APT-level red team operations for enterprises and organizations
CASE FILE RT-0098 Energy / OT adjacent

A clean IT/OT boundary — until the vendor laptop

Every segmentation test we run ends the same way: the boundary holds, and one legitimate maintenance path crosses it anyway. This time it was a vendor laptop with stored RDP credentials for the historian.

Objective
Assess whether the corporate-to-OT segmentation holds under a determined insider-style path
Path
Corporate phishing gave us a foothold in IT. The segmented OT network itself was solid. The gap: a maintenance vendor’s dual-homed laptop that legitimately bridged zones during scheduled visits, with stored RDP credentials for the historian server. Our objective was reached during a simulated maintenance window — with written authorization from site management at every step.
Detected
Nothing fired: vendor traffic was implicitly trusted at the boundary

After: Vendor laptops moved to a dedicated brokered jump host, and every zone crossing now requires a just-in-time access grant.

Names, sectors and infrastructure details are changed; timelines and tradecraft are not. More case files →

The pattern in one page

  • Segmentation is only as strong as the conduits you didn’t design. Vendor and maintenance paths are the usual gap.
  • Stored credentials on a bridging device are stored credentials inside the OT zone. Broker every crossing.
  • Implicit trust produces no telemetry. If vendor traffic never alarms, it is never watched.
Recognize the pattern?
We can verifyTypical effort
The same path against your estate, under signed ROE2–4 wks
Detection validation: what your SOC would have seenincluded
Retest after fixes, within three monthsfree

Could this path exist in your estate?

Tell us your crown jewels — we will tell you how close this case file is to your reality.

Request assessment