Services / OT & ICS Security

When Systems
Fail,
People Get Hurt

OT and ICS environments weren't designed with cyber threats in mind. We assess your industrial infrastructure — SCADA, PLCs, HMIs, and field devices — without disrupting a single process, finding the vulnerabilities before an adversary does.

Industries served ▸ Power & Energy 🏭Manufacturing 💧Water & Utilities 🛢️Oil & Gas 💊Pharmaceuticals 🚂Transport & Rail 🏗️Building Automation
what we assess

OT Attack Surface

Every assessment covers the full OT stack — from field devices and PLCs up through SCADA servers, historian databases, and IT/OT boundary weaknesses.

Field Layer CRITICAL
🔧
PLC & RTU Security

Review of Programmable Logic Controllers and Remote Terminal Units for default credentials, unauthenticated programming ports, firmware vulnerabilities, and unencrypted ladder logic exposure.

Modbus TCPDNP3IEC 60870EtherNet/IP
Supervisory Layer CRITICAL
🖥️
SCADA & HMI Systems

Assessment of SCADA servers and HMI workstations — unpatched OS, weak authentication, insecure remote access (RDP/VNC), historian database exposure, and operator screen injection.

OPC-UAOPC-DAWonderwareiFIX
Network Layer CRITICAL
🔗
IT / OT Boundary

Analysis of DMZ architecture, firewall rule-sets, jump server configurations, data diode implementations, and network segmentation — identifying lateral movement paths from IT to OT networks.

Purdue ModelIEC 62443NERC CIP
Protocol Layer HIGH
📡
Industrial Protocol Analysis

Passive and active analysis of industrial protocols for authentication weaknesses, replay attack exposure, man-in-the-middle vulnerabilities, and unauthenticated command injection risks.

PROFINETBACnetS7commHART-IP
Remote Access HIGH
🌐
Remote Connectivity

Review of vendor remote access channels, cellular modems, VPN configurations, and cloud-connected IIoT gateways — the most common initial access vectors into OT environments.

VPNRDPTeamViewer4G/LTE Modem
Asset Inventory MEDIUM
📋
Asset Discovery & Inventory

Passive network monitoring to build a complete OT asset inventory — identifying rogue devices, unmanaged PLCs, and shadow OT assets that security teams don't know exist on the network.

Passive ScanSPAN PortAsset Registry
assessment coverage

Purdue Model Coverage

We assess every level of the Purdue Reference Model — with non-disruptive passive techniques used at levels 0–2 to protect live operations.

L4
Enterprise Zone
Business & Enterprise Network

ERP, MES, corporate IT — entry point for most OT breaches via spear-phishing and supply chain compromise.

ACTIVE TESTING
L3
Operations Zone
Site Operations & Historian

Production scheduling, historian servers, data aggregation — the bridge between corporate and control networks.

ACTIVE TESTING
DMZ
Demilitarised Zone
IT/OT Boundary & Firewalls

Data diodes, firewalls, jump servers — the critical boundary that separates IT from OT. Misconfigurations here are catastrophic.

ACTIVE TESTING
L2
Control Zone
SCADA, HMI & DCS

Supervisory systems — SCADA servers, HMI workstations, DCS engineering stations operating the physical processes.

PASSIVE + SAFE ACTIVE
L1
Control Zone
PLCs, RTUs & Control Devices

Field controllers executing real-time process logic — disruption here means physical process failure with potential safety consequences.

PASSIVE MONITORING
L0
Field Zone
Sensors, Actuators & Field Devices

Physical instrumentation — temperature sensors, pressure valves, motor drives. Compromise here directly affects physical safety.

PASSIVE ONLY
how we work

Engagement Methodology

Every OT assessment is designed around one non-negotiable constraint — operational continuity. We find critical vulnerabilities without taking systems offline.

// Phase 01 SAFE

OT Environment Scoping

Collect network diagrams, asset lists, and vendor documentation. Define safety-critical systems that require passive-only testing. Agree rules of engagement and emergency contact escalation procedures with operations staff.

// Phase 02 PASSIVE

Passive Network Monitoring

Deploy a SPAN port capture or TAP to passively monitor OT network traffic. Identify all communicating assets, protocols in use, unencrypted command traffic, and anomalous communications — zero impact on operations.

// Phase 03 SAFE

Architecture & Configuration Review

Manual review of SCADA/HMI configurations, PLC ladder logic (offline), firewall rule-sets, remote access configurations, and patch status — identifying critical vulnerabilities from documentation alone.

// Phase 04 CONTROLLED

IT/OT Boundary Testing

Active penetration testing of IT networks with controlled lateral movement attempts toward OT network boundaries — assessing whether an IT compromise can pivot into OT systems via DMZ weaknesses.

// Phase 05 PROTOCOL

Industrial Protocol Assessment

Controlled analysis of industrial protocol implementations — checking for unauthenticated read/write access to Modbus registers, DNP3 replay vulnerabilities, OPC-UA trust misconfigurations, and BACnet enumeration exposure.

// Phase 06 SAFE

Reporting & Remediation

Detailed findings report with IEC 62443 and NERC CIP mapping, risk-rated vulnerabilities, and operationally-aware remediation guidance that accounts for patching constraints in live OT environments.

tools & frameworks

Tools Used

OT-safe tooling combined with passive monitoring frameworks — nothing that can cause process disruption is used without explicit written authorisation.

Claroty Dragos Platform Nozomi Networks Wireshark Zeek (Bro) S7Scan ModbusPal DNP3 Analyser PLCScan Redpoint (Nmap NSE) Metasploit ICS Modules Shodan (pre-engagement) GRASSMARLIN OPC Scout Profitap TAP IEC 62443 Framework NERC CIP Controls NIST SP 800-82
what you receive

What You Get

OT Risk Report

OT Risk Assessment Report

Comprehensive findings report covering every assessed layer — from field device exposure to IT/OT boundary weaknesses — with CVSS scores, attack path diagrams, and operational risk impact ratings.

Asset Inventory

Complete OT Asset Inventory

A full inventory of every discovered OT asset — PLCs, RTUs, HMIs, field devices, and communication paths — many of which organisations discover for the first time during an assessment.

IEC 62443 Gap Analysis

IEC 62443 & NERC CIP Mapping

Findings mapped to IEC 62443 Security Levels and NERC CIP requirements — with a gap analysis showing current vs target Security Level for each OT zone and conduit.

Network Architecture Review

Network Segmentation Report

Annotated network diagrams showing actual traffic flows, identified flat-network risks, IT/OT bridging points, and recommended segmentation improvements with implementation guidance.

Remediation Roadmap

Operationally-Aware Roadmap

A prioritised remediation plan that accounts for OT patching constraints, maintenance windows, and operational availability requirements — so fixes don't create new operational risks.

Compliance Certificate

Compliance Certificate

Signed assessment certificate mapped to IEC 62443, NERC CIP, NIST SP 800-82, and sector-specific regulatory requirements — for use with insurers, regulators, and critical infrastructure bodies.

Non-disruptive. Operationally safe.

Your Facility Keeps
Running. We Find
Every Weakness.

OT security assessments require a different approach — one that respects operational constraints while finding vulnerabilities that could shut down production or cause physical harm. That's exactly what we do.