Industrial. Safety-first testing of the IT/OT boundary.
Production systems are never the target — the path to them is. We verify that your zones, conduits, remote access and physical controls hold against a determined attacker, with written authorization at every step and zero impact on live processes. Aligned with IEC 62443 and the Purdue model.
| We never | We always |
|---|---|
| Send commands to live controllers, PLCs or drives | Work read-only inside the OT zone unless a process engineer signs off |
| Actively scan OT networks without explicit authorization | Map zones and assets passively, from the IT side |
| Treat the boundary as a diagram | Verify every conduit with evidence your engineers can review |
| Continue after a crash-stop signal | Halt within minutes and hand over a full activity log |
What we test.
Everything below runs under the safety contract above. The OT zone is approached read-only; reachability is demonstrated, never impact.
IT/OT boundary
Zone and conduit verification against the Purdue model: where the design says "isolated" and the reality says "one flat network".
Vendor & remote access
Maintenance VPNs, dual-homed vendor laptops, jump hosts and legacy modems — the paths that legitimately cross the boundary.
Physical intrusion
Tailgating, badge cloning and secure-area reach at production sites — discreet, escorted, with ROE agreed in advance.
OT protocols & assets
Passive fingerprinting of Modbus, DNP3, S7 and EtherNet/IP traffic and asset inventory — read-only, no active scanning of live controllers.
Jump-host pivots
The engineering workstations and historian servers that bridge zones — attacked from the IT side, with crash-stop signals in place.
Detection across the boundary
What your SOC sees when OT traffic anomalies fire — and the log sources that close the blind spots.
Building a broader program? Compare all eight services in the full catalog.
How it runs — safety first.
Safety review & ROE
Before any technical work: a safety review with your process engineers, a no-go list of live controllers, crash-stop signals and 24/7 contact — in writing.
Passive recon
Asset inventory and boundary mapping from the IT side only. Read-only traffic analysis; no active probing of OT networks without explicit sign-off.
Path verification
We demonstrate reachability of the OT zone — through vendor access, jump hosts or physical entry — and stop at the boundary. Evidence, not impact.
Debrief & zoning plan
A prioritized plan: brokered vendor access, just-in-time grants, conduit hardening and the detection rules that watch the boundary.
What you get.
- Boundary report — zone-by-zone reachability, evidenced end to end.
- Vendor access map — every legitimate path that crosses the boundary.
- Physical access report — site-by-site fixes for cameras, guards, process.
- IEC 62443 gap list — mapped to the standard's zones-and-conduits model.
Typical engagement: 1–3 weeks depending on the number of sites.
| Case | Lesson |
|---|---|
| RT-0098 | Energy/OT: a clean IT/OT boundary — until the vendor laptop legitimately bridged the zones |
Standards we work to.
IEC 62443
Zones, conduits and security levels — findings reported against the standard's model, ready for your compliance files.
NIST SP 800-82
Defense-in-depth review for ICS: where monitoring, access control and recovery fall short of the guidance.
Purdue model
Every finding is placed on the level map, so fixes go to the right zone — not just “the OT problem”.
Get a consultation.
Tell us about your production sites and the boundary you worry about. We reply within two business days with a safety-first proposal.
Faster: Telegram @infosecslab or [email protected].