Operational Technology (OT) & ICS Assurance

Can an attacker reach the systems that control your operations?

Lean Security provides specialist penetration testing and adversarial security assessments for Operational Technology (OT) and Industrial Control System (ICS) environments. We test whether attackers can move from enterprise IT, remote access, or third-party connections into operational networks — within agreed operational constraints.

ISA/IEC 62443 & AESCSF aligned
Planned around safety & availability
SOCI Act & CIRMP assurance
Senior offensive specialists

Understanding How Attackers Traverse IT/OT Boundaries

Many OT environments now connect to enterprise IT and remote-support services. Cloud analytics, vendor maintenance tunnels, and corporate network integrations improve operations, but they also introduce attack pathways across Purdue boundaries.

Rather than relying on checklist assumptions, we test agreed attack paths within scope to determine whether an enterprise or remote-access compromise can extend across security zones toward production systems:

  • Enterprise-to-DMZ Breakout: Testing firewall filtering, jump hosts, and routing controls between corporate IT and the industrial DMZ.
  • Shared Identity Exposure: Identifying Active Directory trusts, local administrative credential reuse, and privilege escalation pathways bridging IT and OT systems.
  • Controller Reachability: Validating whether industrial services and controllers are reachable from unauthorised network positions.
LEVEL 4 / 5 — ENTERPRISE IT & CLOUD Corporate Endpoints · Active Directory / Entra ID · Remote Access Services Corporate Workstation Phished user / initial access position CORPORATE PERIMETER FIREWALL (PURDUE BOUNDARY) LEVEL 3.5 — INDUSTRIAL DMZ Dual-Homed Jump Hosts · Data Historian Mirrors · Vendor Maintenance Gateways DMZ Jump Host Shared administrative credentials identified INDUSTRIAL OT FIREWALL (SECURITY ZONE BOUNDARY) LEVEL 2 / 3 — SUPERVISORY & OPERATIONS SCADA Servers · HMI Consoles · Engineering Workstations (EWS) Engineering Workstation Lateral movement via cached operator privileges LEVEL 0 / 1 — BASIC CONTROL & FIELD EQUIPMENT PLCs · RTUs · IEDs · Safety Instrumented Systems (SIS) Field Controller (PLC) Unauthorised service reachability (TCP/102)
Figure 1: Illustrative IT-to-OT attack path. Assessment evaluates whether lateral movement can cross the Level 3.5 DMZ into supervisory systems and identify reachable controller services, without active controller manipulation.

What We Test Across Your Industrial Environment

Assessments are scoped around your plant architecture, technology stack, and agreed operational constraints. We evaluate agreed attack paths within scope across four primary domains:

IT-to-OT Boundaries & Industrial DMZ
Validating Purdue Level 3.5 demilitarised zones, firewall rule enforcement, dual-homed system configurations, jump hosts, and cross-zone routing controls separating enterprise IT from operational networks.
Identity, Credentials & Workstations
Auditing shared Active Directory trusts, local administrative credential reuse, and privilege escalation pathways on Engineering Workstations (EWS), jump hosts, and operational management consoles.
Supervisory Systems (SCADA & Historians)
Assessing human-machine interfaces (HMIs), supervisory servers, and enterprise time-series historians for unauthenticated network access, software flaws, and session management weaknesses.
Industrial Protocols & Controller Reachability
Verifying network reachability and configuration exposure of PLCs, RTUs, and industrial services (Modbus TCP, Siemens S7comm, DNP3, CIP / EtherNet/IP, OPC UA) from unauthorised network segments.
Assessment Objective
Determine whether a realistic attacker could reach systems capable of affecting production, safety, or operational availability within the agreed scope.

Safety-Conscious Testing Within Operational Constraints

Production OT environments cannot be treated like ordinary corporate networks. As highlighted in NIST SP 800-82r3 guidance, active scanning and unconstrained network probes can destabilise sensitive industrial devices, saturate fragile serial links, or disrupt critical timing loops.

Testing is planned in close partnership with plant operators and automation engineers, adhering to agreed operational constraints:

Activity Category Testing Method Operational Conditions & Controls Production Status
Passive Discovery & Asset Mapping Permitted Network TAP/SPAN analysis, passive traffic capture, protocol decoding Zero active packets introduced; conducted during normal operations Permitted
Segmentation & Boundary Testing Permitted Firewall rule verification, egress testing, DMZ bypass validation Coordinated with network engineers; targeted packets only Permitted
Identity & Workstation Review Supervised Credential hygiene, Active Directory trusts, privilege escalation review Conducted on designated jump hosts; supervised execution Supervised
Controller Service Reachability Constrained Verifying route reachability to controller ports (e.g. TCP/102, TCP/502) Targeted connectivity checks with agreed rate, retry and device-specific limits Constrained
Logic Changes & Process Manipulation Excluded Overwriting PLC ladder logic, setpoint changes, operating states (RUN/STOP) Strictly excluded from live plant; separately scoped on testbeds or offline systems Excluded
Safety Instrumented Systems (SIS) Excluded Interrogating safety instrumented functions or emergency shutdown logic Safety systems are strictly excluded from active testing Excluded

Testing Policy: Activities capable of modifying controller logic, process variables, or safety system states are strictly excluded from live production testing. Deeper behavioural validation—such as protocol fuzzing, logic verification, or failure-mode testing—is performed exclusively on isolated test equipment (bench or staging testbeds) or on offline production equipment isolated from live physical processes under a separately approved scope and rollback plan.

Evidence-Led Reporting for Engineering & Executive Teams

A generic vulnerability scanner dump creates friction for plant engineers. Lean Security delivers clear reporting structured for practical remediation and executive governance:

  • Executive Briefing: Clear translation of operational risk and Purdue boundary exposure for leadership and board stakeholders.
  • Validated Attack Paths: Step-by-step evidence documenting reachable pathways across agreed assessment boundaries.
  • Engineering Remediation Guidance: Actionable steps that respect existing control system communication, HMIs, and SCADA dependencies.
  • Certificate of Penetration Testing: Formally records assessment scope, dates, and tested boundaries; does not certify statutory compliance or standard conformity.
FINDING REF: OT-SEC-04 PURDUE LEVEL 1 SEVERITY: MEDIUM

Unauthorised S7comm Controller-Service Reachability from Corporate Subnet

1. Observation

A routing and firewall segmentation weakness permits direct TCP port 102 (ISO-on-TCP) reachability from corporate IT workstations (VLAN 20) to controller IP 10.240.40.15 at Purdue Level 1, violating the network zone separation policy.

2. Evidence & Verification
nmap -Pn -p 102 --open 10.240.40.15
102/tcp open iso-tsap
Target host confirmed as Siemens S7-1500 controller via plant network inventory records. No active protocol commands, variable queries, or setpoint reads were executed during connectivity testing.
3. Operational Impact & Severity Rationale

Direct service reachability creates an unsegmented network path toward basic control equipment if corporate IT is compromised. Actual exploitation potential is constrained by lack of direct process variable exposure and requires proprietary protocol communication.

4. Remediation Guidance

Enforce stateful firewall filtering at the Purdue Level 3.5 / Level 2 boundary to block direct corporate traffic to Level 1 subnets. Restrict controller communication strictly to authorised Engineering Workstations and supervisory SCADA/HMI hosts.

Figure 2: Synthetic report excerpt illustrating Lean Security's finding structure.

Why Lean Security for OT & ICS Testing

We deliver evidence-based security testing designed around the operational realities of industrial infrastructure:

01 / Senior Delivery
Experienced Consultants

Assessments are led and conducted directly by experienced offensive security consultants with practical operational technology awareness.

02 / Attack Paths
Manual Path Validation

We evaluate realistic lateral movement, identity exposure, and segmentation weaknesses rather than producing large catalogues of scanner noise.

03 / Availability
Engineering Coordination

Testing is planned in close partnership with plant operators and automation engineers to ensure operational availability is protected throughout.

04 / Reporting
Evidence-Led Reporting

We translate technical findings into defensible operational risk for executives, accompanied by component-level remediation steps that respect existing control system communication.

When Organisations Commission OT Security Testing

IT/OT Convergence

Validate whether a compromise of enterprise IT (such as ransomware or phishing) could provide a pathway into operational environments.

New Plants & Changes

Security-test new industrial systems, SCADA platforms, or remote-access architectures prior to commissioning.

Segmentation & Vendors

Confirm that firewalls contain lateral movement, and audit remote maintenance and vendor access pathways.

Governance & Assurance

Support security programmes aligned with ISA/IEC 62443, SOCI/CIRMP, and ASD/ACSC OT security guidance within the agreed scope.

Frequently Asked Questions

Do you perform testing against live production systems?
Yes, where appropriate, but testing is strictly constrained. Testing focuses on network segmentation, jump host exposure, lateral movement pathways, and controller reachability. Controller logic modifications, process parameter changes, and safety-system testing are strictly excluded from production environments. Deeper validation is performed on isolated test equipment or offline systems under a separately approved scope.
Do you need to test PLCs directly?
Not always. Significant OT risk can often be demonstrated through compromised credentials, engineering workstations, insecure remote access, weak segmentation, or unauthorised controller reachability without manipulating the physical process. Where deeper controller assessment is needed, it is separately scoped on isolated staging equipment or during scheduled turnaround periods.
Can you test whether corporate IT can be used to attack OT?
Yes. IT-to-OT attack-path validation is a primary focus. We assess whether compromised corporate workstations, shared Active Directory accounts, or permissive firewall rules allow lateral traversal into operational zones.
Can the assessment support compliance or regulatory requirements?
Yes. Testing can be structured to support organisations working with frameworks such as ISA/IEC 62443, SOCI/CIRMP, AESCSF, and ASD/ACSC OT guidance within the agreed scope. The resulting report and certificate record the assessment and its boundaries; they do not certify statutory compliance or standard conformity.
Do you provide remediation retesting?
Yes. Focused retesting is available as a scoped follow-up once identified issues have been addressed by your engineering and network teams.
How do you prevent disruption or plant downtime during testing?
We avoid unconstrained automated scanning, employ targeted connectivity checks with agreed rate and device limits, and maintain direct communication with control room operators throughout active testing windows.
Can this help assess a recent enterprise incident?
Yes. We can evaluate whether an enterprise IT compromise could extend into operational networks. Establishing what historically occurred in your environment remains the domain of digital forensics and incident response.
Scoping Consultation

Discuss Your OT Security Testing Scope

If you operate SCADA, PLC, HMI, or other industrial control environments, we can help determine whether your existing security controls withstand realistic attack paths within your operational constraints.

Key Scoping Considerations for OT Engagements
To help us tailor an appropriate scope and safety plan, please consider:
1. Facility Context: Manufacturing, utilities, transport, or energy operations.
2. Purdue Levels: Enterprise boundary (Level 4/3.5), supervisory (Level 2), or field.
3. Access Model: Remote jump host, simulated enterprise IT, or on-site testing.
4. Operational Windows: Live plant constraints or scheduled turnaround periods.
Lean Security. Specialist cybersecurity consulting based in Sydney, Australia.