Get an OT security pentest
Industrial production environments are increasingly connected to IT networks, remote-access solutions and cloud services. This integration introduces new attack paths toward PLCs, SCADA systems and critical industrial processes. Preparing for NIS2 obligations? Does your cyber insurer require demonstrable OT validation? Do you want to know whether your IT/OT segmentation would stop a real attacker?
DongIT performs controlled OT security pentests within strict operational parameters. We map out realistic exposure risks within industrial control systems, without disruption of your production. Our approach aligns with IEC 62443 and the Purdue model, with explicit focus on availability, stability and safety.
Our pentests are performed by OSCP and OSEP-certified ethical hackers under our four-eyes principle. Reporting via our self-developed Security Reporter platform. CCV Keurmerk-accredited. Data stays in Europe.
What we test in an OT security pentest
We determine whether unauthorized access, lateral movement from IT to OT, privilege escalation or manipulation of industrial processes is realistically possible within your architecture. Our scope is precisely defined during the intake with your OT engineers, within your established risk tolerance.
- IT/OT segmentation. Segmentation boundaries between IT and OT domains, firewall configuration, conduits and Purdue-level separation.
- Industrial control components. PLCs, SCADA systems, HMIs, RTUs and engineering workstations on firmware, configuration and authentication.
- Remote access and vendor access. VPN connections, jump hosts, maintenance connections and third-party access paths.
- Industrial protocols. Modbus, DNP3, Profinet, OPC UA and EtherNet/IP. Detection of insecure protocol implementations and unauthenticated communication.
- Authentication, logging and monitoring. Role separation, credential management, detection capabilities and incident response within the OT environment.
- Vendor hardware. CVE tracking for Siemens, Schneider, Rockwell, ABB, Honeywell and other common industrial vendors.
Our approach: how we test your OT environment
Our OT security pentest follows a risk-driven methodology aligned with the Purdue Enterprise Reference Architecture model and the IEC 62443 standard. At every step, the conversation with your engineers takes precedence over the tooling.
Scoping and asset identification
We map out critical OT assets, zones, conduits and trust relationships between IT and OT domains. Your engineers determine what is and is not in scope.
Architecture and configuration analysis
Analysis of segmentation design, firewall rules, routing policies, trust relationships and remote-access paths that could enable pivoting toward production environments.
Passive vulnerability analysis
Identification of exposed services, insecure protocol configurations, authentication weaknesses, outdated firmware and configuration errors in control components.
Controlled validation
Only after explicit approval and with engineers present, we validate whether identified weaknesses are actually exploitable. With strict agreements on impact limits and escalation.
Risk analysis and reporting
Every finding receives an assessment based on realistic likelihood and operational impact. Delivery via Security Reporter with CVSS scoring, mapped to IEC 62443 and NIS2 where applicable.
Follow-up and retest
Prioritized remediation advice with technical rationale. Retest of resolved vulnerabilities on time and materials.
Why OT pentesting works differently
Disruption in your OT environment can have direct consequences for safety, production or service delivery. That is why we work demonstrably differently than in regular IT pentests.
- Passive unless. Reconnaissance and analysis by default without active interaction with OT systems. Active testing only on explicit approval, per finding, with an engineer present.
- Non-production where possible. We prefer to work on test benches or acceptance environments. When production testing is necessary, with documented safety agreements and go/no-go moments.
- Engineers at the table. During scoping, testing and debriefing, your OT engineers are direct counterparts. They determine what is and is not acceptable.
- Realistic pace. OT pentests require more preparation time than IT pentests. We plan for that. No accelerated engagements.
Compliance mapping for OT environments
Our reports are always aligned with the compliance framework relevant to you. Findings are explicitly linked to the relevant controls for your auditor.
IEC 62443
Assessment per IEC 62443-3-3 (system security requirements) and IEC 62443-4-2 (component security requirements). Reporting mapped to Security Levels 1 through 4. For asset owners and product vendors.
NIS2 and Dutch Cybersecurity Act
Demonstrable assessment of security measures per article 21 Dutch Cybersecurity Act. Mandatory for essential entities in energy, water, transport, wastewater management, critical manufacturing and healthcare.
BIO2 and government
For Dutch water boards, municipalities and provinces with OT infrastructure. Network segmentation testing directly usable for ENSIA reporting.
We also deliver reporting suitable for cyber insurance and supply chain requirements from enterprise clients. Our reporting meets the requirements of common cyber insurers and enterprise procurement processes.
What does an OT security pentest cost?
OT security pentests are almost always scoped bespoke, given the unique architecture and operational parameters of every industrial environment. The price depends on the size of your environment, the number of in-scope zones and whether on-site testing is included. For clearly defined environments we can align to our standard packages.
- Quick Pentest, €2,960 excl. VAT
- Expert Pentest, from €5,040 excl. VAT (most chosen)
- Extensive Pentest, from €7,200 excl. VAT
- Enterprise and multi-site engagements, tailored quotation
Always tailored
For every OT engagement we first propose a complimentary technical scoping conversation with your engineers. This ensures you know exactly what the investment will be.
Frequently asked questions about OT security pentesting
Below are the most frequently asked questions about OT security pentesting. For a complete overview please visit our FAQ page.
What is the difference between a network pentest and an OT pentest?
A network pentest focuses on regular IT infrastructure such as servers, networks, cloud and Active Directory. An OT pentest focuses on operational technology: PLCs, SCADA, HMIs, engineering workstations and industrial protocols. Methodologies, toolkits and safety requirements differ substantially. For organizations with both we often offer combined engagements with separate scoping per domain.
Do you also test safety-instrumented systems (SIS)?
We approach SIS with extra care and only after explicit approval. Typically we limit ourselves to architecture and segmentation validation around SIS, without direct interaction with safety logic. Scope is precisely defined during intake with your functional safety officer.
Which industrial protocols do you support?
We have experience with the most common industrial protocols such as Modbus, DNP3, Profinet, OPC UA and EtherNet/IP. For niche or vendor-specific protocols we assess per engagement whether we have the right expertise in-house. Transparent, even when another party is a better fit.
Do you work per IEC 62443?
Our OT pentests align with IEC 62443-3-3 (system security requirements) and IEC 62443-4-2 (component security requirements). Reporting is mapped to the relevant Security Levels 1 through 4, so you have direct evidence for your audit.
What about vendor access and maintenance connections?
Vendor access is one of the most common risk areas in OT environments. We assess jump hosts, VPN configurations, maintenance connections, always-on connections and third-party access paths for segmentation, authentication and logging. We also verify whether vendor access can be limited to a controlled time window.
Do you also cover OT environments in healthcare (medical devices)?
Medical devices are a specific category of OT with their own standards, including IEC 80001 and MDR requirements. We assess per engagement whether our expertise fits your specific equipment. For healthcare organizations with broader OT scope (building management, climate systems) we can perform standard engagements.
How long does an OT pentest take?
Active testing time ranges from 40 hours for a compact OT assessment to 120 hours or more for extensive industrial environments with multiple sites. Total duration is typically 6 to 10 weeks, slightly longer than IT pentests due to careful scoping and engineer involvement.
Is a retest included?
Retest of resolved vulnerabilities is performed on time and materials, depending on the number and complexity of findings. This is discussed during intake and explained in the quotation.
Ready to have your OT environment tested?
Preparing for NIS2? Does your cyber insurer require demonstrable OT validation? Want to know whether your IT/OT segmentation holds up? Our intake starts with a technical conversation. Your engineers sit at the table, from scoping to debriefing.
Nederlands