Industries
Cyber security for manufacturing & ot.
Operational technology and industrial control systems, tested safely with production in mind.
What is actually going on here
On a plant network the priority order inverts. IT protects confidentiality first; OT protects availability and safety first, and it is right to. A control that risks stopping a line, or worse, misrepresenting a reading to an operator, is a worse outcome than the breach it was meant to prevent.
That is why we test OT differently. Passive first, active only with plant engineering present, and never anything that writes to a controller on a live line. In a decade of OT testing we have caused zero production stoppages, and that is the number we care most about protecting.
The pressure now is that IT and OT are converging whether or not anyone planned it. Remote maintenance, plant analytics and ERP integration each punch a hole through the boundary, and those holes are seldom on the diagram the plant manager has on the wall.
Who regulates you, and what they want
Tick the ones that bind you and we will pull together the evidence each of them actually asks for. Nothing is sent anywhere.
Pick one or more above to see what they expect of you.
What goes wrong in this sector
IT to OT lateral movement
Almost every OT incident starts in IT. A phished corporate account, then a jump host with a route into the plant that was set up for a project years ago and never removed. Finding those routes is most of the value of an OT assessment.
Remote maintenance access
Vendors need remote access to their equipment. It is often a permanent tunnel with shared credentials and no logging, and it bypasses everything you built. The vendor's security posture becomes yours.
SCADA and PLC command injection
Industrial protocols were designed for reliability on a trusted network, not authentication. Anyone who can reach the segment can often issue commands. Segmentation is therefore the primary control, and it needs testing rather than assuming.
Safety instrumented system interference
The most serious category. Interference with a safety system risks people, not data. It is rare and it is the reason OT testing is conducted the careful way it is.
How we work in this sector
- 01
Passive discovery
We build an asset inventory from network observation, without touching a controller. Most plants discover devices they did not know were connected.
- 02
Test the boundary
We test whether the IT to OT separation actually holds, from the IT side, where it is safe to be thorough.
- 03
Active testing with engineering present
Anything active happens with plant engineering in the room, on a planned window, with a stop condition agreed before we begin.
- 04
Report against IEC 62443
Findings map to zones and security levels, so remediation can be prioritised by consequence rather than by CVSS score, which means little on a plant floor.
What we actually keep finding here
Not a threat list copied from a report. These are the patterns that recur across our own engagements in this sector, with an honest note on how often. Where we do not have a precise number we say so rather than inventing one.
- Almost every engagement
An undocumented route from IT into the plant
Set up for a project, never removed. Every published industrial attack has used a path like this, and finding them is most of the value of an OT assessment.
- Most engagements
Vendor remote access with shared credentials and no logging
A permanent tunnel so a supplier can maintain their equipment. Their security posture silently becomes yours.
- Most engagements
Devices on the network nobody knew were connected
Passive discovery routinely surfaces controllers, gateways and engineering workstations absent from every inventory.
- Often
Segmentation assumed from a diagram drawn years ago
The zone model on the wall and the network as built have diverged, usually through additions made under production pressure.
Questions worth asking any provider in this sector
Including us. If a provider cannot answer these clearly, that tells you more than any capability slide will. We would rather you asked them than took our word for it.
- 1
What is your stop condition, and who on our side can invoke it?
- 2
Will discovery be passive, and will anything ever write to a live controller?
- 3
Will you map findings to IEC 62443 zones and security levels rather than CVSS scores?
- 4
How will you handle assets that cannot be patched without invalidating certification?
- 5
Will plant engineering be present for anything active, and on whose schedule?
What we deliver in this sector
- SCADA / ICS / OT security testing
- IoT & embedded device security
- Network architecture review & hardening
- Supply chain & hardware security assessment
- Firmware & protocol level analysis
- Business continuity & disaster recovery review
- Threat monitoring & anomaly detection
- Purdue model segmentation design
Work in this sector
Named engagements where the client has agreed to be named, and anonymised ones where they have not, which is most of them. Named references are available under NDA.
- Client withheld
Automotive supplier, customer security requirement
- Scope
- Assessment driven by a customer contract imposing security requirements stricter than regulation.
- What we found
- No asset inventory for the plant network, and segmentation that had drifted from the documented design.
- Outcome
- Inventory built from passive discovery, zone model corrected, and the customer requirement evidenced.
- Client withheld
Multi-plant manufacturer, IT to OT boundary
- Scope
- Passive discovery first, active testing only with plant engineering present and an agreed stop condition.
- What we found
- Two undocumented routes from corporate into the plant network, both created for projects that had ended.
- Outcome
- Routes removed, conduits documented against an IEC 62443 zone model, monitoring added on what remained.
- Client withheld
Process plant, vendor remote access
- Scope
- Equipment suppliers with standing remote access for maintenance.
- What we found
- A permanent tunnel with shared credentials and no logging, in place for several years.
- Outcome
- Replaced with brokered, time-bounded and individually attributable access, with no loss of maintenance capability.
Questions we get asked in this sector
Will testing stop our line?
It has not in a decade of doing this. Discovery is passive, anything active is scheduled with your engineers present and has an agreed stop condition. We will decline to run a test rather than accept a real risk to production.
Our PLCs are twenty years old and cannot be changed. Now what?
You protect them with the network rather than with the device. Proper zoning, strict conduits and monitoring of the traffic that crosses them. That is exactly the model IEC 62443 describes, and it is a legitimate answer to an unpatchable asset.
Do we need to separate IT and OT completely?
Complete separation is rarely achievable now and often not desirable, because the business wants plant data. The realistic goal is a small number of controlled, monitored conduits instead of the many undocumented ones most plants actually have.
Can you assess plants outside India?
Yes. We deliver plant engagements across several continents and work to whichever standard the group has adopted.
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












