Energy & Utilities
Generation, transmission, and distribution under NERC CIP.
We reached the PLC. We left the process alone.
From a seat on the business network, a senior U.S. engineer reaches the controller running your line, then stops where you told us to. Proving the controller is reachable is the finding. Anything that could touch production is agreed with your team first, in writing.
Nothing replaces skill. Illustrative path. Every step was agreed with the customer first, including where it ends.
SCADA servers, historians, and HMI interfaces, tested for unauthorized monitoring and control.
Field devices probed for default credentials, insecure firmware, and open programming interfaces.
Where enterprise access crosses into control systems, the vector behind most industrial breaches.
Modbus, DNP3, OPC UA, EtherNet/IP, and more, analyzed for command injection and replay.
Jump hosts, VPNs, and third-party pathways that tunnel straight into the plant.
Whether the zones on your diagram actually hold, from the enterprise down to the process.
01
We set scope, critical assets, testing windows, and ground rules with your operations and engineering teams. No surprises.
02
Diagrams, asset inventories, and firewall rules first, so we find high-risk paths before touching a live system.
03
We map traffic without sending a disruptive packet, then run targeted active tests with your team standing by.
04
We demonstrate how far an attacker reaches, up to the controller, and stop there. Findings land in Raxis One with fixes written for OT.
No real boundary between the office and the plant floor, one phish from the controllers.
PLCs and HMIs running exactly as they left the factory.
Modbus and DNP3 with no authentication, open to replay and command injection.
Vendor VPNs and jump hosts that tunnel past every control at once.
A single password between the enterprise and the process.
Devices that cannot be patched and were never given a compensating control.
Every test is scoped and coordinated to protect your process. Raxis has never caused an unplanned outage during an OT engagement.
Most OT attacks start in IT. We test the full path, from the enterprise network to the controller, so you see the real risk.
You cannot always patch a PLC on a running line. We give compensating controls alongside remediation, so your team has options that work.
Generation, transmission, and distribution under NERC CIP.
Rail signaling, ports, and pipelines under TSA directives.
Treatment controls where a compromise touches public health.
Network operations and power systems on OT-adjacent technology.
Production lines and robotics where downtime is revenue lost.
Building automation and connected clinical systems, tested with care.
Each with proof, reproduction steps, and a fix that works on a running line.
The whole path, from the office network to the controller we stopped at.
Where patching is not an option, what to put in front of the device instead.
We verify your fixes and deliver a clean final report, at no extra cost.
Our stories are based on real events encountered by Raxis engineers. Some details have been altered or omitted to protect customer identities.
A prominent medical organization brought Raxis in to assess their internal network. They expected the usual: unpatched endpoints, response poisoning, maybe a Kerberoastable service account. What our team found was a direct path from the production network to the control system of a linear accelerator.
Starting at the IT perimeter, we found a subnet with a broader reach than the rest. Using credential pairs harvested from an unprotected internal share, our team mapped the environment, and on the far side of that subnet, everything stopped.
A few “help” commands in a terminal revealed that a control system for one of the hospital’s linear accelerators was reachable from the production network. No compensating controls. No jump host. No MFA. Just an open telnet connection to a system that manages a machine that delivers ionizing radiation to a patient. The device answered. The credentials were exactly as they had left the factory: default username, default password, full access.
A LINAC set to the wrong dose, the wrong field, or without safety interlocks is not a data breach; it is a catastrophe. We stopped, escalated to the CISO and facilities leadership immediately, and went no further in that area. OT risk does not announce itself. It hides in a network diagram nobody updated, and in the quiet assumption that critical systems are isolated because they are supposed to be.
SCADA systems, distributed control systems (DCS), programmable logic controllers (PLCs), remote terminal units (RTUs), human-machine interfaces (HMIs), historian servers, safety instrumented systems (SIS), building automation, and the network infrastructure connecting them. If it controls a physical process, we can assess it.
No. Raxis puts availability above all else. Every test is scoped and coordinated with your operations team, and our engineers use non-intrusive techniques wherever possible. Active testing against live systems happens only with explicit coordination and your team standing by. We prove reach; we do not disrupt the process.
Yes. Many OT assessments need physical proximity to field devices and industrial networks. Our engineers test on site at your facility, or we deploy the Raxis Transporter for remote testing with onsite-quality results.
OT environments use industrial protocols, embedded controllers, and legacy systems that standard tools are not built for and can damage. OT testing requires knowledge of industrial architectures, safety constraints, and the ability to test without disrupting a physical process.
It depends on environment size and scope. A focused architecture or segmentation review may take one to two weeks. A comprehensive ICS test covering the network, controllers, and IT/OT boundary typically runs two to four weeks. We give you a detailed timeline during scoping.
Yes. IT tests do not cover industrial protocols, control system devices, or the OT architecture, and they do not test the IT/OT boundary, which is the most common path into an industrial breach. OT testing fills a gap that IT testing alone cannot.
Senior US-based Raxis engineers holding certifications such as OSCP and OSCE, with hands-on industrial control system experience. No outsourcing, and no junior testers learning on your plant.
OT testing targets industrial control systems, SCADA, PLCs, and DCS that run physical processes. IoT testing focuses on connected devices, their firmware, wireless communications, and cloud integrations. Both are specialized, and they often meet where connected devices reach the plant floor.