SCADA/OT penetration test: an energy and manufacturing case study
An energy utility and manufacturing group wanted to know whether an attack on its office network could reach the equipment that runs its plants. That equipment is managed by SCADA and OT systems (the computers and controllers that operate physical plant machinery). A breach there can stop production or create a safety hazard. So the test itself had to avoid touching anything live.
What the group runs
The group operates two plants and a distribution SCADA system. Between them sit more than 120 PLCs and RTUs, small industrial computers that open valves, run motors and read sensors. A historian (a database that records plant readings over time) collects their data. Equipment vendors connect remotely through a VPN.
The group needed assurance before audits against IEC 62443, the international standard for industrial control system security, and ISO/IEC 27001. The production line could not stop.
Why the plant network had become exposed
An Industry 4.0 program had connected the factory floor to the business network. Over time, the IT and OT networks merged into one flat network. A single jump host (a shared server used to reach plant systems) served both the group’s staff and outside vendors.
Management’s concern was ransomware spreading from the office into the operator screens (HMIs) and controllers. Nobody had tested the OT environment with methods designed for industrial systems before.
Testing without touching production
Industrial controllers can crash if they are scanned the way office computers are. We therefore did no active scanning on the OT network. Instead, we listened to a copy of network traffic from a mirror port, built an asset inventory from it and reviewed the firewall rules.
Anything that could change a controller’s behavior, we tested on a lab replica of the HMI and PLC setup. The work followed IEC 62443 and NIST SP 800-82, the US government’s guide to industrial control security. We mapped each attack path to MITRE ATT&CK for ICS, a public catalog of techniques attackers use against industrial systems. No plant equipment was stopped during testing.
The route from the office to the plant floor
The jump host allowed relay attacks from the office network into the OT DMZ, the buffer zone meant to separate office and plant. From there, in the lab, we sent an unauthenticated write command to a PLC over OPC, a common industrial communication protocol. On the real network, an attacker could have used the same route to change how equipment behaves.
Other findings
The historian still used its default password. That exposed plant trend data and allowed commands to be slipped into the folder that synchronizes HMI projects.
The vendor VPN had no multi-factor authentication, and vendors reused passwords. We mapped this to IEC 62443 SR 1.1 and NIST CSF PR.AC-1.
In total we reported 14 findings: 2 high, 5 medium and 7 low. Each was rated with CVSS and the OWASP Risk Rating, and the report explained the impact in terms of downtime and safety.
After the test
The group applied fixes within 48 hours. It tightened the firewall rules, hardened the jump host and added multi-factor authentication to the vendor VPN. It also changed the historian’s credentials and moved it onto its own isolated segment. Our retest confirmed both high findings were closed, along with four of the five medium findings.
The report arrived within 10 days of testing. It included a one-page risk summary for the board and a mapping to IEC 62443 and MITRE ATT&CK for ICS. The auditor accepted it. The group is now designing continuous OT monitoring and running regular drills to restore systems from backup.
For the technical reader, the main chain was SMB/RDP relay from the IT VLAN through the jump host into the OT DMZ, followed by an unauthenticated OPC write to a lab PLC. We also tested the historian, OPC servers and engineering workstation for unauthenticated writes, project file tampering and credential replay, and the vendor VPN as a third-party breach path.
Plants, utilities and other operators of industrial systems can be tested safely when the work is planned around production. If you would like to know how that would work at your sites, a short conversation is a good place to start.