Home/Services/Energy & Utilities Penetration Testing
security service

Energy & Utilities Penetration Testing

Energy utilities penetration testing for OT, ICS and SCADA. IEC 62443 and NIS2 ready. Safe, manual testing with a free retest. Book a scoping call.

Manual, expert-ledEvidence-based findingsFree remediation retest

Energy utilities penetration testing has to answer one question above all others: can an attacker who gets into the corporate network reach the systems that keep the lights on. We test both the IT side and the boundary to your operational technology, carefully and by hand, so you find the crossing points before an adversary does.

SafetyBis is a European offensive-security team working with generators, distributors, water and district-energy operators across Europe. This is the most consequence-heavy testing we do. A mistake in an OT environment can affect physical processes and safety, so our method is conservative by design: we prove exposure without touching the process, and we treat the IT/OT boundary as the main event.

What energy utilities penetration testing actually covers

Scope spans the enterprise IT that attackers enter through, the segmentation between IT and OT, and the industrial control systems on the other side. We test the corporate surface aggressively and the operational surface with the caution it demands.

Corporate IT: web apps, email, remote access and Active Directory
IT/OT segmentation and the firewalls and jump hosts between them
SCADA and ICS interfaces, HMIs and engineering workstations
Smart-meter head-end systems and metering data collection
Customer portals and billing platforms handling personal data
Remote-access and vendor-maintenance paths into OT
Safety-instrumented and protection systems, tested for exposure only

The segmentation boundary is where a utility lives or dies. In practice the interesting finding is rarely a novel exploit against a PLC. It is a dual-homed engineering workstation, a flat vendor VPN, or a firewall rule that quietly allows corporate traffic into the control network. Those are the paths that turn an ordinary IT breach into a physical-consequence event.

How we test

Energy utilities penetration testing at SafetyBis follows a strict, safety-first methodology. We test IT with Burp Suite, nmap and ffuf as we would any enterprise environment. On the OT side we shift to passive and read-only techniques, agreed in advance with your operations engineers.

Reconnaissance and mapping

We map the corporate external footprint and, critically, look for any OT or ICS interface that has drifted onto the internet: an exposed HMI, a remote-maintenance portal, a metering head-end reachable from outside. Internet-exposed control interfaces are a known and repeatedly exploited class of exposure.

IT testing and the boundary

We test the corporate estate for the initial-access and privilege-escalation paths from MITRE ATT&CK, then focus on the crossing to OT: can a foothold in IT reach a jump host, an engineering workstation or a control-network segment. This is where the real risk sits.

OT assessment, read-only

Inside the OT zone we work non-intrusively: passive traffic analysis, configuration and architecture review against IEC 62443 zones and conduits, and careful enumeration. We do not send unpredictable input to a live PLC or safety system. Demonstrating that a path exists is enough, and it is safe.

Reporting

Findings carry a CVSS score, a reproduction where safe to give one, and remediation mapped to IEC 62443 and NIS2. Anything that exposes the OT boundary is escalated immediately.

Read-only
OT tested without touching the process
IEC 62443
findings mapped to zones and conduits
Free
retest after you fix

Common vulnerabilities we find in energy and utilities

Weak IT/OT segmentation

The headline risk. Firewall rules that allow more than they should, dual-homed hosts bridging both networks, and vendor connections that land inside the OT zone. Our engagements repeatedly show that the control network is one credential away from the corporate one.

Internet-exposed control and metering interfaces

HMIs, historians, and smart-meter head-end systems reachable from the internet, often with default or weak credentials. These are directly discoverable and directly dangerous.

Insecure remote and vendor access

Maintenance VPNs without MFA, shared engineering credentials, and always-on vendor tunnels. Remote access is the classic route into OT, and it maps to initial-access techniques we test explicitly.

Corporate IT weaknesses that pivot

Phishable authentication, over-privileged Active Directory, and unpatched internet-facing services. On their own they are ordinary. As the first link in a chain toward OT they are critical.

Legacy protocols without authentication

Industrial protocols that trust any message on the wire. We assess exposure to this by mapping who can reach those segments, rather than by injecting traffic into them.

Customer-portal and billing exposure

The IT-side systems a utility runs like any other business, holding the personal and payment data of every customer. Self-service portals with broken object-level authorization leak one customer’s account and consumption data to another, and billing platforms with weak access control expose meter readings and addresses at scale. These are ordinary web flaws, but at a utility they carry a regulator’s attention because of whose data is involved.

Unmanaged remote engineering tools

Ad-hoc remote-support software installed on engineering workstations, often outside IT’s inventory, that quietly bridges the internet to a machine one hop from the control network. We look for these specifically, because they are a recurring and under-appreciated route past an otherwise sound boundary.

Tools and techniques

For IT we use Burp Suite Professional, nmap and ffuf, and the standard manual toolkit for access control and business logic. For OT we rely on passive network capture, configuration review and architecture analysis against the IEC 62443 model, plus vendor advisories and CVE analysis for the control equipment in scope. Attack paths are documented against MITRE ATT&CK for ICS so your OT and IT teams read one coherent story. Nothing intrusive touches a live control or safety system.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

What you get

Executive summary framed around safety and continuity of supply
Technical report with CVSS and IEC 62443 mapping per finding
A clear picture of every IT-to-OT crossing point and its risk
Prioritized remediation for IT, OT and network teams
An attestation letter for NIS2 and regulator engagement
A free retest once segmentation and other fixes are in place

The deliverable that regulators and boards want is the boundary map: a defensible statement of how the control network is separated from everything else, and where that separation is thin. We give you exactly that.

Compliance and standards

NIS2

Energy and water operators are essential entities under NIS2, with binding risk-management and incident obligations and personal accountability for management. A penetration test evidences the risk-assessment and testing measures the directive expects.

IEC 62443

We assess and report against the IEC 62443 zone-and-conduit model, so the findings translate directly into the security levels and boundary controls the standard defines.

GDPR and DORA

Customer and metering data brings GDPR into scope, and utilities with significant financial operations may also touch DORA. The report addresses these where they apply to your estate.

Why manual testing beats a scanner in an OT environment

Pointing a scanner at OT is not a test, it is a risk. Automated tools generate unpredictable traffic that can disrupt sensitive control equipment, and they cannot reason about the one thing that matters here: whether the architecture actually keeps the control network apart from the corporate one. That is a judgement about firewall rules, host configuration and trust relationships, and it takes an engineer who understands both offensive technique and industrial safety. We bring both, and we err on the side of not touching the process.

The failures we report are almost never a clever exploit against a controller. They are architecture and trust decisions made years ago, under delivery pressure, that nobody has revisited. A firewall rule opened for a one-off vendor project and never closed. An engineering laptop that plugs into both networks because it was convenient. A historian replicated into corporate reporting over a link that turns out to be bidirectional. None of these shows up as a vulnerability in a scan report, because none of them is a missing patch. Each is a decision, and evaluating decisions against the IEC 62443 zone model is human work. That is also why the finding a board remembers is not a CVE number but a diagram: this is your control network, here are the four ways into it, here is which one we would use.

Who books this and when

CISOs and OT security leads at utilities come to us for a NIS2 readiness assessment, ahead of an IEC 62443 programme, after an audit flags the IT/OT boundary, or when a peer in the sector is hit and the board asks whether it could happen to them. If your organisation runs anything that affects supply or safety, the boundary test is the single most valuable engagement you can commission.

Pricing

Energy utilities penetration testing cost depends heavily on scope: the size of the IT estate, whether OT and segmentation are in scope, the number of sites, and the depth of the control-system review. Every engagement is fixed-price after scoping.

Engagement What’s included Timeline Price
Corporate IT External network and key web applications, remote access and authentication, initial-access and escalation testing, full report and free retest 4–8 working days €2,500–€6,000
IT/OT boundary Internal network, segmentation and crossing-point testing between IT and OT, jump hosts and vendor access, lateral-movement analysis from €4,000, typical €4,000–€9,000 €4,000–€9,000
OT architecture review Read-only ICS/SCADA assessment against IEC 62443 zones and conduits, passive analysis, exposed-interface and metering review scoped per site from €6,000
Compliance add-on Mapping and attestation letter for NIS2 and IEC 62443, or GDPR where relevant with any tier from €800
Custom / multi-site estate Multiple generation, distribution or metering sites, or a full IT and OT programme, scoped to you on scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call, and a retest is included. Get a fixed quote

FAQ

How much does energy utilities penetration testing cost?
Corporate IT testing runs €2,500–€6,000, boundary and internal work from €4,000, and an OT architecture review from €6,000. The exact cost is fixed after a free scoping call, based on the size of your estate and the depth of OT review.
Is it safe to test our SCADA and control systems?
Yes, because we do not send intrusive traffic to live control or safety systems. The OT side is assessed read-only, using passive analysis and configuration review, so we prove exposure without risking the process.
How do you handle the IT/OT boundary?
It is the centre of the engagement. We test whether a foothold in corporate IT can reach the OT network through firewalls, jump hosts, dual-homed machines or vendor access, and map every crossing point against IEC 62443.
Does this satisfy NIS2?
Yes. As an essential entity you must have risk-management measures and test them, and the report plus attestation letter provide direct evidence toward those NIS2 obligations, including for management accountability.
Do you work to IEC 62443?
Yes. We assess and report against the IEC 62443 zone-and-conduit model so findings map to the security levels and boundary controls the standard defines, ready to feed your OT security programme.
Can you test smart meters and the metering head-end?
Yes. We assess the head-end systems and metering data collection for exposure, weak authentication and internet-reachable interfaces, treating live field devices with the same read-only caution as the rest of OT.
Will you need to be on site?
The corporate IT and external testing is largely remote. The OT and segmentation review usually benefits from a scheduled on-site or jump-host session with your operations engineers present, which we agree during scoping.
Is the retest included?
Yes, and free. Once you have tightened segmentation and remediated other findings we retest and update the report and attestation to confirm the boundary holds.
Can you test our OT and SCADA systems without risking the plant?
Yes, and safety comes first. On live operational technology we default to passive analysis and carefully scoped, out-of-hours testing agreed with your engineers, never intrusive checks against production controllers mid-run. The work aligns to IEC 62443 and NIS2, and we map every finding to real-world impact on availability and safety, not just IT confidentiality.

Related services

Who needs this

Generators, grid and distribution operators, water and district-energy utilities across Europe that fall under NIS2 and run OT, ICS or SCADA, and need a safe, boundary-focused test that proves their control network is protected from an IT-side breach.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "Energy & Utilities Penetration Testing"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.