Red team operations for enterprises
[email protected] @infosecslab Authorized testing only

Industrial. Safety-first testing of the IT/OT boundary.

Production systems are never the target — the path to them is. We verify that your zones, conduits, remote access and physical controls hold against a determined attacker, with written authorization at every step and zero impact on live processes. Aligned with IEC 62443 and the Purdue model.

Our safety contract — agreed in writing before any packet
We neverWe always
Send commands to live controllers, PLCs or drivesWork read-only inside the OT zone unless a process engineer signs off
Actively scan OT networks without explicit authorizationMap zones and assets passively, from the IT side
Treat the boundary as a diagramVerify every conduit with evidence your engineers can review
Continue after a crash-stop signalHalt within minutes and hand over a full activity log

What we test.

Everything below runs under the safety contract above. The OT zone is approached read-only; reachability is demonstrated, never impact.

IND-01

IT/OT boundary

Zone and conduit verification against the Purdue model: where the design says "isolated" and the reality says "one flat network".

1–2 wks
IND-02

Vendor & remote access

Maintenance VPNs, dual-homed vendor laptops, jump hosts and legacy modems — the paths that legitimately cross the boundary.

3–5 days
IND-03

Physical intrusion

Tailgating, badge cloning and secure-area reach at production sites — discreet, escorted, with ROE agreed in advance.

per site
IND-04

OT protocols & assets

Passive fingerprinting of Modbus, DNP3, S7 and EtherNet/IP traffic and asset inventory — read-only, no active scanning of live controllers.

add-on
IND-05

Jump-host pivots

The engineering workstations and historian servers that bridge zones — attacked from the IT side, with crash-stop signals in place.

included
IND-06

Detection across the boundary

What your SOC sees when OT traffic anomalies fire — and the log sources that close the blind spots.

3–5 days

Building a broader program? Compare all eight services in the full catalog.

How it runs — safety first.

01

Safety review & ROE

Before any technical work: a safety review with your process engineers, a no-go list of live controllers, crash-stop signals and 24/7 contact — in writing.

02

Passive recon

Asset inventory and boundary mapping from the IT side only. Read-only traffic analysis; no active probing of OT networks without explicit sign-off.

03

Path verification

We demonstrate reachability of the OT zone — through vendor access, jump hosts or physical entry — and stop at the boundary. Evidence, not impact.

04

Debrief & zoning plan

A prioritized plan: brokered vendor access, just-in-time grants, conduit hardening and the detection rules that watch the boundary.

What you get.

  • Boundary report — zone-by-zone reachability, evidenced end to end.
  • Vendor access map — every legitimate path that crosses the boundary.
  • Physical access report — site-by-site fixes for cameras, guards, process.
  • IEC 62443 gap list — mapped to the standard's zones-and-conduits model.

Typical engagement: 1–3 weeks depending on the number of sites.

From our case files
CaseLesson
RT-0098Energy/OT: a clean IT/OT boundary — until the vendor laptop legitimately bridged the zones

Standards we work to.

A

IEC 62443

Zones, conduits and security levels — findings reported against the standard's model, ready for your compliance files.

B

NIST SP 800-82

Defense-in-depth review for ICS: where monitoring, access control and recovery fall short of the guidance.

C

Purdue model

Every finding is placed on the level map, so fixes go to the right zone — not just “the OT problem”.

Get a consultation.

Tell us about your production sites and the boundary you worry about. We reply within two business days with a safety-first proposal.

Get consultation

Faster: Telegram @infosecslab or [email protected].