OT Penetration Testing Services

We reached the PLC. We left the process alone.

From a seat on the business network, a senior U.S. engineer reaches the controller running your line, then stops where you told us to. Proving the controller is reachable is the finding. Anything that could touch production is agreed with your team first, in writing.

  1. IT Business network Where a phish lands. Segmented
  2. HMI Operator console Default credentials. Segmented
  3. PLC Line controller Answering from the office. Reachable from IT. Critical.
  4. SIS Safety PLC Emergency shutdown. You told us to stop here. Off limits
  • Off limits The line you drew in scoping
  • Segmented What the diagram claims

Nothing replaces skill. Illustrative path. Every step was agreed with the customer first, including where it ends.

What We Test

Knowing what not to touch is most of the job. We scope with your operators, put availability ahead of coverage, and prove reach without proving it the hard way.

SCADA & ICS

SCADA servers, historians, and HMI interfaces, tested for unauthorized monitoring and control.

PLCs, RTUs & Controllers

Field devices probed for default credentials, insecure firmware, and open programming interfaces.

IT/OT Boundary

Where enterprise access crosses into control systems, the vector behind most industrial breaches.

Industrial Protocols

Modbus, DNP3, OPC UA, EtherNet/IP, and more, analyzed for command injection and replay.

Remote Access

Jump hosts, VPNs, and third-party pathways that tunnel straight into the plant.

Network Segmentation

Whether the zones on your diagram actually hold, from the enterprise down to the process.

How We Test

Grounded in NIST SP 800-82 and IEC 62443, and built around one rule: your operations keep running.

01

Scope & Coordinate

We set scope, critical assets, testing windows, and ground rules with your operations and engineering teams. No surprises.

02

Review on Paper

Diagrams, asset inventories, and firewall rules first, so we find high-risk paths before touching a live system.

03

Passive, Then Careful

We map traffic without sending a disruptive packet, then run targeted active tests with your team standing by.

04

Show the Chain, Stop Short

We demonstrate how far an attacker reaches, up to the controller, and stop there. Findings land in Raxis One with fixes written for OT.

Findings We See in the Wild

What we find in plants, every one of them proved without taking a process offline.

Flat IT/OT Networks

No real boundary between the office and the plant floor, one phish from the controllers.

Default Controller Credentials

PLCs and HMIs running exactly as they left the factory.

Plaintext Protocols

Modbus and DNP3 with no authentication, open to replay and command injection.

Exposed Remote Access

Vendor VPNs and jump hosts that tunnel past every control at once.

No MFA on the Bridge

A single password between the enterprise and the process.

Unpatchable Legacy Controllers

Devices that cannot be patched and were never given a compensating control.

Why Raxis for OT

This is not an IT team dabbling in OT. Our engineers know the protocols, the architectures, and the operational reality that availability is non-negotiable.

Availability First, Always

Every test is scoped and coordinated to protect your process. Raxis has never caused an unplanned outage during an OT engagement.

The Whole IT-to-OT Path

Most OT attacks start in IT. We test the full path, from the enterprise network to the controller, so you see the real risk.

Fixes That Fit OT

You cannot always patch a PLC on a running line. We give compensating controls alongside remediation, so your team has options that work.

OT Industries We Protect

OT risk changes with the process. We bring sector experience to the industries where a disruption carries the most.

What You Get

Written by the engineer who walked the path, for the team that has to close it, with remediation that assumes you cannot always patch a controller.

Technical Findings

Each with proof, reproduction steps, and a fix that works on a running line.

Attack Storyboard

The whole path, from the office network to the controller we stopped at.

Compensating Controls

Where patching is not an option, what to put in front of the device instead.

Included Retest

We verify your fixes and deliver a clean final report, at no extra cost.

A Radiation Machine on the Open Network

Our stories are based on real events encountered by Raxis engineers. Some details have been altered or omitted to protect customer identities.

A prominent medical organization brought Raxis in to assess their internal network. They expected the usual: unpatched endpoints, response poisoning, maybe a Kerberoastable service account. What our team found was a direct path from the production network to the control system of a linear accelerator.

Starting at the IT perimeter, we found a subnet with a broader reach than the rest. Using credential pairs harvested from an unprotected internal share, our team mapped the environment, and on the far side of that subnet, everything stopped.

A few “help” commands in a terminal revealed that a control system for one of the hospital’s linear accelerators was reachable from the production network. No compensating controls. No jump host. No MFA. Just an open telnet connection to a system that manages a machine that delivers ionizing radiation to a patient. The device answered. The credentials were exactly as they had left the factory: default username, default password, full access.

A LINAC set to the wrong dose, the wrong field, or without safety interlocks is not a data breach; it is a catastrophe. We stopped, escalated to the CISO and facilities leadership immediately, and went no further in that area. OT risk does not announce itself. It hides in a network diagram nobody updated, and in the quiet assumption that critical systems are isolated because they are supposed to be.

FAQ: OT Penetration Testing

What types of OT systems can Raxis test?

SCADA systems, distributed control systems (DCS), programmable logic controllers (PLCs), remote terminal units (RTUs), human-machine interfaces (HMIs), historian servers, safety instrumented systems (SIS), building automation, and the network infrastructure connecting them. If it controls a physical process, we can assess it.

Will OT penetration testing disrupt my operations?

No. Raxis puts availability above all else. Every test is scoped and coordinated with your operations team, and our engineers use non-intrusive techniques wherever possible. Active testing against live systems happens only with explicit coordination and your team standing by. We prove reach; we do not disrupt the process.

Can Raxis test OT systems on-site?

Yes. Many OT assessments need physical proximity to field devices and industrial networks. Our engineers test on site at your facility, or we deploy the Raxis Transporter for remote testing with onsite-quality results.

How is OT penetration testing different from a standard network pentest?

OT environments use industrial protocols, embedded controllers, and legacy systems that standard tools are not built for and can damage. OT testing requires knowledge of industrial architectures, safety constraints, and the ability to test without disrupting a physical process.

How long does an OT penetration test take?

It depends on environment size and scope. A focused architecture or segmentation review may take one to two weeks. A comprehensive ICS test covering the network, controllers, and IT/OT boundary typically runs two to four weeks. We give you a detailed timeline during scoping.

Do we need an OT pentest if we already do IT penetration testing?

Yes. IT tests do not cover industrial protocols, control system devices, or the OT architecture, and they do not test the IT/OT boundary, which is the most common path into an industrial breach. OT testing fills a gap that IT testing alone cannot.

Who performs the testing?

Senior US-based Raxis engineers holding certifications such as OSCP and OSCE, with hands-on industrial control system experience. No outsourcing, and no junior testers learning on your plant.

What is the difference between OT and IoT penetration testing?

OT testing targets industrial control systems, SCADA, PLCs, and DCS that run physical processes. IoT testing focuses on connected devices, their firmware, wireless communications, and cloud integrations. Both are specialized, and they often meet where connected devices reach the plant floor.

Request a quote

Tell Us What You Need Tested

We usually respond in one business day.

Please let us know what's on your mind. Include any details about your target environment, timeline, or compliance drivers.