Skip to content

Cybersecurity for manufacturing

Penetration Testing for Manufacturers

Manufacturers run production, ERP, and supplier connections on networks where an hour of downtime means lost output. Invadel tests the corporate network, the IT and plant boundary, PLCs and HMIs with plant-safe methods, and connected products at a fixed price, with a fixed scope and a free retest.

Senior certified testers, manual-first185+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology
LatentPerygeeCity National BankAubaDesteiaDTCC

The stakes

Why manufacturers get tested differently

Attackers go after manufacturers for leverage. Ransomware that reaches production stops the line, and a stopped line pushes owners to pay fast. The FBI’s 2025 Internet Crime Report names critical manufacturing among the critical infrastructure sectors most affected by ransomware. The usual path starts in IT: a phished account, an exposed VPN, or a vendor’s remote access tool. From there it runs through Active Directory to the engineering workstations one hop from production.

The pressure to test comes from customers, insurers, and the defense supply chain. Large customers send supplier security questionnaires before they renew a contract. Cyber insurers ask about remote access, backups, and testing at renewal. Defense suppliers that handle controlled unclassified information need CMMC Level 2, which checks the 110 security requirements of NIST SP 800-171. Since the July 2026 suspension of Phase 2, new DoD solicitations can require only a Level 1 or Level 2 self-assessment.

A generic test either stops at the corporate network or scans the plant like an office and puts a controller at risk. Neither answers the owner’s real question: can an attacker who lands in IT reach production, and what could they do there? Plant testing needs testers who know that PLCs and HMIs cannot be scanned like servers, that discovery starts passively, and that some fixes wait for the next maintenance window.

What we test

The systems attackers go after first

01

Corporate network and Active Directory

The office network, file servers, and the domain most plants share with IT, tested from an assumed foothold for the paths ransomware operators use to reach production.

02

The IT and plant boundary

Firewalls, jump hosts, historians, and the plant DMZ between IT and OT, tested for open routes, shared credentials, and dual-homed machines that cross the line.

03

PLCs, HMIs, and engineering workstations

Controllers, operator panels, and the workstations that program them, tested on the live plant with passive discovery first and active steps only in agreed maintenance windows.

04

Vendor and integrator remote access

The remote support tools OEMs and integrators use to reach HMIs and engineering workstations, reviewed for standing access, shared accounts, and missing multi-factor authentication.

05

ERP, MES, and supplier portals

The systems holding orders, recipes, and drawings, and the portals customers and suppliers log into, tested for authorization gaps and routes into the plant network.

06

Connected products

The equipment and devices you build and ship, tested at the firmware, debug port, radio, and cloud API layers before customers connect them to their own plants.

Compliance

The frameworks that usually apply

  • CMMC Level 2

    External and internal testing of the CUI enclave boundary for defense suppliers, with findings mapped to NIST SP 800-171 for a self-assessment or a C3PAO assessment.

  • NIST SP 800-171

    The 110 requirements behind DFARS 252.204-7012 and CMMC Level 2, including periodic assessment of controls (3.12.1) and vulnerability scanning (3.11.2).

  • IEC 62443

    Zone and conduit segmentation between the plant and the enterprise network, tested against the zones you defined, plus device testing for product makers.

  • Cyber insurance

    Renewal applications ask about remote access, MFA, backups, and whether anyone has tested your controls in the last year. The attestation letter backs up the answers.

Services

What manufacturers usually buy

Plant safety

How we test a live plant without stopping it

Plant testing follows written rules agreed with your plant and IT leads before anything starts. These are the rules we work to on every plant engagement.

Written rules of engagement

What it means on your plant
Systems in scope, systems off limits, systems handled with care, testing windows, and a plant contact who can stop work at any time, all agreed in writing before testing starts.

Passive discovery first

What it means on your plant
We map plant assets and traffic by listening on the network before anything is sent to a controller or HMI.

Agreed maintenance windows

What it means on your plant
Any active step against plant equipment runs only in a window agreed with your plant team.

No unsafe scanning of controllers

What it means on your plant
PLCs and safety systems are never swept with the scans used on office networks, and denial-of-service techniques are never used.

Bench testing where it fits

What it means on your plant
When a spare controller, HMI, or device is available, device-level testing runs on our bench instead of the line.

IT-side boundary testing

What it means on your plant
The route from the corporate network into the plant is tested from the IT side, the way an intruder who lands in the office would travel.

How it runs

Typical engagements

Illustrative scopes for this industry, written to show what a test covers and what you walk away with. They are not client stories; our anonymized engagements are on the case studies page.

Typical engagement

Manufacturer testing its ransomware exposure

A mid-sized manufacturer wants to know whether ransomware that lands in the office could stop the line. We run an internal test from a standard user workstation, escalate through Active Directory, and map every route from IT into the plant network, such as a shared engineering account, a dual-homed historian, or a vendor jump host. The owner receives the routes ranked by what they would stop, a segmentation plan, and a free retest once the fixes are in.

Typical engagement

Defense supplier before its CMMC assessment

A machine shop supplying a defense prime handles controlled unclassified information and is preparing for its CMMC Level 2 assessment. We test the external boundary, then the CUI enclave from an assumed foothold on the corporate network, and check whether drawings marked as CUI sit on file shares outside it. Findings map to the NIST SP 800-171 requirements they touch, so they feed the System Security Plan and POA&M, and the retest documents the fixes before assessment day.

Typical engagement

Equipment maker adding remote monitoring

An equipment maker adding remote monitoring to its product line wants the device tested before customers connect it to their plants. We extract and analyze the firmware, test the debug ports and the radio, and test the cloud API and the companion app the device reports to. A credential shared across the fleet is found and fixed before production. The report goes to engineering and supports the answers the maker gives customers’ security teams.

FAQ

What manufacturers ask

01Will penetration testing disrupt production?

It should not, and we plan it so it does not. Rules of engagement are agreed with your plant and IT leads before testing starts, a plant contact can stop work at any time, and we never use denial-of-service techniques. The disruption worth planning for is the unplanned kind: our ransomware statistics collect the sourced numbers, including the FBI’s sector data. A ransomware readiness assessment, from $6,000, tests whether an intruder who lands in the office could reach the line and whether your backups would survive.

02Do you test PLCs and HMIs on a live plant?

Yes. We test live plant networks, including PLCs, HMIs, and engineering workstations, with plant-safe OT and ICS penetration testing: passive discovery first, active steps only in agreed maintenance windows, and no unsafe active scanning of controllers. Where a spare unit exists, we test it on our bench instead. Device-level work is covered by hardware penetration testing, from $5,200 for a small device.

03We supply the Department of Defense. Does CMMC Level 2 require a penetration test?

Level 2 does not name penetration testing among its 110 practices, but it requires you to assess your controls periodically and to scan for vulnerabilities, and a penetration test is the strongest evidence that the controls work. We test the CUI enclave boundary from outside and from an assumed foothold inside, and map findings to NIST SP 800-171. See CMMC Level 2 penetration testing, and our CMMC Level 2 requirements checklist for all 110 requirements by family.

04How much does penetration testing cost for a manufacturer?

External network testing starts at $4,200, internal network testing at $6,000, hardware testing at $5,200 for a small device, and a phishing campaign at $3,600. Each price is fixed in writing before work starts, and the penetration tests include a free retest of remediated findings. Live plant testing is scoped per site and quoted in writing. A typical first engagement is an internal test that covers the IT and plant boundary, often with a phishing campaign aimed at the staff who handle supplier invoices. Where the plant shares a domain with the office, an Active Directory security assessment from $6,000 shows whether one compromised office account can reach Domain Admin, and with it the plant systems joined to that domain.

05Do you come on site, or can you test remotely?

Both. External, application, and cloud testing run remotely. Internal testing, including the IT side of the plant boundary, runs through a small device we ship to your site. Live plant testing is done on site: plants in the New York metro are a short trip from our Manhattan office, and sites elsewhere are served on site by arrangement.

06Have you tested manufacturers before?

Yes. Our customers page includes an anonymized industrial operator, with a segmentation review and OT-adjacent network testing across plant systems. On the same page you can ask for a reference in your sector.

Get a fixed price for your plant and network scope

Tell us what needs testing. You get a written fixed price within one business day, with the compliance mapping your auditors and customers expect.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.