office@safebyte.io București, România ISO 27001:2023 · ISO 9001:2023
Offensive testing

Industrial security (ICS / SCADA / OT)

Mission-critical industrial systems, networks and infrastructure — assessed around process safety and continuity, following IEC 62443 and NIST 800-82, with passive reconnaissance that injects nothing into the control zone.

Deutsch: această pagină nu e încă tradusă. Textul de mai jos e în English.

Industrial security (ICS / SCADA / OT)

In IT, the priority is confidentiality. In OT, everything inverts: safety and availability come first, and a single packet sent wrong can halt a control loop or trigger a safety function. A test conducted with an IT-pentest mindset — aggressive scanning, unrestricted exploitation — is more dangerous to you than the attacker you’re defending against. That’s why industrial assessment is governed differently from the first hour, and experience means knowing exactly what NOT to do, and when.

How we work, safely

Safety governance, first

We define critical processes and explicit stop/rollback conditions, exclude Safety Instrumented Systems (SIS) from active testing and schedule anything intrusive only during maintenance windows or on replicas/labs. Nothing active runs without process engineers in the room.

Passive reconnaissance

We build the asset inventory and flow map from mirrored traffic (SPAN/TAP), without injecting a single packet into the control zone. This alone reveals equipment, firmware, protocols and unexpected communications — including connections nobody knew still existed. IT tools that actively query controllers have no place in a live control zone.

Architecture and segmentation (where the biggest gains are)

We validate the Purdue model and the IT/OT DMZ — the classic real-incident chain is phishing in IT, then pivot into OT through a bridge host or a poorly isolated supplier access. We examine firewall rules, historians, engineering workstations and integrators’ remote access. This is the activity with the highest return and the lowest risk.

Configurations, vulnerabilities and, only where safe, active testing

We check firmware and patches, default or shared credentials, HMI and engineering workstation hardening (often legacy Windows) — mostly from configurations, offline. Active testing, when we do it, is narrow and targeted: a few known ports, never a full sweep, and controller-level testing only on replicas or during maintenance. The golden rule: we know exactly what packets each tool sends before we start it.

What we cover

  • IT ↔ OT segmentation and lateral movement paths between levels
  • Industrial protocols — Modbus, DNP3, EtherNet/IP, PROFINET, S7comm, IEC 61850, OPC UA. Many variants lack authentication or integrity by design; that fact is itself a finding, with implications we explain, not just something to “exploit”
  • Equipment — HMIs, SCADA servers, engineering workstations with PLC credentials, historians, PLC/RTU/DCS controllers
  • Remote access — supplier VPNs, always-on maintenance links, credentials shared between sites (the root cause of some of the best-known OT incidents)

What you get

  • Risk summary in operational and safety terms (downtime, safety, production loss), not just CVSS
  • Observed asset and flow map, abstracted
  • Zone and conduit diagram with target vs. achieved security level (IEC 62443-3-2)
  • Prioritised findings, with OT-appropriate remediation — compensating controls where patching isn’t possible, the common case in industry
  • Roadmap for segmentation and monitoring (for example, passive IDS aware of industrial protocols)