OT and ICS pentest for PLCs, SCADA, field buses and network segments. We work like real attackers, but within a framework your operations team signs off beforehand.
Workstations, jump servers, remote maintenance access.
VPN, remote maintenance access, jump servers and DMZ architectures checked for misconfigurations.
The bridge from the office network into production. We test zoning, DMZ configuration, firewall rules and unauthorised crossover connections.
SCADA, HMI, OPC UA, historian, IEC 60870-5-104, DNP3.
Web interfaces, OPC servers, historian databases and remote access checked for known vulnerabilities.
PLCs and RTUs from Siemens, Rockwell, Schneider, ABB.
Authentication, firmware, programming ports and unauthorised commands on the controller itself.
Field buses: Profibus, Profinet, Modbus RTU/TCP.
Sniffing, replay and manipulation under controlled conditions, plus firmware analysis.
Pure read-only scan of the traffic, not a single packet sent to a controller.
Scans at very low intervals, only in time windows your operations team approves in advance.
Identical hardware in your test plant or in our OT lab.
A production stop caused by a failed test does more damage than the attack it is meant to find. Every step is agreed with your control room beforehand, and critical findings go out immediately, not only with the report.
The report is aligned with IEC 62443, the ICS profile of the BSI IT-Grundschutz, the KRITIS obligations under sections 30 and 31 BSIG including evidence under section 39 BSIG, NIS2 and ISO 27001.
We deliver the test and the technical evidence. Registration, certification and the legal classification remain with you.
Patches are rare, known CVEs stay open and are actively exploited.
Modbus, DNP3 and Profibus were never designed for it. No encryption, no authentication.
Many PLCs and RTUs require no authentication and are directly reachable on the network.
Colonial Pipeline and Norsk Hydro showed what a production standstill costs.
Without VPN and without certificate validation, an attacker sits between operator station and PLC, reads the cleartext traffic and injects their own control commands. The operator sees the same screen as before.
A legitimate valve command is recorded and sent again at an unfavourable moment. The PLC accepts it because no sequence number is checked.
Port 502 is flooded with Modbus requests. PLCs have no protection against this, the connection drops and the control room loses access.
Without 802.1X, a planted device with the PLC's MAC address is enough to send commands to valves and pumps.
WLAN in production, Bluetooth sensors and LoRaWAN are part of the scope, as are access points someone has plugged into the network without approval.
Operators of critical facilities are required under sections 30 and 31 BSIG to implement adequate OT security measures and, under section 39 BSIG, to evidence them to the BSI every three years.
The EU directive significantly widens the circle of affected companies and requires an assessment of effectiveness, in production including OT.
International standard series for OT and ICS security, the de facto standard for SCADA and industrial control systems.
Annex A requires network segregation (A.8.22) and physical controls (A.7), which IEC 62443 then details for industry.
The ICS profile provides concrete measures for operators of industrial control systems in Germany.
Complements NIS2 with the physical resilience of critical entities, implemented in Germany by the KRITIS Umbrella Act.
Three to ten days, depending on scope. Typically one to two days of passive reconnaissance, two to four days of active testing and one to two days of reporting. For large critical infrastructure we plan in stages across several maintenance windows.
Critical findings go to your security and operations team while the test is still running, with an immediate risk assessment and a workaround. The final report then contains the complete remediation roadmap, prioritised by business impact.
Siemens S7 with S7comm and S7comm-Plus, Rockwell and Allen-Bradley with EtherNet/IP and CIP, Schneider Electric, ABB, Beckhoff and others. On the protocol side Modbus TCP and RTU, DNP3, IEC 60870-5-101 and -104, Profinet, Profibus, OPC UA, OPC Classic and BACnet.
Yes, and that produces the most realistic picture. A full-chain scenario begins with physical access, continues through lateral movement in the IT network and the pivot into the OT network, and goes all the way to manipulating the plant.
In a free initial call we clarify plants, time windows and the permitted test depth. You then receive a written quote.