OT / ICS Penetration Testing
05 — OT / ICS PENTEST

OT / ICS Penetration Testing

SCADA, PLCs, HMIs, safety systems. Industrial control environments carry physical consequences — production downtime, equipment damage, safety risk. Our methodology offers grey box and white box approaches built for this reality.

What Is OT / ICS Penetration Testing?

Operational Technology (OT) and Industrial Control Systems (ICS) penetration testing evaluates the security of systems that control physical processes — manufacturing lines, power grids, water treatment plants, building management systems. Unlike standard IT environments, OT systems carry physical safety consequences. A successful attack can halt production, damage equipment, or endanger human life.

This requires a fundamentally different approach. Traditional pentesting techniques can crash fragile OT protocols. Our methodology is informed by IEC 62443, designed specifically for industrial environments, and prioritises safety above all else.

Scope of an OT / ICS Pentest

The systems that keep the physical world running.

SCADA Systems

Supervisory Control and Data Acquisition systems — the central monitoring and control platforms. HMI vulnerabilities, historian database exposure, engineering workstation weaknesses, and communication protocol analysis.

PLCs & RTUs

Programmable Logic Controllers and Remote Terminal Units. Firmware analysis, authentication weaknesses, ladder logic manipulation potential, and the embedded services that could allow an attacker to alter physical processes.

HMIs

Human-Machine Interfaces — the operator screens used to monitor and control physical processes. Authentication bypass, default credentials, software vulnerabilities, and the potential for unauthorised control commands.

Network Segmentation

The boundary between IT and OT networks. Purdue model validation, firewall rule analysis, DMZ testing, and verification that a compromise in the corporate network cannot reach operational systems.

Safety Systems

Safety Instrumented Systems (SIS) evaluation. We assess whether safety-critical systems can be reached, disabled, or manipulated through cyber means — without touching them destructively.

Industrial Protocols

Modbus, DNP3, OPC DA/UA, Profinet, EtherNet/IP, IEC 61850. These protocols were designed for reliability, not security. We test for replay, spoofing, and manipulation attacks specific to industrial communications.

Testing Approaches

Two methodologies designed for operational environments.

Grey Box

Passive reconnaissance and non-intrusive assessment. Architecture and topology review, protocol identification, traffic capture, and configuration analysis without sending packets that could disrupt physical processes. Asset inventory validation, exposed service identification, and documentation of the IT/OT boundary. Based on the Yinson project reference: suitable for environments where production continuity is non-negotiable.

Best for: Operational OT environments where active testing carries physical risk.

White Box

Full transparency assessment similar to a Security Architecture Review. Detailed configuration review of PLCs, HMIs, engineering workstations, and network devices. IEC 62443 zone and conduit validation. Patch level analysis, firmware review, and protocol-level deep dive against staging replicas where available.

Includes: OT Security Architecture Review aligned to IEC 62443 and Purdue model.

Best for: Pre-commissioning assessments, compliance-driven engagements, environments with test/staging systems.

Our Approach

Different from standard IT pentesting. Safety comes first.

01

Safe Reconnaissance

Passive information gathering, architecture review, asset inventory validation, and protocol identification. We map the environment without sending traffic that could disrupt physical processes.

02

Risk-Based Identification

Vulnerability discovery using OT-safe methodologies. Configuration review, protocol analysis, and architecture evaluation. We prioritise findings that could impact safety or production availability.

03

Controlled Assessment

Active testing conducted in coordination with operations teams. Exploitation attempts are performed against staging environments or during maintenance windows, never against live production processes.

04

Operational Reporting

Findings framed in operational impact terms — not just CVSS scores. We translate technical vulnerabilities into business language: production downtime, safety risk, regulatory consequences.

Our Technical Expertise

Where IT security meets operational reality.

IEC 62443 Framework

The international standard for industrial automation and control systems security. We assess zones and conduits, security levels (SL-T, SL-C, SL-A), and the requirements for each component in the architecture.

OT-Safe Testing

We understand that a crashed PLC means a halted production line. Our testing methodology avoids destructive techniques against live systems, using passive enumeration, staging replicas, and controlled assessment windows.

Purdue Model Expertise

We evaluate segmentation against the Purdue Enterprise Reference Architecture — the standard model for IT/OT network hierarchy. Level 0 through Level 5, every boundary tested.

Physical Impact Analysis

Our reports don't just say "vulnerability found." We explain what could happen in the physical world if exploited — process disruption, equipment damage, safety system compromise, environmental release.

Specialised OT / ICS Assessments

Sub-services under the OT / ICS practice.

EV Charger Pentest

Charging stations, CSMS backend, OCPP protocol testing, payment systems, and grid integration. ISO 15118 and IEC 62443 aligned.

Learn more ›

Medical Device Pentest (MDOT)

Connected medical devices, clinical networks, embedded firmware, and wireless protocols. FDA premarket and IEC 81001-5-1 aligned.

Learn more ›

Request an OT / ICS Pentest

Tell us about your industrial environment. We'll scope a safe, controlled engagement.

Get in Touch