Manufacturing & Machine Building · NIS2 & IEC 62443

Sometimes all it takes
is a USB stick on a desk

As part of the manufacturing sector, you fall under NIS2 as an "important entity" once you pass 50 employees or 10 million EUR in annual revenue. In practice, the technical benchmark for that is IEC 62443, backed up by the BSI's ICS Security Compendium. We test exactly where IT meets production: PLCs and SCADA systems, remote-maintenance access, and the factory floor itself, without putting your production at risk in the process.

Example scenario Break room · 06:52 · early shift
Testing methodology aligned with IEC 62443 Experience with OT/ICS & production environments Free initial consultation
How common real incidents are
24%

Roughly one in four companies in mechanical and plant engineering reported a significant cybersecurity incident within the past two years.

Source: VDMA study "Industrial Security und Produktpiraterie 2024," Fraunhofer AISEC, 100 surveyed VDMA member companies

A scenario from real assessments

The story in five steps

Media dropping is an established social-engineering technique we run in a controlled form at accessgranted on a regular basis. Not a specific incident at a specific customer, just a typical sequence that shows how little it can take.

The stickBreak room

A prepared USB stick turns up, apparently by chance, in the break room or at goods receiving

Placed unobtrusively, often carrying a company logo or a label designed to spark curiosity.

The clickOffice workstation

An employee plugs it into a company computer, out of curiosity

Out of curiosity, a wish to be helpful ("maybe it belongs to someone"), or plain habit, with no bad intent at all.

The first footholdOffice network

Without network segmentation, that's enough for a first foothold in your internal network

From there, the real assessment checks how far that access could be pushed toward the production network.

From office IT to the shop floorProduction network

Where IT and OT aren't cleanly separated, the path leads straight on to the controllers

Without segmentation between office IT and the production network, PLCs, control systems, and the machine vendor's remote-maintenance access are all reachable from the compromised workstation. We document that path rather than walking it to the end: on OT-adjacent systems we work passively, and actively only in pre-agreed time windows.

The report on the tableMeeting room · a few weeks later

What ends up on the table isn't an incident, it's a report

Every finding rated by severity, exploitability, and potential impact on production, with a management summary for executive, IT, and plant leadership and a mapping to NIS2 and IEC 62443. This is what an excerpt can look like:

Manufacturing pentest report · Sample excerptSample
USB-drop test: 3 out of 10 planted sticks were plugged in (example figure)
Awareness & endpoint control
No network segmentation between office IT and the production network
IT/OT segmentation
Remote-maintenance VPN for a machine vendor reachable without multi-factor authentication
Remote-maintenance access
PLC firmware left unpatched for years across multiple lines
Patch & firmware management
Tailgating: entry into the production hall possible without a badge check (example figure)
Physical access control
Industrial device reachable with factory-default credentials
Credential hardening
6 findings · remediation plan includedMapped to NIS2 & IEC 62443
Illustrative example – no real customer data.
We measure how high the pickup rate actually is at your company, and whether missing segmentation turns that into more than a footnote.
Manufacturing's attack surface

Where things really go wrong on the shop floor

Production environments pair decades-old control technology with modern IT, usually without both sides sharing the same security culture.

Technology

OT/SCADA & control systems

PLCs, control systems, and fieldbuses are often built for uptime rather than security, and can run for years without a patch.

Industrial IoT (IIoT)

Sensors and networked machines widen the attack surface, frequently still on factory-default settings nobody ever changed.

Remote-maintenance access

Machine builders and system integrators need remote access for service and maintenance, a favorite way in when it isn't locked down properly.

The IT/OT boundary

Exactly where classic office IT touches the production layer, network segmentation that would otherwise stop the spread is often missing.

People & premises

Goods receiving

Parcel deliveries, suppliers, truck drivers: unfamiliar people and unfamiliar objects come through here every day, often without anyone asking who actually belongs.

Third-party contractors

Service technicians, cleaning staff, and temp workers move through the plant with their own laptops or their own badges. Their access and devices rarely go through the same controls as your own.

Break room

Where colleagues are relaxed and happy to help, an orphaned USB stick or an "I'm new here" is at its most convincing.

Tailgating

A door held open, a smokers' exit, a badge check that only happens in the morning: the way into the production hall often bypasses technology entirely.

Our approach

How we test without stopping the line

Keeping production available matters more than test depth. Before we touch anything, we agree with IT and OT stakeholders which systems get actively tested, which are only analyzed passively, and which are excluded entirely. On PLCs, control systems, and other OT-adjacent systems we work passively as a rule: we read along, we don't write.

Where active testing is needed, it runs in pre-agreed production windows, with a defined emergency contact on both sides and a firm rule to stop immediately at any unexpected effect. Testing machines and lines never happens without plant management at the table, so no test step accidentally halts production.

Relevant modules

These are the tests that bring your production up to the state of the art

Where IT, OT, and the factory floor meet, one test isn't enough. These are the building blocks we work with.

Physical Pentest

Simulated entry into factory grounds, goods receiving, and the production hall, including tailgating attempts.

Learn more

Social Engineering

Phishing, pretexting, and media-dropping simulations, tailored to shift work and third-party contractors.

Learn more

OT/ICS Pentest

Targeted testing of PLCs, SCADA, and remote-maintenance access, scheduled around your production windows and without risk to ongoing operations.

Learn more

Infrastructure

Network segmentation between IT and OT, Active Directory hardening, and the classic office IT inside the plant.

Learn more

NIS2: the deeper dive

Our NIS2 page walks through the full Article 21(2) requirement catalog and how a penetration test technically covers most of it.

Learn more

Pentesting for manufacturing & production: your questions

Probably, once you pass 50 employees or 10 million EUR in annual revenue. Manufacturing, including machine building, electronics, automotive parts, and medical devices, falls under the NIS2 sectors and is then classified as an "important entity." Not sure whether you cross that threshold? We'll work it out with you in a free initial consultation.
In OT, availability comes before everything else: a crashed controller can shut down a production line for hours. So we test more carefully, often passively rather than actively, and with a narrower scope. A clearly defined emergency contact is in place before any active testing ever touches a PLC.
Yes, and for OT-adjacent systems that's actually the norm. We agree in advance on which systems get actively tested, which are only analyzed passively, and which are excluded entirely. A defined emergency contact and an immediate stop at the first sign of trouble are standard parts of the plan.
IEC 62443 is the relevant standards series for securing industrial automation and control systems. There's usually no direct legal mandate to follow it, but it's the practically recognized benchmark for what "state of the art" means in an OT context, which makes it relevant for your NIS2 evidence.
It depends heavily on scope: number of sites and production lines, whether OT/ICS systems are included, and whether physical and social-engineering testing are part of it. After a free initial consultation, we'll know your scope and you'll get a transparent fixed-price quote.
Media dropping is a documented, actively used attack technique, not a theoretical exercise. Ransomware at manufacturing companies typically gets in through the IT side and then spreads toward OT-adjacent systems. A dropped USB stick is one of the simplest ways to simulate exactly that first step.
Typically IT management, plant or OT leadership, and, depending on scope, executive management. The coordination between IT and OT is often the trickiest part, since responsibilities in practice frequently aren't cleanly split between the two. We bring the relevant stakeholders to the table from day one.
Yes. Remote-maintenance access for machine vendors and system integrators is one of the most common weaknesses we find in practice, often without multi-factor authentication or with overly broad permissions. We test that access specifically as part of the OT/ICS and infrastructure pentest.