Cyber Security Testing
SCADA / ICS Security Testing
Safety-first assessment of operational technology, PLCs and industrial protocols.
Every engagement includes manual validation, a two audience report and free re-testing.
Get a scoped quote+91 96682 00222What this actually is
Testing operational technology is not the same job as testing IT, and treating it that way is how people cause outages. A scan that is routine on a corporate network can knock a PLC offline, and on a plant floor that has physical consequences.
We work safety first. Passive analysis wherever possible, active testing only in agreed windows with engineering in the room, and a rollback plan for anything we touch. We have not caused a production stoppage and we intend to keep it that way.
The usual finding is not a vulnerable controller. It is a flat network where the corporate side and the plant side can reach each other, which turns an ordinary ransomware incident into a production shutdown.
What we go after
- Passive OT asset discovery and protocol inventory
- IT and OT segmentation validation against the Purdue model
- PLC, RTU and HMI configuration review
- Industrial protocol analysis including Modbus, DNP3 and OPC
- Engineering workstation and jump host security
- Vendor and integrator remote access review
- Safety instrumented system separation
- Incident readiness for an OT event
How we run it
- 01
Scope and authorise
Targets, testing windows, escalation contacts and safety limits, all agreed in writing before anyone touches anything.
- 02
Map the surface
We enumerate what is actually exposed, which is usually more than the asset register says.
- 03
Test by hand
Tooling gives coverage, our engineers give proof. Every finding is reproduced before it is written down.
- 04
Report
An executive narrative your board can act on, and a technical annexe with the exact request, payload and fix.
- 05
Re-test and sign off
Once you have fixed it we verify each one at no extra cost, then close the engagement properly.
What you receive
- OT asset inventory built without disrupting operations
- Segmentation assessment against IEC 62443 zones and conduits
- Findings rated by safety and production impact, not just CVSS
- Prioritised hardening plan that respects change windows
- Incident response guidance specific to your plant
Who needs this
Manufacturing, utilities, energy, water, transport and any operator whose downtime has physical or public safety consequences.
How long it takes
Two to four weeks, scheduled around your maintenance windows.
Standards this satisfies
- IEC 62443
- NIST SP 800-82
- CERT-In
- ISO 27001
Why it matters
In an industrial environment the worst outcome is not data loss, it is a process behaving differently from what the operator sees. That is why this testing is conducted passively first and never writes to a controller on a live line.
Convergence is the pressure. Remote maintenance, plant analytics and ERP integration each punch a hole through the IT to OT boundary, and those holes are rarely on the diagram.
Choose the depth you actually need
Most of the price difference between quotes comes down to this one choice, and it is rarely explained. Pick one to see what it covers, what it suits and what it costs you.
You give us working accounts at each privilege level and a short walkthrough. We then test what a real attacker reaches after the first stolen password, which is where the findings that matter almost always live. This is what we recommend for most engagements.
Choose this when
- Any application with authenticated functionality
- Multi-tenant products, where tenant isolation is the real risk
- Getting the most findings for the money
Effort and cost
Moderate effort and by far the best coverage per rupee. Most of the serious findings we report come out of authenticated testing rather than unauthenticated.
Assessed against IEC 62443
Industrial testing is scoped to the zone and conduit model in IEC 62443, with findings mapped to a target security level per zone. That lets you prioritise by consequence rather than by CVSS score, which means very little on a plant floor.
Scope it yourself, before you call anyone
Answer a few questions and you get an indicative number, the working behind it and what your answers tell us. It runs in your browser, so nothing you type reaches us.
What needs testing?
Pick everything in scope. Effort is driven by unique functionality, not by how many IP addresses you own.
What we look for, and keep finding
These are the classes of problem this work exists to surface. Not every engagement finds all of them, but these are the ones that turn up often enough to be worth naming.
IT to OT boundary failure
The route every published industrial attack has used. We map every path from the corporate network into the control environment, including the ones created for projects and left in place.
Unauthenticated industrial protocols
Modbus, DNP3 and their relatives assume a trusted network. Anyone who reaches the segment can often issue commands, which makes segmentation the primary control rather than a secondary one.
Vendor remote access
Permanent tunnels with shared credentials and no logging, established so a supplier can maintain their equipment. The supplier's security posture silently becomes yours.
Unpatchable legacy assets
Devices that cannot be updated without invalidating certification. The finding is not the missing patch, it is whether the compensating isolation actually holds when tested.
Firmware and physical interfaces
Debug ports, unsigned firmware and extractable secrets on devices sitting in places no one supervises. We assess these in a lab rather than on a live line.
Who runs your engagement
A senior tester, named before you sign
Testing is led by an engineer holding OSCP, CREST or equivalent, and you are told who it is before the engagement starts. They write the report themselves rather than handing notes to someone else, and they are on the call when findings are walked through. If the person changes, we tell you why.
Questions we get asked
Will this risk our production line?
We design the engagement so it does not. Passive first, active testing only in agreed windows with your engineers present, and an agreed stop word that halts everything immediately.
Our OT network is air gapped. Do we still need this?
In our experience genuinely air-gapped networks are rare. There is usually a historian, a vendor laptop or a remote support link. Part of the work is finding out whether the gap is real.
Often scoped alongside
- Web Application Security TestingOWASP-aligned manual and automated testing of web applications, with validated proof-of-concept for every finding.Read more
- Mobile Apps Security TestingAndroid and iOS binary, runtime and API-layer assessment against OWASP MASVS.Read more
- Network Penetration TestingInternal and external network exploitation, lateral movement and privilege escalation testing.Read more
- API Security TestingAuthentication, authorisation, rate-limiting and business-logic testing across REST, GraphQL and gRPC.Read more
Ready to scope your scada / ics security testing?
Thirty minutes with a senior engineer, and you leave with a written scope and indicative effort.












