Roughly one in four companies in mechanical and plant engineering reported a significant cybersecurity incident within the past two years.
Source: VDMA study "Industrial Security und Produktpiraterie 2024," Fraunhofer AISEC, 100 surveyed VDMA member companies
Media dropping is an established social-engineering technique we run in a controlled form at accessgranted on a regular basis. Not a specific incident at a specific customer, just a typical sequence that shows how little it can take.
Placed unobtrusively, often carrying a company logo or a label designed to spark curiosity.
Out of curiosity, a wish to be helpful ("maybe it belongs to someone"), or plain habit, with no bad intent at all.
From there, the real assessment checks how far that access could be pushed toward the production network.
Without segmentation between office IT and the production network, PLCs, control systems, and the machine vendor's remote-maintenance access are all reachable from the compromised workstation. We document that path rather than walking it to the end: on OT-adjacent systems we work passively, and actively only in pre-agreed time windows.
Every finding rated by severity, exploitability, and potential impact on production, with a management summary for executive, IT, and plant leadership and a mapping to NIS2 and IEC 62443. This is what an excerpt can look like:
Production environments pair decades-old control technology with modern IT, usually without both sides sharing the same security culture.
PLCs, control systems, and fieldbuses are often built for uptime rather than security, and can run for years without a patch.
Sensors and networked machines widen the attack surface, frequently still on factory-default settings nobody ever changed.
Machine builders and system integrators need remote access for service and maintenance, a favorite way in when it isn't locked down properly.
Exactly where classic office IT touches the production layer, network segmentation that would otherwise stop the spread is often missing.
Parcel deliveries, suppliers, truck drivers: unfamiliar people and unfamiliar objects come through here every day, often without anyone asking who actually belongs.
Service technicians, cleaning staff, and temp workers move through the plant with their own laptops or their own badges. Their access and devices rarely go through the same controls as your own.
Where colleagues are relaxed and happy to help, an orphaned USB stick or an "I'm new here" is at its most convincing.
A door held open, a smokers' exit, a badge check that only happens in the morning: the way into the production hall often bypasses technology entirely.
Keeping production available matters more than test depth. Before we touch anything, we agree with IT and OT stakeholders which systems get actively tested, which are only analyzed passively, and which are excluded entirely. On PLCs, control systems, and other OT-adjacent systems we work passively as a rule: we read along, we don't write.
Where active testing is needed, it runs in pre-agreed production windows, with a defined emergency contact on both sides and a firm rule to stop immediately at any unexpected effect. Testing machines and lines never happens without plant management at the table, so no test step accidentally halts production.
Where IT, OT, and the factory floor meet, one test isn't enough. These are the building blocks we work with.
Simulated entry into factory grounds, goods receiving, and the production hall, including tailgating attempts.
Phishing, pretexting, and media-dropping simulations, tailored to shift work and third-party contractors.
Targeted testing of PLCs, SCADA, and remote-maintenance access, scheduled around your production windows and without risk to ongoing operations.
Network segmentation between IT and OT, Active Directory hardening, and the classic office IT inside the plant.
Our NIS2 page walks through the full Article 21(2) requirement catalog and how a penetration test technically covers most of it.