Industrial. Safety-first testing of the IT/OT boundary.
Production systems are never the target — the path to them is. Ransomware crews increasingly cross from IT into OT through the same doors your vendors use. We verify that your zones, conduits, remote access and physical controls hold against a determined attacker, with written authorization at every step and zero impact on live processes. Aligned with IEC 62443 and the Purdue model.
| We never | We always |
|---|---|
| Send commands to live controllers, PLCs or drives | Work read-only inside the OT zone unless a process engineer signs off |
| Actively scan OT networks without explicit authorization | Map zones and assets passively, from the IT side |
| Treat the boundary as a diagram | Verify every conduit with evidence your engineers can review |
| Continue after a crash-stop signal | Halt within minutes and hand over a full activity log |
Scope of assessment
Everything below runs under the safety contract above. The OT zone is approached read-only; reachability is demonstrated, never impact.
IT/OT boundary
Zone and conduit verification against the Purdue model: where the design says "isolated" and the reality says "one flat network".
Vendor & remote access
Maintenance VPNs, dual-homed vendor laptops, jump hosts and legacy modems — the paths that legitimately cross the boundary.
Physical intrusion
Tailgating, badge cloning and secure-area reach at production sites — discreet, escorted, with ROE agreed in advance.
OT protocols & assets
Passive fingerprinting of Modbus, DNP3, S7 and EtherNet/IP traffic and asset inventory — read-only, no active scanning of live controllers.
Jump-host pivots
The engineering workstations and historian servers that bridge zones — attacked from the IT side, with crash-stop signals in place.
Detection across the boundary
What your SOC sees when OT traffic anomalies fire — and the log sources that close the blind spots.
Building a broader program? Compare all eight services in the full catalog.
How it runs — safety first.
Safety review & ROE
Before any technical work: a safety review with your process engineers, a no-go list of live controllers, crash-stop signals and 24/7 contact — in writing.
Passive recon
Asset inventory and boundary mapping from the IT side only. Read-only traffic analysis; no active probing of OT networks without explicit sign-off.
Path verification
We demonstrate reachability of the OT zone — through vendor access, jump hosts or physical entry — and stop at the boundary. Evidence, not impact.
Debrief & zoning plan
A prioritized plan: brokered vendor access, just-in-time grants, conduit hardening and the detection rules that watch the boundary.
What you receive
- Boundary report — zone-by-zone reachability, evidenced end to end.
- Vendor access map — every legitimate path that crosses the boundary.
- Physical access report — site-by-site fixes for cameras, guards, process.
- IEC 62443 gap list — mapped to the standard's zones-and-conduits model.
Typical engagement: 1–3 weeks depending on the number of sites.
| Case | Lesson |
|---|---|
| RT-0098 | Energy/OT: a clean IT/OT boundary — until the vendor laptop legitimately bridged the zones |
Standards we work to.
IEC 62443
Zones, conduits and security levels — findings reported against the standard's model, ready for your compliance files.
NIST SP 800-82
Defense-in-depth review for ICS: where monitoring, access control and recovery fall short of the guidance.
Purdue model
Every finding is placed on the level map, so fixes go to the right zone — not just “the OT problem”.
Get a consultation
Tell us about your production sites and the boundary you worry about. We reply within two business days with a safety-first proposal, objectives and draft ROE.
Faster: Telegram @infosecslab or [email protected].