The challenge behind the engagement.
Operational technology security testing examines industrial control environments with a plan built around safety and availability first. Our approach follows the accepted guidance for this work: we favor passive observation and architecture and configuration review, and any hands-on testing is done cautiously and, where possible, on spare or test-bench systems first. We review how the business and control networks are separated, the remote paths into the control environment, the exposure of the communications between control devices, and the hardening of operator workstations and control interfaces. Safety-critical systems stay out of hands-on testing unless you agree a maintenance window in writing. You receive an assessment of how the control network is divided and protected, findings prioritized by safety and availability impact, and a retest where it is safe to run one.
For plant, manufacturing, utility, and critical-infrastructure operators who need their operational technology tested without risking a process. Common ahead of a control-system security program, an insurer’s review, or the integration of a newly acquired site.
What we do.
What you can use.
Plan around safety
We collect network diagrams and an asset inventory, identify the safety-critical systems to exclude from hands-on testing, and agree maintenance windows for anything active. You provide a site-safety briefing and supervised access, and we agree that testing pauses on any process anomaly.
Test cautiously
We favor passive observation and architecture review, trying active tools on spare or test-bench systems first where possible. We assess how the business and control networks are separated, the remote paths in, the exposure of control-device communications, and the hardening of operator workstations and control interfaces.
Prioritize by safety and retest
You receive an assessment of how the control network is divided and protected, findings prioritized by safety and availability impact with severity ratings that account for safety, and remediation aligned to recognized control-system security guidance. We retest where it is safe.
Who it’s for.
When you need it.
- Plant, manufacturing, utility, and critical-infrastructure operators running industrial control environments
- Organizations that must test operational technology without risking safety or availability
- Teams starting a control-system security program and needing a current baseline
- Operators integrating a newly acquired site with its own control network
- An insurer, regulator, or customer is asking about operational technology security
- A new site, control system, or remote-access path was added to the environment
- A new control-system security program or a segmentation review is getting under way
- IT and OT networks were connected or converged without an independent review
What the scope can include.
- 01
Review how the business and control networks are separated
- 02
Assess remote-access paths into the control environment
- 03
Check the exposure of communications between control devices
- 04
Review the hardening of operator workstations and control interfaces
- 05
Map how the control network is divided and protected
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and reporting, plus a retest of your fixes, included. Find the size closest to yours.
One production line or small facility, mostly observation and design review
About 40–60 hoursOne full plant or facility, including remote access paths and operator stations
About 64–100 hoursSeveral plants or a regional utility, phased site by site
About 120+ hours- Number of sites and on-site days needed
- Observation only, or hands-on testing during maintenance windows
- Number of paths between the business and control networks
- Availability of spare or test-bench equipment
Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Assessment of how the control network is divided and protected
- Findings prioritized by safety and availability impact with severity ratings
- Remediation aligned to recognized control-system security guidance
- Retest of remediated findings where it is safe to run one
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
Will testing risk taking a process offline?
That risk drives the whole plan. We default to passive observation and configuration review, and we try active tools on spare or test-bench systems before anything live, as the accepted guidance for this work advises. Safety-critical systems stay out of hands-on testing unless you agree a window in writing. We pause on any process anomaly, and you control a stop at all times.
Can you do passive-only if we cannot allow active testing?
Yes. Many engagements are passive by design: traffic capture, architecture and configuration review, and interviews, with no active probing of live controllers. You still get an assessment of how the control network is divided and protected, segmentation findings, and remediation mapped to recognized control-system guidance. Active testing can be added later for specific systems during an agreed maintenance window.
- NIST SP 800-115: Technical Guide to Information Security Testing and Assessment
- OWASP Web Security Testing Guide
- OWASP Top 10 API Security Risks – 2023
- Common Vulnerability Scoring System version 4.0: Specification Document
- NIST SP 800-82 Rev. 3: Guide to Operational Technology (OT) Security
- Penetration Testing - Amazon Web Services (AWS)
