Skip to main content
CERT-In Empanelled Since 2008 — One of India's earliest empanelled cybersecurity auditors for critical infrastructure

OT/SCADA Security Testing for Critical Infrastructure and Industrial Environments

Non-intrusive security assessments that uncover real attack paths across your industrial control systems, SCADA networks, and IT/OT convergence points without disrupting production operations.

6,700+
Assessments
1,000+
Clients
150+
Team
2006
Founded

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

The inversion

In OT the priority order turns upside down, and so does the testing

Where the real path runs

Almost nobody attacks a PLC first

The realistic intrusion path into a control environment starts on the business network and crosses a boundary that everyone believes is tighter than it is. Engineering workstations are the recurring route: dual-homed by convenience, carrying vendor software with broad privileges, often on an older operating system because the engineering suite requires it. Vendor remote access is the second: standing connections created for support, rarely inventoried, frequently sharing credentials across sites, and usually invisible to the team that owns the firewall. Historians and reporting servers are the third, because they exist specifically to move data from the control network to the business one and are therefore permitted to cross. Then there is the flat legacy segment that predates the segmentation project and was never migrated, and the wireless link installed for a contractor in a hurry. Our assessments concentrate there, because that is where an attacker who is not already inside would actually go, and because every one of those can be tested without touching a live controller. Establishing the boundary honestly is the thing most sites have never had done, and it is worth more than a finding list on any single device.

How we assess it

Methods matched to what the system can tolerate

No traffic

Architecture and configuration review

Network design, firewall rule sets, segmentation between levels, remote-access paths and account structure, assessed from documentation and configuration exports without touching the environment.

Listening only

Passive traffic analysis

Observation of control-network traffic from a span or tap to identify assets, protocols and communication patterns, including devices nobody knew were there. No packets are generated.

Where it is safe

Active testing at the IT boundary

Full testing from the business side against the boundary itself, which is where the realistic attack path runs and where testing carries no process risk.

The usual route

Engineering workstations and jump hosts

Assessed directly, including the vendor software, the privilege model and the remote-access tooling installed on them.

Only by arrangement

Deep testing in an agreed window

Anything that could affect a live process is scoped explicitly and scheduled into a planned outage, or performed against a test rig where one exists. Never by surprise.

The framework

Mapped to IEC 62443

Findings expressed against zones, conduits and security levels so the output feeds a certification path instead of sitting beside it.

What we usually find

Four states, in roughly the order of how often we meet them

Four states, in roughly the order of how often we meet them
StateWhat it meansWhat follows
Segmented and verified A boundary between the business and control networks that is enforced by rules matching the diagram, with crossings inventoried. The target state. Where it exists, the remaining work is about monitoring and about the vendor access paths.
Segmented on paper The diagram shows separation; the rule set, the shared directory, the management network and a historian with interfaces on both sides do not. The commonest finding by a wide margin, and it is discovered by reading configuration, not by scanning anything.
Vendor access uninventoried Standing remote-access paths for equipment suppliers that the site owns commercially and does not track technically. A route in that bypasses the boundary entirely, and one where the credentials are frequently shared across sites and across customers.
Asset inventory incomplete Devices on the control network that no current list records, found by listening to the traffic. Not a failure of diligence so much as of turnover: plants change over decades. It is also the precondition for everything else, since a zone model cannot be drawn around assets nobody has named.
Key
  • Target state
  • Blocks the zone model
  • A live route across the boundary

Methodology

What happens between kickoff and the report

Every engagement follows this process through Lemon, our proprietary audit management platform.

Discovery
01

Scoping and Industrial Environment Discovery

Collaborative workshops with OT engineering, IT security, and plant operations teams to document network architecture, identify all ICS assets and communication flows, define assessment boundaries, and establish safety protocols. ShadowMap external reconnaissance identifies internet-facing industrial assets and exposed services.

02

Passive Reconnaissance and Network Mapping

Non-intrusive network traffic analysis to map communication patterns between IT and OT zones. Identification of ICS protocols in use, device inventories, firmware versions, and network topology without sending active probes to sensitive industrial controllers.

03

IT/OT Boundary and Segmentation Assessment

Detailed evaluation of firewall configurations, DMZ architecture, data diode implementations, and access control lists governing traffic between enterprise IT and operational technology networks. Identification of unauthorised cross-zone communication paths.

Testing
04

ICS Protocol and Device Security Testing

Controlled assessment of industrial protocol implementations including Modbus TCP/RTU, DNP3, OPC UA, and PROFINET. Evaluation of authentication mechanisms, encryption usage, command validation, and protocol-level attack vectors — conducted in coordination with plant operations.

05

IT/OT Convergence Attack Path Analysis

Red team-style evaluation tracing realistic attack chains from enterprise IT environments through convergence points into OT networks. Validates whether an attacker who compromises a corporate workstation or VPN could reach and impact industrial control systems.

Delivery
06

Remote Access and Vendor Pathway Review

Assessment of all remote access mechanisms — VPN tunnels, jump servers, vendor maintenance portals, and cloud-based management interfaces — that provide external connectivity into the OT environment. Evaluation of credential management and session controls.

07

Multi-Layer Review and Validation

All findings undergo L1/L2/L3 review. L1 auditors document findings with detailed proof-of-concepts. L2 senior consultants validate coverage completeness and methodology adherence. L3 security architects confirm impact assessments and ensure reporting accuracy specific to industrial environments.

08

Reporting, Remediation Roadmap, and Walkthrough

Delivery of executive and technical reports with OT-specific remediation guidance. Prioritised remediation roadmap accounting for industrial patching constraints, maintenance windows, and safety system dependencies. Walkthrough sessions with OT engineering and IT security teams.

"We needed an assessment on a 3-week timeline because of a partner integration deadline. Security Brigade turned it around in 18 days, including the L2 and L3 reviews. The report was regulator-ready — we submitted it to our partner's compliance team unchanged. When speed and credibility both matter, they're the only call we make."
VP Engineering, Retail & Quick Commerce
Vice President — Engineering

Read more client stories →

FAQ

OT and SCADA security, answered

Safety, method and what we actually find. Talk to our team about your control environment.

Contact us
Will testing disrupt production?+
Not the way we scope it. Live control systems are approached through architecture and configuration review and passive traffic analysis, which generate no packets. Active testing is performed at the IT boundary, where the realistic attack path runs and where it carries no process risk. Anything that could affect a live process is scoped explicitly and scheduled into a planned outage, or run against a test rig. A probe that is routine on an IT network can halt a controller, and an assessment that forgets this has misunderstood the environment.
Where do attacks on control environments actually start?+
On the business network, crossing a boundary that is looser than the diagram suggests. Engineering workstations are the recurring route: dual-homed by convenience, running vendor software with broad privileges. Vendor remote access is the second, usually uninventoried and frequently sharing credentials across sites. Historians and reporting servers are the third, because they exist to move data across the boundary and are permitted to do so.
Our equipment is twenty years old and cannot be patched. What then?+
That is the normal condition of the environment and it does not stop the work. Where a device cannot be patched, the protection is the boundary around it: segmentation that is verified instead of assumed, tight control of the paths that reach it, and monitoring of those paths. The assessment concentrates on what can be changed, which is the architecture around the device far more often than the device.
How does this relate to IEC 62443?+
Findings are expressed against the model that standard uses: zones, conduits and security levels. Doing it that way means the assessment output feeds a certification path instead of sitting beside it, and it gives you a way to hold a procurement conversation with automation vendors in specifics, by stating a required capability level.
Do you need to be on site?+
For the passive analysis and any deep testing, usually yes, because it involves a tap or span on the control network and access to the engineering environment. Architecture and configuration review, and active testing at the IT boundary, can be done remotely. Most engagements are a mix, with the on-site portion kept short and scheduled around plant operations.

Stay protected between assessments with ShadowMap

Continuous attack surface monitoring: it discovers new assets, detects credential leaks, and alerts on new exposures the day they appear.

Learn about ShadowMap →

Secure Your Industrial Environment Before Attackers Find the Path In

Hundreds of India's largest manufacturing conglomerates trust Security Brigade to protect their operational technology. Start with a scoping call to understand your OT security posture.

Typically responds within 1 business day · No commitment required

Request a Scoping Call