APT-level red team operations for enterprises and organizations

Industrial. Safety-first testing of the IT/OT boundary.

Production systems are never the target — the path to them is. Ransomware crews increasingly cross from IT into OT through the same doors your vendors use. We verify that your zones, conduits, remote access and physical controls hold against a determined attacker, with written authorization at every step and zero impact on live processes. Aligned with IEC 62443 and the Purdue model.

Our safety contract — agreed in writing before any packet
We neverWe always
Send commands to live controllers, PLCs or drivesWork read-only inside the OT zone unless a process engineer signs off
Actively scan OT networks without explicit authorizationMap zones and assets passively, from the IT side
Treat the boundary as a diagramVerify every conduit with evidence your engineers can review
Continue after a crash-stop signalHalt within minutes and hand over a full activity log

Scope of assessment

Everything below runs under the safety contract above. The OT zone is approached read-only; reachability is demonstrated, never impact.

IND-01

IT/OT boundary

Zone and conduit verification against the Purdue model: where the design says "isolated" and the reality says "one flat network".

1–2 wks
IND-02

Vendor & remote access

Maintenance VPNs, dual-homed vendor laptops, jump hosts and legacy modems — the paths that legitimately cross the boundary.

3–5 days
IND-03

Physical intrusion

Tailgating, badge cloning and secure-area reach at production sites — discreet, escorted, with ROE agreed in advance.

per site
IND-04

OT protocols & assets

Passive fingerprinting of Modbus, DNP3, S7 and EtherNet/IP traffic and asset inventory — read-only, no active scanning of live controllers.

add-on
IND-05

Jump-host pivots

The engineering workstations and historian servers that bridge zones — attacked from the IT side, with crash-stop signals in place.

included
IND-06

Detection across the boundary

What your SOC sees when OT traffic anomalies fire — and the log sources that close the blind spots.

3–5 days

Building a broader program? Compare all eight services in the full catalog.

How it runs — safety first.

01

Safety review & ROE

Before any technical work: a safety review with your process engineers, a no-go list of live controllers, crash-stop signals and 24/7 contact — in writing.

02

Passive recon

Asset inventory and boundary mapping from the IT side only. Read-only traffic analysis; no active probing of OT networks without explicit sign-off.

03

Path verification

We demonstrate reachability of the OT zone — through vendor access, jump hosts or physical entry — and stop at the boundary. Evidence, not impact.

04

Debrief & zoning plan

A prioritized plan: brokered vendor access, just-in-time grants, conduit hardening and the detection rules that watch the boundary.

What you receive

  • Boundary report — zone-by-zone reachability, evidenced end to end.
  • Vendor access map — every legitimate path that crosses the boundary.
  • Physical access report — site-by-site fixes for cameras, guards, process.
  • IEC 62443 gap list — mapped to the standard's zones-and-conduits model.

Typical engagement: 1–3 weeks depending on the number of sites.

From our case files
CaseLesson
RT-0098Energy/OT: a clean IT/OT boundary — until the vendor laptop legitimately bridged the zones

Standards we work to.

A

IEC 62443

Zones, conduits and security levels — findings reported against the standard's model, ready for your compliance files.

B

NIST SP 800-82

Defense-in-depth review for ICS: where monitoring, access control and recovery fall short of the guidance.

C

Purdue model

Every finding is placed on the level map, so fixes go to the right zone — not just “the OT problem”.

Get a consultation

Tell us about your production sites and the boundary you worry about. We reply within two business days with a safety-first proposal, objectives and draft ROE.

Get consultation

Faster: Telegram @infosecslab or [email protected].