Penetration Testing Hub › Penetration Testing Explained
OT & ICS Penetration Testing: Why It's Different
Only assess OT/ICS environments you own or operate, or have explicit written permission to test. Unauthorised access to a control system is a criminal offence in Ireland under the Criminal Justice (Offences Relating to Information Systems) Act 2017 — and in OT, unauthorised or careless testing can also endanger physical safety. Everything below assumes an authorised assessment of your own environment.
Operational technology — the PLCs, SCADA systems, RTUs and building-management controllers that run plants, utilities, manufacturing lines and campuses — cannot be tested like an IT network. The difference isn't a matter of degree. Run a standard vulnerability scanner against a live PLC and you can crash it, and crashing a PLC can stop a production line, trip a safety system, or worse. This page explains why OT testing is its own discipline, how it's done safely, and how to spot a provider who'll hurt you.
This is the area most Irish cybersecurity firms won't touch or don't understand. It's worth understanding properly.
1. Why it's different
- Availability beats confidentiality. In IT, you protect data. In OT, the priority is keeping the process running safely. A test that risks downtime is often worse than the vulnerability it finds.
- Fragile devices. Many controllers have tiny stacks and were never built to survive a port scan. Legitimate IT tools can hang or crash them.
- Physical consequences. A misstep doesn't corrupt a spreadsheet — it can open a valve, stop a pump, or disable a safety interlock.
- Ancient kit. OT systems live for decades. You'll meet unpatched Windows XP, unauthenticated protocols (Modbus, DNP3, S7) and equipment the vendor no longer supports.
- You can't just patch. Change windows are rare, vendor-controlled, and safety-critical. 'Just update it' isn't available.
2. How it's done safely
Architecture and documentation review first
Most of the value comes before anything is touched. The assessor reviews the network architecture against the Purdue model — are IT and OT properly segmented, is there a real DMZ between them, can someone pivot from the business network to the plant floor? Firewall rules, remote-access paths, and data flows between levels are examined on paper and in config, not by probing live devices.
Passive analysis
Where live analysis happens, it's passive: a network tap or span port captures traffic for analysis without sending anything to the controllers. This reveals the protocols in use, unauthenticated commands, cleartext credentials, and rogue connections — all without risking a single device.
Active testing only where it's safe
Any active testing happens on the IT/OT boundary, on engineering workstations and historians, or on a lab or offline replica of the control environment — never blindly against live production controllers. Testing a PLC's response to malformed input, if done at all, is done on a spare unit on a bench, in a scheduled window, with the process owner present.
What it usually finds
Flat networks where the office and the plant share a broadcast domain, a jump box with a shared password bridging IT and OT, remote-access tools installed by a vendor and forgotten, unauthenticated control protocols, and no monitoring on the OT network at all.
3. What to look for — the self-check
- IT and OT networks are genuinely segmented, with a DMZ between them (Purdue-aligned).
- No engineering workstation has a straight path to the internet.
- Vendor remote-access tools are inventoried, controlled, and disabled when not in use.
- Default credentials on HMIs, PLCs and historians have been changed where the vendor allows.
- There is passive monitoring on the OT network — you'd notice new devices or unusual commands.
- Safety-instrumented systems are isolated from the general control network.
- You have an asset inventory of every controller, its firmware, and its owner.
- Backups of PLC logic and HMI configs exist and have been tested.
The one rule
If a provider offers to run a normal vulnerability scanner against your live ICS, or can't explain how they'll avoid touching production controllers, walk away. In OT, the wrong test is more dangerous than no test.
4. What to expect / when you need a pro
OT assessment is almost always a professional engagement — the safe-DIY portion is the architecture and segmentation self-check above, plus building your asset inventory. Everything beyond that needs someone who understands control systems and safety. Expect the work to lean heavily on review and passive analysis, to require the process owner and often the equipment vendor at the table, and to be scheduled around production and maintenance windows. Expect a good assessor to say 'we won't touch that live' far more often than in IT. That caution is the competence.
If you run a plant, a utility, a campus or a manufacturing line, this is the assessment where the 'when you need a pro' line sits closest to the top of the page — and where the cheapest, safest, most valuable work (segmentation and monitoring) can start before any active testing at all.
Common questions
Can you run a penetration test on OT or ICS systems?
Yes, but never like an IT network. Active scanning can crash a PLC and stop a production line, so OT assessment leans on architecture review, segmentation analysis and passive traffic capture, with any active testing confined to lab replicas or the IT/OT boundary in agreed windows. If a provider offers to scan live ICS, walk away.
What is the Purdue model?
A reference architecture for industrial networks that layers systems from the plant floor (controllers, sensors) up to enterprise IT, with defined boundaries between levels. It's the framework OT assessors use to judge whether your IT and OT are properly segmented and whether an attacker could pivot from the office network to the control system.
Why can't you just patch OT systems like IT systems?
OT devices often run for decades on unsupported software, sit in safety-critical processes, and can only be changed in rare vendor-controlled windows. 'Just update it' usually isn't available, so OT security relies more on segmentation, monitoring and access control than on patching — which is exactly why testing focuses there too.
If you run OT or ICS and want an assessment that improves your security without endangering your process, that's exactly the work we're built for — here's how a CyberLabs OT engagement works, starting with the safe, high-value segmentation review.
No prices on this page and no hard sell.
This page is educational and not legal advice. Only test systems you own or are explicitly authorised to test. · ↑ Back to top