Why Manufacturing Penetration Testing Is Different
Standard penetration testing methodology was developed for IT environments — systems that can be probed aggressively, exploited, and recovered without consequence. Operational technology environments do not share these characteristics. A PLC handling a chemical process, a historian server aggregating production data, or an engineering workstation running SCADA software may respond to aggressive network probing in ways that cause process upsets, equipment damage, or safety events. Standard penetration testing tools and techniques applied without modification to OT networks can cause the very incidents they are meant to prevent.
At the same time, manufacturing organizations cannot afford to exclude OT from their security assessment program. IT/OT convergence has made previously air-gapped production networks accessible from corporate networks. Remote monitoring and vendor access create pathways from the internet to operational systems. Ransomware campaigns increasingly target manufacturing because production downtime is more financially coercive than data theft alone.
NIST SP 800-82 Guide to OT Security provides the methodology framework for securing industrial control system environments. Armorstack’s OT/ICS penetration testing applies this guidance in practice, with testers who understand both the security objectives and the operational constraints of manufacturing environments.
The IT/OT Boundary: Where Manufacturing Attacks Begin
The boundary between corporate IT networks and operational technology networks is the primary attack surface in manufacturing security. Historically, this boundary was physical — air-gapped networks with no connectivity between the plant floor and the enterprise. Connectivity requirements for remote monitoring, ERP integration, vendor support, and supply chain visibility have eliminated most air gaps, replacing them with network connections that are often inadequately controlled.
Common attack paths at the IT/OT boundary include inadequately secured remote access solutions used by vendors and support personnel, historian servers positioned to aggregate data from both IT and OT networks with insufficient network segmentation, engineering workstations that connect to both corporate networks and OT environments, unmanaged switches and legacy networking equipment in the OT zone with no authentication requirements, and software update pathways that traverse the boundary without adequate integrity controls.
MITRE ATT&CK for ICS documents the tactics and techniques adversaries use after gaining access to OT environments — including techniques for lateral movement within OT networks, manipulation of control processes, and inhibition of response functions. Armorstack’s OT penetration testing maps findings to ATT&CK for ICS to give your security team and operations personnel a common threat language.
OT/ICS Penetration Testing Methodology
Pre-Engagement Safety Planning
Every engagement begins with a safety planning session with your OT, plant safety, and IT security teams — documenting what can be tested passively only, what tolerates active probing during maintenance windows, and what requires production shutdown before testing.
Passive Network Assessment
Network taps and span ports capture and analyze traffic without injecting packets — identifying unencrypted industrial protocols, authentication-free PLC communications, abnormal traffic, and undocumented assets. Safe in production without a maintenance window.
IT/OT Boundary Testing
Active testing examines segmentation controls, firewall rule adequacy, and the exploitability of historian servers, data diodes, remote access concentrators, and protocol converters bridging both environments.
OT Network Active Testing
Where operational risk permits, controlled active testing examines engineering workstation security, HMI application vulnerabilities, PLC authentication, and vendor account management — scoped conservatively, during defined maintenance windows, with operations staff present.
NIST SP 800-82 Control Mapping
Findings are mapped to the NIST SP 800-82 control framework for structured remediation prioritization. Defense contractors with OT environments get findings cross-referenced to NIST SP 800-171 controls relevant to their CMMC boundary.
Common OT/ICS Penetration Testing Findings
- Inadequate segmentation between IT and OT zones allowing direct routing between corporate workstations and PLC networks
- Vendor remote access accounts with excessive privileges and no time-limiting controls
- Engineering workstations running outdated operating systems with direct internet access
- Unencrypted industrial protocols carrying authentication credentials in cleartext
- Default credentials on HMI systems and network devices
- Historian servers configured with domain credentials that provide lateral movement opportunities from the OT network back into the corporate IT environment
These findings are not theoretical. Publicly documented manufacturing ransomware incidents — including attacks on food production, automotive manufacturing, and industrial equipment suppliers — have followed these exact attack paths. Human testers identify these attack paths; automated vulnerability scanners do not.
Integrating OT Security with Converged Monitoring
Penetration testing identifies the attack paths in your OT environment. Remediation closes the specific findings. Continuous monitoring detects when new attack paths emerge or when threat actors target the same vectors identified during testing.
Armorstack’s SENTRY practice extends managed detection and response into OT environments, providing the continuous visibility layer that connects point-in-time penetration testing findings to ongoing threat detection. For organizations that need governance and risk management structure around OT security investment decisions, the VERITY risk advisory practice bridges technical findings to strategic planning.
To scope an OT/ICS engagement for your facility, contact the SENTRY team.
Frequently Asked Questions
Is it safe to conduct penetration testing in a manufacturing OT environment?
OT and ICS penetration testing requires specialized methodology to avoid disrupting production systems. Armorstack conducts passive network analysis safely in production environments and limits active testing to defined maintenance windows with operations staff present. Pre-engagement safety planning with plant operations and safety personnel is mandatory before any active testing begins in OT environments.
What methodology governs OT/ICS penetration testing?
OT and ICS penetration testing follows NIST SP 800-82 Guide to OT Security. Findings are mapped to MITRE ATT&CK for ICS tactics and techniques. The engagement includes passive network analysis, IT/OT boundary assessment, and controlled active testing within the OT environment where operational risk permits.
What is the IT/OT boundary and why is it the primary attack target?
The IT/OT boundary is the network connection point between corporate IT infrastructure and operational technology systems on the plant floor. Remote monitoring requirements, ERP integration, and vendor access have eliminated most air gaps in modern manufacturing, creating attack paths from the internet to production systems through inadequately controlled connections. Historian servers, engineering workstations, and remote access concentrators at this boundary are the most common entry points for manufacturing cyberattacks.
What common vulnerabilities does OT penetration testing find in manufacturing environments?
Common findings include inadequate IT/OT network segmentation, vendor remote access accounts with excessive and time-unlimited privileges, engineering workstations running outdated operating systems, unencrypted industrial protocols transmitting credentials in cleartext, default credentials on HMI systems, and historian servers with domain credentials that enable lateral movement from OT back to corporate networks.
Related Resources
Ready to Scope an OT/ICS Engagement?
Every OT/ICS penetration test begins with a pre-engagement safety planning session with your operations, plant safety, and IT security teams. No active testing occurs until rules of engagement are agreed upon in writing.Contact the SENTRY Team