Energy & Utilities Penetration Testing
Energy utilities penetration testing for OT, ICS and SCADA. IEC 62443 and NIS2 ready. Safe, manual testing with a free retest. Book a scoping call.
Energy utilities penetration testing has to answer one question above all others: can an attacker who gets into the corporate network reach the systems that keep the lights on. We test both the IT side and the boundary to your operational technology, carefully and by hand, so you find the crossing points before an adversary does.
SafetyBis is a European offensive-security team working with generators, distributors, water and district-energy operators across Europe. This is the most consequence-heavy testing we do. A mistake in an OT environment can affect physical processes and safety, so our method is conservative by design: we prove exposure without touching the process, and we treat the IT/OT boundary as the main event.
What energy utilities penetration testing actually covers
Scope spans the enterprise IT that attackers enter through, the segmentation between IT and OT, and the industrial control systems on the other side. We test the corporate surface aggressively and the operational surface with the caution it demands.
The segmentation boundary is where a utility lives or dies. In practice the interesting finding is rarely a novel exploit against a PLC. It is a dual-homed engineering workstation, a flat vendor VPN, or a firewall rule that quietly allows corporate traffic into the control network. Those are the paths that turn an ordinary IT breach into a physical-consequence event.
How we test
Energy utilities penetration testing at SafetyBis follows a strict, safety-first methodology. We test IT with Burp Suite, nmap and ffuf as we would any enterprise environment. On the OT side we shift to passive and read-only techniques, agreed in advance with your operations engineers.
Reconnaissance and mapping
We map the corporate external footprint and, critically, look for any OT or ICS interface that has drifted onto the internet: an exposed HMI, a remote-maintenance portal, a metering head-end reachable from outside. Internet-exposed control interfaces are a known and repeatedly exploited class of exposure.
IT testing and the boundary
We test the corporate estate for the initial-access and privilege-escalation paths from MITRE ATT&CK, then focus on the crossing to OT: can a foothold in IT reach a jump host, an engineering workstation or a control-network segment. This is where the real risk sits.
OT assessment, read-only
Inside the OT zone we work non-intrusively: passive traffic analysis, configuration and architecture review against IEC 62443 zones and conduits, and careful enumeration. We do not send unpredictable input to a live PLC or safety system. Demonstrating that a path exists is enough, and it is safe.
Reporting
Findings carry a CVSS score, a reproduction where safe to give one, and remediation mapped to IEC 62443 and NIS2. Anything that exposes the OT boundary is escalated immediately.
Common vulnerabilities we find in energy and utilities
Weak IT/OT segmentation
The headline risk. Firewall rules that allow more than they should, dual-homed hosts bridging both networks, and vendor connections that land inside the OT zone. Our engagements repeatedly show that the control network is one credential away from the corporate one.
Internet-exposed control and metering interfaces
HMIs, historians, and smart-meter head-end systems reachable from the internet, often with default or weak credentials. These are directly discoverable and directly dangerous.
Insecure remote and vendor access
Maintenance VPNs without MFA, shared engineering credentials, and always-on vendor tunnels. Remote access is the classic route into OT, and it maps to initial-access techniques we test explicitly.
Corporate IT weaknesses that pivot
Phishable authentication, over-privileged Active Directory, and unpatched internet-facing services. On their own they are ordinary. As the first link in a chain toward OT they are critical.
Legacy protocols without authentication
Industrial protocols that trust any message on the wire. We assess exposure to this by mapping who can reach those segments, rather than by injecting traffic into them.
Customer-portal and billing exposure
The IT-side systems a utility runs like any other business, holding the personal and payment data of every customer. Self-service portals with broken object-level authorization leak one customer’s account and consumption data to another, and billing platforms with weak access control expose meter readings and addresses at scale. These are ordinary web flaws, but at a utility they carry a regulator’s attention because of whose data is involved.
Unmanaged remote engineering tools
Ad-hoc remote-support software installed on engineering workstations, often outside IT’s inventory, that quietly bridges the internet to a machine one hop from the control network. We look for these specifically, because they are a recurring and under-appreciated route past an otherwise sound boundary.
Tools and techniques
For IT we use Burp Suite Professional, nmap and ffuf, and the standard manual toolkit for access control and business logic. For OT we rely on passive network capture, configuration review and architecture analysis against the IEC 62443 model, plus vendor advisories and CVE analysis for the control equipment in scope. Attack paths are documented against MITRE ATT&CK for ICS so your OT and IT teams read one coherent story. Nothing intrusive touches a live control or safety system.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
What you get
The deliverable that regulators and boards want is the boundary map: a defensible statement of how the control network is separated from everything else, and where that separation is thin. We give you exactly that.
Compliance and standards
NIS2
Energy and water operators are essential entities under NIS2, with binding risk-management and incident obligations and personal accountability for management. A penetration test evidences the risk-assessment and testing measures the directive expects.
IEC 62443
We assess and report against the IEC 62443 zone-and-conduit model, so the findings translate directly into the security levels and boundary controls the standard defines.
GDPR and DORA
Customer and metering data brings GDPR into scope, and utilities with significant financial operations may also touch DORA. The report addresses these where they apply to your estate.
Why manual testing beats a scanner in an OT environment
Pointing a scanner at OT is not a test, it is a risk. Automated tools generate unpredictable traffic that can disrupt sensitive control equipment, and they cannot reason about the one thing that matters here: whether the architecture actually keeps the control network apart from the corporate one. That is a judgement about firewall rules, host configuration and trust relationships, and it takes an engineer who understands both offensive technique and industrial safety. We bring both, and we err on the side of not touching the process.
The failures we report are almost never a clever exploit against a controller. They are architecture and trust decisions made years ago, under delivery pressure, that nobody has revisited. A firewall rule opened for a one-off vendor project and never closed. An engineering laptop that plugs into both networks because it was convenient. A historian replicated into corporate reporting over a link that turns out to be bidirectional. None of these shows up as a vulnerability in a scan report, because none of them is a missing patch. Each is a decision, and evaluating decisions against the IEC 62443 zone model is human work. That is also why the finding a board remembers is not a CVE number but a diagram: this is your control network, here are the four ways into it, here is which one we would use.
Who books this and when
CISOs and OT security leads at utilities come to us for a NIS2 readiness assessment, ahead of an IEC 62443 programme, after an audit flags the IT/OT boundary, or when a peer in the sector is hit and the board asks whether it could happen to them. If your organisation runs anything that affects supply or safety, the boundary test is the single most valuable engagement you can commission.
Pricing
Energy utilities penetration testing cost depends heavily on scope: the size of the IT estate, whether OT and segmentation are in scope, the number of sites, and the depth of the control-system review. Every engagement is fixed-price after scoping.
| Engagement | What’s included | Timeline | Price |
|---|---|---|---|
| Corporate IT | External network and key web applications, remote access and authentication, initial-access and escalation testing, full report and free retest | 4–8 working days | €2,500–€6,000 |
| IT/OT boundary | Internal network, segmentation and crossing-point testing between IT and OT, jump hosts and vendor access, lateral-movement analysis | from €4,000, typical €4,000–€9,000 | €4,000–€9,000 |
| OT architecture review | Read-only ICS/SCADA assessment against IEC 62443 zones and conduits, passive analysis, exposed-interface and metering review | scoped per site | from €6,000 |
| Compliance add-on | Mapping and attestation letter for NIS2 and IEC 62443, or GDPR where relevant | with any tier | from €800 |
| Custom / multi-site estate | Multiple generation, distribution or metering sites, or a full IT and OT programme, scoped to you | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, and a retest is included. Get a fixed quote
FAQ
How much does energy utilities penetration testing cost?
Is it safe to test our SCADA and control systems?
How do you handle the IT/OT boundary?
Does this satisfy NIS2?
Do you work to IEC 62443?
Can you test smart meters and the metering head-end?
Will you need to be on site?
Is the retest included?
Can you test our OT and SCADA systems without risking the plant?
Related services
Generators, grid and distribution operators, water and district-energy utilities across Europe that fall under NIS2 and run OT, ICS or SCADA, and need a safe, boundary-focused test that proves their control network is protected from an IT-side breach.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.