Basilisk
BASILISK
[setor_industria_ot]INDUSTRIAL & OT

Offensive security for industrial and OT environments.

On the factory floor the risk is not a data leak: it is a stopped line, a lost batch and the safety of people. We test the IT/OT boundary on the premise that production cannot stop.

The boundary that became the weak point

For decades the industrial environment was protected by physical isolation. That separation has effectively disappeared: vendor remote maintenance, data collection for production metrics and ERP integration have opened permanent paths between the corporate network and the plant floor. Attackers almost never enter through the controller — they enter through the office and walk to it.

  • Vendor remote access tends to be permanent, broad and lightly monitored.
  • Industrial controllers were designed for reliability, not for authentication.
  • Maintenance windows for patching are rare and contested against production.
  • An incident can have physical consequences, not only financial or reputational ones.

What we test in an industrial environment

The focus is the path between the administrative world and the world that controls machinery — and how narrow it really is.

// IT/OT segmentation

We test whether the network layers genuinely isolate: what a foothold in the corporate environment reaches towards the control zone.

// vendor remote access

Maintenance tunnels, jump hosts and integrator shared credentials — a recurring vector and the most frequently underestimated one.

// supervisory systems

Operator stations and supervisory servers: authentication, patching, interface exposure and the integrity of what the operator is shown.

// historians and integration

Data flow from the plant floor to ERP and dashboards, including connectors that cross the boundary in both directions.

// industrial wireless

Coverage, authentication and isolation of networks used by handhelds, forklifts and mobile devices inside the plant.

// identity and physical access

Shared administrative accounts, access control to technical rooms and doors that lead straight to equipment.

Technical reference and legal duty

We use references specific to industrial environments, not only the corporate IT framework.

IEC 62443
We work with the zones and conduits model, the consolidated reference for segmenting automation environments, and report findings in that vocabulary.
Safety of people
Any finding capable of affecting a safety instrumented system is handled separately, communicated immediately, outside the normal reporting flow.
NIS2 for manufacturing
Manufacturing and energy operators fall within scope for risk management and supply chain security duties. Findings are framed against them.
Operational continuity
We translate technical findings into downtime and batch loss risk, the language in which industrial leadership decides on investment.

How we run without stopping production

01

Ground rule agreed up front

Nothing that directly touches a controller or a safety instrumented system undergoes active testing. This is agreed in writing before any activity begins.

02

Attack from the IT side

The engagement normally starts in the corporate environment and measures how far we advance towards OT. That is the real scenario in most incidents.

03

Passive observation inside OT

Within the control zone we favour passive analysis and configuration review, without injecting traffic that could confuse a controller.

04

Remediation fit to maintenance

The plan separates what can be fixed without stopping the line from what needs a maintenance window, so recommendations are actually executable.

What you receive

  • Executive report in downtime risk
  • Reproducible technical report
  • Map of observed zones and conduits
  • Vendor remote access analysis
  • Justified CVSS scoring
  • Remediation plan by maintenance window
  • Retest of remediated findings
  • Attestation letter for the engagement

Sector FAQ

Is there a risk that testing stops the production line?

+

The engagement is designed so that there is not. Controllers and safety instrumented systems are excluded from active testing by rule, agreed in writing before we start. Inside the control zone we use passive analysis and configuration review. Active testing happens on the corporate side, which is where the real attack begins.

Do you test PLCs and SCADA directly?

+

Not directly and not aggressively. We assess exposure, authentication, versions and segmentation, and demonstrate the reach an attacker would have from the point we obtained. Where a lab or replica exists, we do go deeper with active testing, because there is no risk of physical consequence.

Is our integrators' remote access in scope?

+

It is, and we strongly recommend including it. It is the most frequent vector and the least reviewed: permanent tunnels, credentials shared between technicians and permissions far broader than maintenance requires. It usually produces the highest-impact findings of the engagement.

How do you report risk to industrial leadership?

+

In operational language. The executive report translates technical findings into downtime risk, batch loss and impact on people's safety, with a remediation plan separated by whether a maintenance window is required. The detailed technical layer goes in its own document.

Services applied to this sector

// contact

Ready to uncover your flaws?

First scoping call is free and covered by NDA. Within 48 hours you receive technical proposal, scope and timeline. No bureaucratic forms.