Skip to content

Hardware

OT and ICS
Penetration Testing

SCADA and industrial control system security assessment

Bench testing from $5,200, live-plant work scoped and quoted, fixed scope, free retest. See all pricing →

Get a fixed quote

Reply in one business day

Senior certified testers, manual-first185+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology

When you need it

When an industrial operator needs OT and ICS testing

The situations that bring teams to this engagement, and where it fits alongside the rest of your program.

  • Ransomware that reaches production would stop the line, and nobody has tested whether an intruder who lands in IT can cross into the plant.
  • A customer, insurer, or regulator asked for evidence that the OT environment and its segmentation are tested, not just documented.
  • A controller or HMI is reachable from the corporate network, or from the internet, and you need to know what an attacker could do with it.
  • You are defining IEC 62443 zones and conduits and want the segmentation between enterprise and plant proven before it sets.
  • You build or ship connected industrial equipment and want it tested on the bench before customers put it on their own plant networks, alongside hardware and IoT testing.

Definition

What is OT and ICS penetration testing?

OT and ICS penetration testing is the security testing of operational technology and industrial control systems: the PLCs, HMIs, RTUs, SCADA servers, and engineering workstations that run a physical process, and the network boundary between them and the enterprise. It is not a normal network test. A plant runs protocols with little or no authentication, on devices that cannot be scanned like servers, where an unsafe probe can stop a line or trip a safety system. So the method is different: passive discovery first, testing from the IT side inward, and any active work only in agreed maintenance windows.

Bench and lab testing of a single controller or device starts at $5,200, the same as our hardware and IoT testing. Live-plant and multi-site work is scoped and quoted from the environment, still fixed in writing before anyone starts. The vertical view of this work for a plant owner is on our penetration testing for manufacturers page.

Plant safety

Plant-safe ICS penetration testing, rule by rule

An office network test sends traffic first and asks questions later. A plant cannot take that risk, so every engagement runs under written rules your plant and IT leads approve before the first packet is sent.

Why it protects the process

Written rules of engagement
In-scope and off-limits systems, testing windows, and a named plant contact with the authority to halt testing, all signed off before work begins.
Passive discovery first
Older controllers can misbehave when probed, so the first picture of the plant comes from listening to traffic, not from sending it.
No unsafe scanning of controllers
Office-style sweeps never touch PLCs or safety systems, and denial-of-service techniques are excluded outright.
Agreed maintenance windows
Anything active against plant equipment waits for a window your plant team schedules, when a hiccup cannot cost production.
Bench testing where it fits
A spare controller, HMI, or device on our bench can be pushed much harder than anything on a running line.
IT-side boundary testing
Most of the risk question is answered from the office side of the boundary, where a real intrusion starts and testing cannot touch the process.

Safety instrumented systems are never tested in a way that could affect their function, and the same rules apply to every plant we test, whatever it makes or moves.

What we look for

OT and ICS weaknesses we test for

A plant network was built for reliability, not for adversaries, and much of it speaks protocols with no authentication. We test the way a real intruder would reach it, from the IT side inward, with methods that never put a live process at risk.

IT-to-plant boundary

The route a real intrusion takes: from a phished office account, through Active Directory, to the machines one hop from production.

We test for

  • Firewalls, jump hosts, and the plant DMZ
  • Dual-homed historians and machines that cross the boundary
  • Shared and never-revoked credentials between IT and OT
  • Flat networks where the office reaches the plant directly
  • Paths from the corporate domain to engineering workstations

Controllers, HMIs, and RTUs

The devices that run the process, tested with plant-safe methods so nothing on a live line is ever put at risk.

We test for

  • Default, absent, and shared passwords on PLCs and HMIs
  • Exposed programming and management ports
  • Firmware and configuration weaknesses on a bench unit
  • Unauthenticated control and engineering functions
  • Devices reachable from the internet, the failure behind CISA advisory AA23-335A

SCADA and industrial protocols

The protocols that carry commands between the control room and the plant floor, most of them designed without authentication.

We test for

  • Modbus, DNP3, EtherNet/IP, PROFINET, and OPC exposure
  • Unauthenticated read and write of process values
  • Replay and spoofing of control messages, on a bench or a passive capture
  • Cleartext engineering and configuration traffic
  • Weak or absent protocol-level authentication

Segmentation, zones, and conduits

The finding that matters most for a live plant: whether the boundaries between zones actually hold.

We test for

  • Segmentation between enterprise and plant, against your IEC 62443 zones
  • Conduit controls between zones with different security levels
  • Reachability of controllers from the corporate or guest network
  • VLAN and firewall-rule gaps between zones
  • Vendor and integrator remote-access paths into the plant

Vendor and remote access

The support tools OEMs and integrators use to reach the plant, a standing route that often skips the controls the rest of the network has.

We test for

  • Standing and shared vendor accounts
  • Remote-support tools with direct plant reach
  • Missing multi-factor authentication on remote access
  • Jump-host and VPN scope into OT
  • Third-party access that was never removed

Standards

IEC 62443, NIST SP 800-82, and MITRE ATT&CK for ICS

OT testing is anchored to the recognized standards. ISA/IEC 62443 is the consensus-based series for industrial automation and control systems; it models the plant as zones (groups of assets that share security requirements) connected by conduits (the controlled communication channels between them), and the segmentation testing in this engagement is measured against the zones you have defined. NIST SP 800-82 Rev. 3, the "Guide to Operational Technology (OT) Security" (September 2023), covers the same ground for control, building-automation, and transportation systems.

Attacker behavior is mapped to MITRE ATT&CK for ICS, whose tactics run from Initial Access through Lateral Movement to Inhibit Response Function and Impair Process Control, so your defenders can replay the timeline against their monitoring. NERC CIP is out of scope; where an electric-utility client needs it, we say so up front and scope only the OT testing we can deliver.

Sectors

Who needs OT and SCADA security testing

Any operator whose network drives a physical process has an IT-to-plant boundary worth testing. These are the operators who ask for it most.

Manufacturing

Plant networks, PLCs and HMIs, and the IT-to-plant boundary ransomware operators use to reach production. See penetration testing for manufacturers.

Water and building automation

Water and wastewater controls, where internet-exposed PLCs with default or no passwords were the failure CISA described in advisory AA23-335A, and building-automation systems that often share the corporate network.

Terminals and logistics

Port, terminal, and warehouse control systems, and the segmentation between the operational floor and the corporate network that runs orders and billing. See logistics cybersecurity and penetration testing.

For the corporate side of any of these, the internal network test and an Active Directory security assessment cover the office network the plant so often shares with IT.

Methodology

OT and ICS penetration testing methodology

Full methodology →

Every engagement follows the Penetration Testing Execution Standard and the relevant OWASP guides.

These are the phases your OT and ICS penetration testing runs through.

  1. 01

    Scope & safety plan

    The zones, sites, and devices in play, the fixed price, and the written rules that protect the process, agreed with your plant and IT leads.

  2. 02

    Asset & traffic map

    A picture of what is on the plant network and who talks to whom, built from listening, compared with your own asset list and zone drawings.

  3. 03

    IT-to-plant paths

    Every route from an office foothold toward the engineering workstations and controllers, traced and proven where the rules allow.

  4. 04

    Zone & device testing

    Conduit controls between zones checked against your IEC 62443 design, and device-level work on a spare unit or in an agreed window.

  5. 05

    Report & re-check

    Findings mapped to IEC 62443 and MITRE ATT&CK for ICS, a segmentation plan, and a free re-check of the fixes.

How it works

How your engagement runs

From scope through the final retest, your team stays in the loop at every step, with findings tracked live in our platform.

  1. 01

    Scope & kickoff

    Targets, roles, and rules of engagement defined in writing, with a fixed scope and timeline.

  2. 02

    Testing goes live

    Findings post to your live platform dashboard the moment our testers confirm them.

  3. 03

    Track remediation

    Follow every finding from open to fixed, with severity, evidence, and status in one place.

  4. 04

    Report & retest

    Executive and technical reports land, then request a free retest in one click.

Proof

Proof in the field

Every engagement is confidential, so the work below is anonymized to sector and engagement type.

All case studies →

Free

Retest on every penetration test

185+

Years combined experience

14

Senior in-house specialists

24h

Onboarding after signing

Fintech · Payments

Web Application Penetration Test

High risk

Critical: a remote code execution flaw in the application’s web framework that could have given an attacker full control of the server. We escalated it to the development team while the test was still running.

Outcome. The critical RCE was reported and remediated during the engagement via an emergency framework upgrade, which also closed the server-side request forgery, and the remaining findings were retested to confirmation.

1

Critical (RCE)

Mid-test

Critical remediated

2

High

Read the case study

HR & Payroll SaaS

Web Application Penetration Test

High risk

Critical: a file-inclusion flaw that let an attacker read sensitive files from the server through the application itself. High: stored cross-site scripting capable of session theft, insecure direct object references, and an authorization bypass that let an administrator create or delete organization owners.

Outcome. Delivered a remediation plan sequenced by real business impact, critical and high findings first, with a complimentary retest to verify every fix.

28

Findings

1

Critical

5

High

Read the case study

FAQ

Frequently asked questions

What teams most often ask before scoping OT and ICS penetration testing.

Still have questions? 
01What is OT and ICS penetration testing?

It is the security testing of the systems that run a physical process: PLCs, HMIs, RTUs, SCADA servers, and engineering workstations, plus the network boundary between the plant and the enterprise. Because a plant runs low-authentication protocols on devices that cannot be scanned like servers, the method is plant-safe: passive discovery first, testing from the IT side inward, and any active work only in agreed maintenance windows. It is mapped to IEC 62443 and MITRE ATT&CK for ICS.

02Will testing disrupt production?

It should not, and we plan it so it does not. Rules of engagement are agreed with your plant and IT leads before testing starts, a plant contact can stop work at any time, controllers are never swept with office-network scans, and denial-of-service techniques are never used. Most of the work is passive listening and IT-side boundary testing. Anything active against plant equipment runs only in a window your team approves.

03Do you test live PLCs and HMIs, or only on a bench?

Both, and we prefer the bench where a spare unit exists. Device-level testing of an individual controller, HMI, or RTU runs on our bench from $5,200, the hardware testing price. Live-plant testing is done on site under plant-safe rules, with passive discovery first and active steps only in agreed maintenance windows, and it is scoped and quoted per site. We never test a safety instrumented system in a way that could affect its function.

04How much does OT and ICS penetration testing cost?

Bench or lab testing of a single controller or device starts at $5,200, fixed before work begins, with a free re-check. Live-plant and multi-site work is scoped and quoted from the environment, and the price is still fixed in writing before testing starts. A typical first engagement is the IT-to-plant boundary and segmentation, tested from the corporate side, often alongside an internal network test. Starting prices for every service are on our pricing page.

05Which standards do you test against?

ISA/IEC 62443 for zones, conduits, and security levels; NIST SP 800-82 Rev. 3, the Guide to Operational Technology (OT) Security; and MITRE ATT&CK for ICS for the attacker behavior. Segmentation is measured against the zones you have defined. NERC CIP is out of scope, and we say so up front where an electric-utility client needs it.

06Do you come on site?

For live-plant work, yes. Plants in the New York metro are a short trip from our Manhattan office, and sites elsewhere are served on site by arrangement with the travel agreed up front. The IT-side boundary testing runs through a small device we ship, and device testing happens on our bench, so much of the engagement needs no visit at all.

07Can you test the connected equipment we build?

Yes. Industrial equipment you build and ship is tested on the bench at the firmware, debug-port, radio, and protocol layers, so a flaw is fixed before customers put the device on their own plant networks. That work is our hardware and IoT testing, from $5,200 for a small device, and it maps to the IEC 62443 component requirements (62443-4-2) that product makers build to.

Ready to test your defenses?

Talk to our team about scoping OT and ICS penetration testing.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.