The plant keeps running, even while we test it

OT and ICS pentest for PLCs, SCADA, field buses and network segments. We work like real attackers, but within a framework your operations team signs off beforehand.

  • IEC 62443, KRITIS, NIS2
  • Passive, semi-active or in the lab
  • Availability before confidentiality

Four zones, four tests

What sits there What we test there
Office IT

Workstations, jump servers, remote maintenance access.

VPN, remote maintenance access, jump servers and DMZ architectures checked for misconfigurations.

IT/OT boundary

The bridge from the office network into production. We test zoning, DMZ configuration, firewall rules and unauthorised crossover connections.

Supervisory level

SCADA, HMI, OPC UA, historian, IEC 60870-5-104, DNP3.

Web interfaces, OPC servers, historian databases and remote access checked for known vulnerabilities.

Control level

PLCs and RTUs from Siemens, Rockwell, Schneider, ABB.

Authentication, firmware, programming ports and unauthorised commands on the controller itself.

Field level

Field buses: Profibus, Profinet, Modbus RTU/TCP.

Sniffing, replay and manipulation under controlled conditions, plus firmware analysis.

How we test without stopping production

Passive

Pure read-only scan of the traffic, not a single packet sent to a controller.

Semi-active

Scans at very low intervals, only in time windows your operations team approves in advance.

Parallel test environment

Identical hardware in your test plant or in our OT lab.

A production stop caused by a failed test does more damage than the attack it is meant to find. Every step is agreed with your control room beforehand, and critical findings go out immediately, not only with the report.

The evidence you get

The report is aligned with IEC 62443, the ICS profile of the BSI IT-Grundschutz, the KRITIS obligations under sections 30 and 31 BSIG including evidence under section 39 BSIG, NIS2 and ISO 27001.

We deliver the test and the technical evidence. Registration, certification and the legal classification remain with you.

Why OT cannot be tested like IT

  • Systems run for 15 to 30 years

    Patches are rare, known CVEs stay open and are actively exploited.

  • Protocols without security

    Modbus, DNP3 and Profibus were never designed for it. No encryption, no authentication.

  • Controllers without login

    Many PLCs and RTUs require no authentication and are directly reachable on the network.

  • Ransomware hits manufacturing

    Colonial Pipeline and Norsk Hydro showed what a production standstill costs.

Attacks we reproduce within an agreed framework

Eavesdropping on the HMI

Without VPN and without certificate validation, an attacker sits between operator station and PLC, reads the cleartext traffic and injects their own control commands. The operator sees the same screen as before.

Replay against the PLC

A legitimate valve command is recorded and sent again at an unfavourable moment. The PLC accepts it because no sequence number is checked.

Load on the control connection

Port 502 is flooded with Modbus requests. PLCs have no protection against this, the connection drops and the control room loses access.

Rogue device in the OT network

Without 802.1X, a planted device with the PLC's MAC address is enough to send commands to valves and pumps.

Wireless as a side entrance

WLAN in production, Bluetooth sensors and LoRaWAN are part of the scope, as are access points someone has plugged into the network without approval.

The standards in detail

KRITIS

Operators of critical facilities are required under sections 30 and 31 BSIG to implement adequate OT security measures and, under section 39 BSIG, to evidence them to the BSI every three years.

NIS2

The EU directive significantly widens the circle of affected companies and requires an assessment of effectiveness, in production including OT.

IEC 62443

International standard series for OT and ICS security, the de facto standard for SCADA and industrial control systems.

ISO 27001

Annex A requires network segregation (A.8.22) and physical controls (A.7), which IEC 62443 then details for industry.

BSI IT-Grundschutz

The ICS profile provides concrete measures for operators of industrial control systems in Germany.

CER Directive

Complements NIS2 with the physical resilience of critical entities, implemented in Germany by the KRITIS Umbrella Act.

Frequently asked questions

How long does an OT pentest take?

Three to ten days, depending on scope. Typically one to two days of passive reconnaissance, two to four days of active testing and one to two days of reporting. For large critical infrastructure we plan in stages across several maintenance windows.

What happens if you find something critical?

Critical findings go to your security and operations team while the test is still running, with an immediate risk assessment and a workaround. The final report then contains the complete remediation roadmap, prioritised by business impact.

Which vendors and protocols do you cover?

Siemens S7 with S7comm and S7comm-Plus, Rockwell and Allen-Bradley with EtherNet/IP and CIP, Schneider Electric, ABB, Beckhoff and others. On the protocol side Modbus TCP and RTU, DNP3, IEC 60870-5-101 and -104, Profinet, Profibus, OPC UA, OPC Classic and BACnet.

Can this be combined with an IT or physical pentest?

Yes, and that produces the most realistic picture. A full-chain scenario begins with physical access, continues through lateral movement in the IT network and the pivot into the OT network, and goes all the way to manipulating the plant.

Talk first, then test

In a free initial call we clarify plants, time windows and the permitted test depth. You then receive a written quote.