#1
most targeted industry for ransomware worldwide, for the 5th year running
IBM X-Force Threat Intelligence Index 2025
Why audit and pentest are critical in an IT/OT environment
The convergence between IT systems (office tools, ERP, corporate network) and OT (PLCs, SCADA, industrial supervision) creates an attack path that didn't exist when these two worlds were physically separated. A compromised office workstation can, without sufficient segmentation, become a pivot point toward the production line.
Industrial equipment has long lifecycles — sometimes fifteen to twenty years — and is rarely updated because any intervention risks interrupting production. This means known vulnerabilities can remain exploitable for years if not offset by other controls.
Concrete risks in a connected industrial environment
Remote access left open for maintenance by integrators or equipment vendors is a frequent entry point, often poorly documented and rarely revoked once an intervention ends. Legacy industrial protocols (Modbus and equivalents) were often designed without authentication mechanisms, making them vulnerable as soon as an attacker reaches the OT network.
Default credentials on industrial equipment — never changed since installation — remain one of the simplest flaws to exploit, and one of the most commonly found during on-site audits.
What an audit on a production site involves
The methodology is adapted to never risk interrupting production: OT zones are mapped and analyzed mostly passively, while active testing focuses on the IT perimeter and the boundary between the two worlds. This approach requires close coordination with production and automation teams, who understand the site's operational constraints.
Since it's rarely possible to fix every vulnerability on aging industrial equipment, the audit's priority is strengthening IT/OT segmentation — the control that most effectively reduces risk when direct remediation isn't feasible.
Go further
See the full presentation of Audit & Pentest or all our solutions for Cybersecurity for Industry.
FAQ
Frequently asked questions
No, the methodology is specifically designed to avoid that: OT zones undergo passive analysis rather than active exploitation, and any risky test is scoped and validated in advance with production teams.