
Do you test PLCs and SCADA directly?
+
Not directly and not aggressively. We assess exposure, authentication, versions and segmentation, and demonstrate the reach an attacker would have from the point we obtained. Where a lab or replica exists, we do go deeper with active testing, because there is no risk of physical consequence.
Is our integrators' remote access in scope?
+
It is, and we strongly recommend including it. It is the most frequent vector and the least reviewed: permanent tunnels, credentials shared between technicians and permissions far broader than maintenance requires. It usually produces the highest-impact findings of the engagement.
How do you report risk to industrial leadership?
+
In operational language. The executive report translates technical findings into downtime risk, batch loss and impact on people's safety, with a remediation plan separated by whether a maintenance window is required. The detailed technical layer goes in its own document.
Services applied to this sector
Ready to uncover your flaws?
First scoping call is free and covered by NDA. Within 48 hours you receive technical proposal, scope and timeline. No bureaucratic forms.