OT, ICS & SCADA Penetration Testing
OT ICS SCADA penetration testing across Europe, safety-first: IT/OT segmentation, Modbus, DNP3, PLCs. Fixed price, free retest. Get a fixed quote.
OT ICS SCADA penetration testing is where security meets physical process, and where a careless test can stop a production line or trip a safety system. We test operational technology the way it has to be tested: safety first, availability protected, and every intrusive step agreed before it runs. The goal is to find how an attacker reaches your PLCs and controllers before one does.
What OT ICS SCADA penetration testing actually covers
Industrial environments break the usual security priorities. In IT, confidentiality tends to come first; in operational technology, availability and safety do, because the system is running a physical process that people and equipment depend on. A test that would be routine against a web app can be reckless against a live PLC. So the scope is defined as much by what we will not do carelessly as by what we cover, and we shape it around your Purdue-model architecture and the real path an attacker would take from the business network down to the plant floor.
A full assessment usually spans:
How we run an OT ICS SCADA penetration test
Everything starts from the assumption that the process must keep running. Where a live control network is in scope, we lean on passive analysis, careful and agreed active steps, and maintenance windows. Where you have a lab, a test cell or a digital twin, we do the intrusive work there and validate carefully against production. This is not a limitation on the assessment, it is what makes it usable in the real world.
Architecture review and threat modelling
We start on paper and diagrams. We map your zones and conduits against the Purdue model and IEC 62443, identify where enterprise IT touches OT, and work out the most likely route an attacker takes: a phished engineer, a flat network, a forgotten vendor VPN, an internet-exposed HMI. That map tells us where testing effort actually reduces risk.
Passive discovery
On the control network we begin by listening. Passive traffic analysis identifies the devices, protocols and communication patterns present without sending a single risky packet. This alone frequently surfaces serious issues: unencrypted control traffic, unexpected internet connectivity, rogue devices, and protocols in use that nobody documented.
Controlled active testing
With scope and safety agreed, we move to active work at the IT-to-OT boundary and against non-production or resilient assets. We test whether segmentation actually holds, whether an attacker on the business network can reach control systems, and whether device and protocol authentication stands up. Anything that could affect a live process is either run in your test environment or scheduled into a maintenance window with your team present.
Reporting and retest
Findings come as an executive summary for leadership and plant management and a technical report for engineering and OT security. Each finding has an impact rating in operational terms, reproduction detail, and a remediation that respects how hard OT change is. After you remediate, we retest for free within the same safety constraints.
The weaknesses we find most often
Industrial estates share a set of recurring problems, most of them rooted in systems that were designed for isolation and then quietly connected to everything.
Flat networks and weak segmentation
The single most common finding is that the boundary between IT and OT is thinner than the network diagram claims. A firewall exists but permits far more than it should, a management VLAN bridges both worlds, or a dual-homed workstation quietly connects them. Once inside IT, an attacker reaches control systems with little resistance. We prove whether that path is real.
Protocols with no authentication
Modbus, DNP3 and their peers were built for trusted networks and often carry no authentication or encryption at all. An attacker on the control network can read process values and, worse, issue commands to controllers. We assess where these protocols run exposed and what an attacker could do with access to them.
Unmanaged remote access
Vendor VPNs left permanently open, remote-access tools installed for a maintenance job and never removed, and shared engineering credentials are a favourite entry point. Many real ICS incidents began with legitimate remote access, not an exotic exploit. We hunt these paths down and test how far each one reaches.
Exposed and unpatched devices
HMIs reachable from the internet, historians with default credentials, and PLCs running firmware years behind on patches are routine. Patching OT is genuinely hard, so we focus on compensating controls and isolation rather than pretending you can simply update everything overnight.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
What you get
The report is written for two audiences at once. Plant and executive leadership get the operational and safety risk in language they can act on, including what a realistic attack would mean for production and downtime. Engineering and OT security get a technical breakdown with each finding’s impact, reproduction detail and a remediation that accounts for change-control reality and downtime windows.
Where a finding reflects a systemic issue, such as an ineffective IT-to-OT boundary or an undocumented remote-access path, we call it out as a priority, because fixing the architecture closes many findings at once. The free retest confirms the fixes hold, run within the same safety limits as the original engagement.
Standards and compliance
We align the assessment to the frameworks that govern industrial and critical-infrastructure security in Europe.
IEC 62443
The core standard for industrial automation and control system security. We frame findings in its language of zones, conduits and security levels, so your team and any assessor can place each one in the model you already work to.
NIST SP 800-82
The established guide to securing operational technology. Where you report to a framework built on it, we map findings accordingly and keep recommendations consistent with its guidance.
NIS2 Directive
For operators of essential and important services across Europe, NIS2 raises the bar on risk management and incident readiness. Our testing evidence and report support your obligations, and we are a European team that understands how these requirements are being applied across member states.
How an OT attack usually unfolds
The dramatic image of a hacker directly manipulating a turbine is mostly fiction. Real industrial intrusions are patient and mundane, and they almost never start in the OT network at all. Understanding the actual sequence is what lets us test the steps that matter rather than the ones that make good headlines.
It starts in IT
The first foothold is usually a phished credential, an exposed remote-access service, or a vulnerable internet-facing application on the corporate side. None of that is exotic, and none of it touches a PLC yet. This is why the IT estate and its people are part of a serious OT assessment, not a separate concern.
It moves through the boundary
From IT, the attacker looks for the path to OT: a firewall rule that is too permissive, a dual-homed engineering workstation, a jump host with weak controls, or a management network that quietly spans both. The strength of this boundary is the single biggest factor in whether an IT compromise ever becomes an OT one, so we spend disproportionate effort proving whether it holds.
It reaches the process last
Only once inside the control network does the attacker interact with HMIs, historians and controllers, often using entirely legitimate protocol commands because the protocols themselves ask for no proof of identity. By the time we are testing this stage, the point is usually already made: if the earlier steps succeed, the process is exposed. We demonstrate that chain end to end, safely, rather than leaving you to assume it.
Why manual, process-aware testing is the only safe option
You cannot point a generic vulnerability scanner at a live control network and expect to walk away with your plant still running. Aggressive scanning has crashed PLCs and tripped processes, which is exactly why an OT assessment demands an engineer who knows both offensive security and industrial systems, and who understands when to stop and use a passive technique instead. The value is not just what we find, it is finding it without becoming the incident. That judgement, built from real engagements in live industrial environments, is not something a tool can supply, and it is the reason we scope OT work by hand and refuse to treat it as a bigger version of a network scan.
Pricing
Pricing depends on scope: the number of sites and zones, whether a lab or test environment is available for intrusive work, how many device types and protocols are in play, and the depth of architecture review. Here is the shape of a typical European engagement.
| Engagement | What’s included | Timeline | Price |
|---|---|---|---|
| Architecture & boundary review | Purdue-model and IEC 62443 zone review, IT-to-OT segmentation testing, remote-access assessment, full report, free retest | 5–8 working days | from €4,500 |
| Standard | Boundary review plus passive control-network analysis and protocol testing at one site, exec + technical report | 8–12 working days | €6,000–€14,000 |
| Advanced | Multi-zone or multi-site estate, lab-based active device and PLC testing, safety-system isolation review, attack-chaining | 12–25 working days | €14,000–€35,000 |
| Compliance add-on | Mapping and attestation letter for IEC 62443, NIS2, ISO 27001 or SOC 2 | with any tier | from €1,000 |
| Custom / multi-site | Full industrial estate across sites, scoped after a site call | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and a retest included. Get a fixed quote
FAQ
How much does OT ICS SCADA penetration testing cost?
Will the test disrupt our production or trip a safety system?
Do you test on our live network or a lab?
What do you actually deliver?
Does this support IEC 62443 or NIS2 compliance?
Which industrial protocols do you cover?
Can you test remote access and vendor connections?
Do you work across multiple sites and countries?
Related services
Manufacturers, utilities, energy and water operators, transport and logistics, and any operator of essential services facing NIS2 or IEC 62443 obligations who needs to know whether an attacker on the business network can reach the plant floor, tested safely and without stopping production.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.