Case Study — SCADA/OT Penetration Testing (Zero-Outage)
One IT/OT firewall rule = plant-wide write to PLC. We proved it in lab, not in production.
Client Context
Energy utility & manufacturing group — 2 plants, 1 distribution SCADA, 120+ PLC/RTU, historian + remote vendor VPN. Requirement: pre-audit assurance for IEC 62443 & ISO 27001 without stopping the line.
Challenge
IT/OT had converged after Industry 4.0 rollout. Flat network + jump-host shared with OT vendors. Risk: ransomware lateral movement to HMI/PLC = safety + outage. No prior OT-aware test.
Scope — Snipeyes OT-Aware Methodology (CREST)
- Passive discovery (SPAN, no active scan on OT), asset inventory & network capture review
- IT→OT segmentation test — firewall rule review + jump-host pivot validation (lab-replicated HMI/PLC)
- Historian, OPC & engineering workstation — unauth write, project file tamper, credential replay
- Remote access & vendor VPN — third-party NOC breach path
Key Findings (redacted)
- HIGH: Jump-host allowed SMB/RDP relay from IT VLAN to OT DMZ — chained to unauth OPC write in lab (CVE-like PLC write)
- HIGH: Historian exposed with default creds, allowed trend exfil + command injection to HMI project sync folder
- MEDIUM: Vendor VPN without MFA, reused creds — mapped to IEC 62443 SR 1.1 / NIST PR.AC-1
- 14 findings total: 2 High, 5 Medium, 7 Low — CVSS + OWASP Risk Rating + board impact (downtime + safety model)
Outcome (48h → retest)
- Segmentation fixed (firewall + jump-host hardening + MFA on vendor VPN), historian credential rotated + network isolation — retest: 100% High closed, 80% Medium closed
- Board report in 10 days: 1-page risk, MITRE ATT&CK for ICS, IEC 62443 mapping — auditor accepted first time, insurer reduced premium
- Continuous: OT monitoring blueprint + backup restore drill, zero outage during test
Relevance for you: If you run SCADA/ICS, DCS, or plant OT — we test production-safe, lab-validated, with retest before audit window.