Penetration Testing Hub › Penetration Testing Explained

OT & ICS Penetration Testing: Why It's Different

Before you do anything

Only assess OT/ICS environments you own or operate, or have explicit written permission to test. Unauthorised access to a control system is a criminal offence in Ireland under the Criminal Justice (Offences Relating to Information Systems) Act 2017 — and in OT, unauthorised or careless testing can also endanger physical safety. Everything below assumes an authorised assessment of your own environment.

Operational technology — the PLCs, SCADA systems, RTUs and building-management controllers that run plants, utilities, manufacturing lines and campuses — cannot be tested like an IT network. The difference isn't a matter of degree. Run a standard vulnerability scanner against a live PLC and you can crash it, and crashing a PLC can stop a production line, trip a safety system, or worse. This page explains why OT testing is its own discipline, how it's done safely, and how to spot a provider who'll hurt you.

This is the area most Irish cybersecurity firms won't touch or don't understand. It's worth understanding properly.

1. Why it's different

2. How it's done safely

Architecture and documentation review first

Most of the value comes before anything is touched. The assessor reviews the network architecture against the Purdue model — are IT and OT properly segmented, is there a real DMZ between them, can someone pivot from the business network to the plant floor? Firewall rules, remote-access paths, and data flows between levels are examined on paper and in config, not by probing live devices.

Passive analysis

Where live analysis happens, it's passive: a network tap or span port captures traffic for analysis without sending anything to the controllers. This reveals the protocols in use, unauthenticated commands, cleartext credentials, and rogue connections — all without risking a single device.

Active testing only where it's safe

Any active testing happens on the IT/OT boundary, on engineering workstations and historians, or on a lab or offline replica of the control environment — never blindly against live production controllers. Testing a PLC's response to malformed input, if done at all, is done on a spare unit on a bench, in a scheduled window, with the process owner present.

What it usually finds

Flat networks where the office and the plant share a broadcast domain, a jump box with a shared password bridging IT and OT, remote-access tools installed by a vendor and forgotten, unauthenticated control protocols, and no monitoring on the OT network at all.

3. What to look for — the self-check

The one rule

If a provider offers to run a normal vulnerability scanner against your live ICS, or can't explain how they'll avoid touching production controllers, walk away. In OT, the wrong test is more dangerous than no test.

4. What to expect / when you need a pro

OT assessment is almost always a professional engagement — the safe-DIY portion is the architecture and segmentation self-check above, plus building your asset inventory. Everything beyond that needs someone who understands control systems and safety. Expect the work to lean heavily on review and passive analysis, to require the process owner and often the equipment vendor at the table, and to be scheduled around production and maintenance windows. Expect a good assessor to say 'we won't touch that live' far more often than in IT. That caution is the competence.

If you run a plant, a utility, a campus or a manufacturing line, this is the assessment where the 'when you need a pro' line sits closest to the top of the page — and where the cheapest, safest, most valuable work (segmentation and monitoring) can start before any active testing at all.

Common questions

Can you run a penetration test on OT or ICS systems?

Yes, but never like an IT network. Active scanning can crash a PLC and stop a production line, so OT assessment leans on architecture review, segmentation analysis and passive traffic capture, with any active testing confined to lab replicas or the IT/OT boundary in agreed windows. If a provider offers to scan live ICS, walk away.

What is the Purdue model?

A reference architecture for industrial networks that layers systems from the plant floor (controllers, sensors) up to enterprise IT, with defined boundaries between levels. It's the framework OT assessors use to judge whether your IT and OT are properly segmented and whether an attacker could pivot from the office network to the control system.

Why can't you just patch OT systems like IT systems?

OT devices often run for decades on unsupported software, sit in safety-critical processes, and can only be changed in rare vendor-controlled windows. 'Just update it' usually isn't available, so OT security relies more on segmentation, monitoring and access control than on patching — which is exactly why testing focuses there too.

If you'd rather we did this

If you run OT or ICS and want an assessment that improves your security without endangering your process, that's exactly the work we're built for — here's how a CyberLabs OT engagement works, starting with the safe, high-value segmentation review.

No prices on this page and no hard sell.

See how working with us works →

This page is educational and not legal advice. Only test systems you own or are explicitly authorised to test.  ·  ↑ Back to top