Industrial operators, production sites, and energy, water, or transport operators whose PLCs, SCADA systems, and supervisory networks (OT/ICS) are connected to, or converging with, the corporate IT network.
Last updated — August 22, 2026
Industrial equipment ends up connected to the office network without segmentation, sometimes through a vendor access path left open. On this perimeter, a production stoppage often costs more than a data leak — the audit approach has to account for that.
—
OT asset map and IT/OT data flow diagram
—
Segmentation report and IEC 62443 zone/conduit analysis
—
Remediation plan prioritized by operational criticality
—
Executive summary for industrial/plant management
4 to 8 weeks depending on the number of sites and PLCs covered
Typical duration
Passive analysis — listening to and observing network traffic — is the priority approach specifically to avoid that risk. No active testing (sending traffic, directly querying a PLC) is performed without the operator's prior written validation; the operator remains the sole decision-maker on this point.
OT equipment (PLCs, SCADA systems) is often older, has limited tolerance for network activity not anticipated in its original design, and is directly tied to a physical process. A poorly controlled active request can trigger unexpected equipment behavior. Passive analysis provides substantial visibility without exposing production to that risk.
An IT penetration test actively seeks to demonstrate that a vulnerability is exploitable. On the OT/ICS perimeter, continuity of the industrial process takes priority: the audit favors mapping, segmentation analysis, and passive observation, and only moves to a targeted active test if the operator explicitly validates it in writing, with full awareness of the risks.