Can an attacker reach the systems that control your operations?
Lean Security provides specialist penetration testing and adversarial security assessments for Operational Technology (OT) and Industrial Control System (ICS) environments. We test whether attackers can move from enterprise IT, remote access, or third-party connections into operational networks — within agreed operational constraints.
Understanding How Attackers Traverse IT/OT Boundaries
Many OT environments now connect to enterprise IT and remote-support services. Cloud analytics, vendor maintenance tunnels, and corporate network integrations improve operations, but they also introduce attack pathways across Purdue boundaries.
Rather than relying on checklist assumptions, we test agreed attack paths within scope to determine whether an enterprise or remote-access compromise can extend across security zones toward production systems:
- Enterprise-to-DMZ Breakout: Testing firewall filtering, jump hosts, and routing controls between corporate IT and the industrial DMZ.
- Shared Identity Exposure: Identifying Active Directory trusts, local administrative credential reuse, and privilege escalation pathways bridging IT and OT systems.
- Controller Reachability: Validating whether industrial services and controllers are reachable from unauthorised network positions.
What We Test Across Your Industrial Environment
Assessments are scoped around your plant architecture, technology stack, and agreed operational constraints. We evaluate agreed attack paths within scope across four primary domains:
Safety-Conscious Testing Within Operational Constraints
Production OT environments cannot be treated like ordinary corporate networks. As highlighted in NIST SP 800-82r3 guidance, active scanning and unconstrained network probes can destabilise sensitive industrial devices, saturate fragile serial links, or disrupt critical timing loops.
Testing is planned in close partnership with plant operators and automation engineers, adhering to agreed operational constraints:
| Activity Category | Testing Method | Operational Conditions & Controls | Production Status |
|---|---|---|---|
| Passive Discovery & Asset Mapping Permitted | Network TAP/SPAN analysis, passive traffic capture, protocol decoding | Zero active packets introduced; conducted during normal operations | Permitted |
| Segmentation & Boundary Testing Permitted | Firewall rule verification, egress testing, DMZ bypass validation | Coordinated with network engineers; targeted packets only | Permitted |
| Identity & Workstation Review Supervised | Credential hygiene, Active Directory trusts, privilege escalation review | Conducted on designated jump hosts; supervised execution | Supervised |
| Controller Service Reachability Constrained | Verifying route reachability to controller ports (e.g. TCP/102, TCP/502) | Targeted connectivity checks with agreed rate, retry and device-specific limits | Constrained |
| Logic Changes & Process Manipulation Excluded | Overwriting PLC ladder logic, setpoint changes, operating states (RUN/STOP) | Strictly excluded from live plant; separately scoped on testbeds or offline systems | Excluded |
| Safety Instrumented Systems (SIS) Excluded | Interrogating safety instrumented functions or emergency shutdown logic | Safety systems are strictly excluded from active testing | Excluded |
Testing Policy: Activities capable of modifying controller logic, process variables, or safety system states are strictly excluded from live production testing. Deeper behavioural validation—such as protocol fuzzing, logic verification, or failure-mode testing—is performed exclusively on isolated test equipment (bench or staging testbeds) or on offline production equipment isolated from live physical processes under a separately approved scope and rollback plan.
Evidence-Led Reporting for Engineering & Executive Teams
A generic vulnerability scanner dump creates friction for plant engineers. Lean Security delivers clear reporting structured for practical remediation and executive governance:
- Executive Briefing: Clear translation of operational risk and Purdue boundary exposure for leadership and board stakeholders.
- Validated Attack Paths: Step-by-step evidence documenting reachable pathways across agreed assessment boundaries.
- Engineering Remediation Guidance: Actionable steps that respect existing control system communication, HMIs, and SCADA dependencies.
- Certificate of Penetration Testing: Formally records assessment scope, dates, and tested boundaries; does not certify statutory compliance or standard conformity.
Unauthorised S7comm Controller-Service Reachability from Corporate Subnet
A routing and firewall segmentation weakness permits direct TCP port 102 (ISO-on-TCP) reachability from corporate IT workstations (VLAN 20) to controller IP 10.240.40.15 at Purdue Level 1, violating the network zone separation policy.
102/tcp open iso-tsap
Target host confirmed as Siemens S7-1500 controller via plant network inventory records. No active protocol commands, variable queries, or setpoint reads were executed during connectivity testing.
Direct service reachability creates an unsegmented network path toward basic control equipment if corporate IT is compromised. Actual exploitation potential is constrained by lack of direct process variable exposure and requires proprietary protocol communication.
Enforce stateful firewall filtering at the Purdue Level 3.5 / Level 2 boundary to block direct corporate traffic to Level 1 subnets. Restrict controller communication strictly to authorised Engineering Workstations and supervisory SCADA/HMI hosts.
Why Lean Security for OT & ICS Testing
We deliver evidence-based security testing designed around the operational realities of industrial infrastructure:
Assessments are led and conducted directly by experienced offensive security consultants with practical operational technology awareness.
We evaluate realistic lateral movement, identity exposure, and segmentation weaknesses rather than producing large catalogues of scanner noise.
Testing is planned in close partnership with plant operators and automation engineers to ensure operational availability is protected throughout.
We translate technical findings into defensible operational risk for executives, accompanied by component-level remediation steps that respect existing control system communication.
When Organisations Commission OT Security Testing
Validate whether a compromise of enterprise IT (such as ransomware or phishing) could provide a pathway into operational environments.
Security-test new industrial systems, SCADA platforms, or remote-access architectures prior to commissioning.
Confirm that firewalls contain lateral movement, and audit remote maintenance and vendor access pathways.
Support security programmes aligned with ISA/IEC 62443, SOCI/CIRMP, and ASD/ACSC OT security guidance within the agreed scope.
Frequently Asked Questions
Discuss Your OT Security Testing Scope
If you operate SCADA, PLC, HMI, or other industrial control environments, we can help determine whether your existing security controls withstand realistic attack paths within your operational constraints.