The problem
A plant is not an office, and testing its security as if it were is a mistake in both directions. On the corporate network (IT), testing can—and should—push hard: genuine exploitation, lateral movement, privilege escalation and proof of how far an attacker could go. On the control network (OT), the same aggression may take a fifteen-year-old controller out of service merely by scanning it.
We therefore offer two services with the same philosophy but different methods. IT testing pursues data and control of systems; OT testing seeks one answer: can someone alter or stop the physical process? The greatest risk is often at the seam between the two—the IT-to-OT path that almost nobody tests end to end.
The other common failure is the report: hundreds of vulnerabilities ordered by CVSS, without distinguishing one that could stop a reactor from one affecting a printer. In OT, a pentest without process context produces noise, not decisions.
Scope
- Written scope and rules of engagement specific to each service: what is tested, where, when and what is excluded.
- IT ethical hacking: penetration of the corporate network with real exploitation, lateral movement and privilege escalation within the agreed scope.
- OT ethical hacking: live testing of the industrial perimeter—remote access, DMZ and paths from IT—with intrusive control-system testing performed on a replica, in Ti Lab or during a shutdown window.
- End-to-end testing of the IT-to-OT path: the actual route an attacker would take from an email to a PLC.
- Review of PLC, SCADA and engineering workstation configurations.
- Simulated phishing campaign for agreed personnel (optional).
- Retesting of corrections, included in the scope.
Deliverables
- A technical report with step-by-step reproducible evidence, separating IT and OT findings.
- Each finding classified by the appropriate criterion: technical severity in IT and physical process impact in OT.
- A remediation plan with recommended order and estimated effort.
- An executive summary of the three most important attack paths, including the one crossing from IT to OT.
- A retest report verifying what has been closed.
What we can test
The service is not limited to the control network. On the IT side, we cover the full attack surface exposed by an industrial organisation; in OT, we cover what is specific to the plant. The two are combined according to what needs to be tested.
Web applications and APIs
OWASP Top 10, authentication and authorisation, and above all business logic, both on the web and in the services and APIs behind it.
Cloud environments
AWS, Azure and Google Cloud: configuration, identities and permissions (IAM), exposure of services and storage, and container security.
External infrastructure
The perimeter visible from the internet: published services, VPN, email and portals—what an attacker finds before getting inside.
Internal infrastructure and directory
What someone who has already gained access can do: Active Directory and Entra ID, lateral movement and privilege escalation up to the domain.
Mobile applications
Android and iOS, including native components and communication with the back end.
Wi-Fi networks
Encryption, guest networks and effective separation from both the corporate and plant networks.
Red Team and social engineering
End-to-end adversary simulation: targeted phishing, physical intrusion and evasion, measuring what is detected and how the organisation responds.
Control network (OT/ICS)
The industrial perimeter and live remote access, plus the control systems themselves on a replica, in Ti Lab or during a shutdown window.
Advanced offensive security
When a pentest falls short because the whole organisation—not a list of systems—needs to be tested, we step up a level.
Red Team (adversary emulation)
A complete APT-style attack carried out covertly over several weeks without the SOC's knowledge, with a specific objective: exfiltrate data, compromise production or reach OT. Any vector—technical, physical or human—is in play, providing a genuine measure of detection and response.
Custom implants
When a commercial tool is detected by EDR or does not fit, we build it. Our Evil Crow family—BadUSB cables, keyloggers, RF, video capture and Wi-Fi exfiltration—is developed to measure and concealed in everyday objects or industrial equipment.
Breach and attack simulation (BAS)
Continuous, automated validation of your controls: thousands of real attack scenarios based on MITRE ATT&CK, executed safely in production to measure what is blocked, what goes unnoticed and where the gaps are.
Two services, two methodologies
The same underlying question—how far could an attacker go?—answered in two different ways. This is how IT and OT testing differ.
| IT ethical hacking | OT ethical hacking | |
|---|---|---|
| Objective | Data confidentiality and integrity; gain control of systems and demonstrate the true extent of compromise. | The physical process and safety: can production be altered or stopped? |
| Intensity | Real exploitation, brute force and lateral movement: the system can withstand it. | Controlled: control equipment may not withstand it, so aggressive work moves to the laboratory or a window. |
| Where testing occurs | On production systems, within the agreed scope. | Live perimeter and access; intrusive control-system work on a replica, in Ti Lab or during a shutdown. |
| Tools | Standard pentesting and post-exploitation frameworks. | The same tools at the perimeter, plus passive analysis and industrial-protocol tooling. |
| Measurement | Technical severity, CVSS and exploitation chains. | Process impact: what stops, what can be manipulated and which safety functions are compromised. |
| References | OWASP, PTES, OSSTMM. | IEC 62443-3-3 (SL verification) and MITRE ATT&CK for ICS. |
Questions we are asked before engagement
Could a test bring down my plant?
In OT, the rules of engagement are designed to prevent this: only tests agreed as safe are run in production, while anything carrying risk moves to a replica, Ti Lab or a shutdown window. IT allows more aggressive testing, always within the signed scope. Any test is stopped if operations requests it.
Can I contract IT only, OT only or both?
Whichever you prefer: they are two services and can be contracted separately or together. However, end-to-end testing of the IT-to-OT path brings the greatest value and requires scope on both networks. If you can only start with one, we will tell you which makes most sense.
Does it make sense if we have not yet completed an assessment?
Testing usually delivers more value after an assessment because it can target what matters. If you do not yet have one, we will say so and propose starting there.