OT Penetration Testing Services

Exploitable weaknesses in SCADA, ICS, and industrial networks, found by hand by an engineer who knows what not to touch.

Operational Technology Is Under Attack

What We Test in OT

PLC, RTU & Controller Testing

Programmable Logic Controllers, Remote Terminal Units, and other field devices are the workhorses of industrial automation. Raxis tests these controllers for default credentials, insecure firmware, unprotected programming interfaces, and protocol-level vulnerabilities that could allow an attacker to alter set points, inject false data, or shut down processes.

Industrial Protocol Analysis

Modbus, DNP3, OPC UA, EtherNet/IP, PROFINET, BACnet, industrial protocols were designed for reliability, not security. Many transmit data in plaintext with no authentication. Raxis analyzes protocol traffic for exploitable weaknesses, including command injection, replay attacks, man-in-the-middle opportunities, and unauthorized read/write access to control system data.

Remote Access & VPN Assessment

Remote access to OT environments has exploded, for vendors, engineers, and operators. Raxis evaluates jump hosts, VPN configurations, remote desktop deployments, and third-party access pathways for weaknesses that could give an attacker a direct tunnel into your industrial network. We test whether your remote access controls would survive a determined adversary.

IT/OT Convergence & Boundary Testing

The boundary between IT and OT is where most real-world attacks cross over. Raxis specifically targets the systems, services, and data flows that bridge these environments, Active Directory dependencies, shared file servers, historian connections, and cloud integrations, to determine whether an attacker with enterprise network access can pivot into your industrial control systems.

OT Industries We Protect

OT security is not one-size-fits-all. Raxis brings sector-specific expertise to the industries where operational disruption carries the highest consequences.

Energy and Utilities

How Raxis OT Penetration Testing Works

01

Scoping & Coordination

OT testing starts with trust. Raxis works closely with your operations, engineering, and security teams to define scope, identify critical assets, establish testing windows, and set ground rules that protect system availability. No surprises. No cowboy testing.

02

Architecture & Documentation Review

Before touching any live system, our engineers review network diagrams, asset inventories, firewall configurations, and remote access architectures. We identify high-risk pathways and potential pivot points on paper first, reducing risk and maximizing the value of active testing.

03

Passive Reconnaissance & Traffic Analysis

Raxis monitors OT network traffic to map communications, identify devices, and detect anomalies without sending a single packet that could disrupt operations. This non-intrusive phase reveals protocol usage, trust relationships, and unencrypted data flows across your industrial network.

04

Targeted Active Testing

With full coordination and your team standing by, Raxis performs controlled active testing against in-scope systems. We test authentication mechanisms, probe controller interfaces, attempt privilege escalation, and validate segmentation boundaries, always with availability as the top priority.

05

Pivoting & Attack Chain Demonstration

When we find a way in, we show you how far it goes. Raxis demonstrates realistic attack chains, from initial network access through lateral movement to reaching critical control systems. Our signature storyboard walkthroughs map the full path an attacker would take, complete with proof-of-concept evidence.

06

Reporting & Remediation Guidance

Real skill leaves evidence. Findings land in the Raxis One portal with risk ratings, proof-of-concept documentation, and remediation steps written for OT, where patching isn’t always an option and compensating controls matter. We debrief with your team so every finding is clear and actionable.

Compliance

OT Security Standards & Compliance

Raxis OT penetration testing supports compliance with the regulations and frameworks governing industrial control system security.

NERC CIP

Mandatory cybersecurity standards for the bulk electric system in North America

IEC 62443

International standard for industrial automation and control system security

NIST SP 800-82

Guide to operational technology security for industrial control systems

TSA Security Directives

Cybersecurity requirements for pipeline and surface transportation operators

HSE OG86

UK guidance for cyber security of industrial automation and control systems

CFATS

Chemical Facility Anti-Terrorism Standards for high-risk chemical facilities

API 1164

Pipeline SCADA security standard for the oil and gas industry

Why Raxis for OT Penetration Testing

Our engineers understand industrial protocols, control system architectures, and the operational realities of testing environments where availability is non-negotiable. This isn’t an IT pentest team dabbling in OT.

Panama Canal OT locks

Availability-first methodology

Every test is coordinated with your operations team, scoped to protect critical processes, and executed with the caution that industrial environments demand. Raxis has never caused an unplanned outage during an OT engagement.

Full IT/OT boundary coverage

Most OT attacks originate in IT. Raxis tests the entire attack path, from enterprise network to control system, so you see the real risk, not just isolated OT findings.

Actionable reporting for OT realities

We know you can’t always patch a PLC on a running production line. Raxis provides compensating control recommendations alongside traditional remediation steps, so your team has options that work in the real world.

How a Pentest Found a Hospital’s Radiation Machine on the Open Network

Our stories are based on real events encountered by Raxis engineers. Some details have been altered or omitted to protect customer identities.

When a prominent medical entity engaged Raxis to assess the security of their internal network, they expected our team to call out the usual suspects: unpatched endpoints, response poisoning, maybe Kerberoasting a forgotten service account or two. What our team uncovered instead was a direct path from their production network to a control system managing one of the most tightly regulated pieces of equipment on their property, a linear accelerator.

The engagement started at the IT perimeter. The facility’s network was large and complex in the way large medical environments often are. Once inside the perimeter, Raxis identified a subnet that had a broader internal network space than the others. Using credential pairs harvested from an unprotected internal share, the Raxis team began mapping the environment. What our team found on the other side of that subnet stopped them in their tracks.

It wasn’t immediately apparent, but a few “help” commands typed into the terminal revealed that a control system associated with one of the hospital’s Linear Accelerators (LINACs) was reachable from the production network. No compensating controls. No jump host. No out-of-band access requirement or MFA. Just an open telnet connection to a system that, in the wrong hands, could manipulate the operational parameters of a machine designed to deliver ionizing radiation to a living patient. The Raxis team queried the device. It responded. When they checked the credentials, the system was configured exactly as it had left the factory floor.

Default username. Default password. Full access.

In a real attack scenario, this is the moment that potentially ends careers, triggers federal notifications, and makes news. A LINAC misconfigured to deliver the wrong dose, to the wrong field, or without the proper safety interlocks engaged isn’t a data breach; it’s a catastrophe waiting to happen. For this customer, it was an immediate escalation to their CISO and facilities leadership before continuing any further in that area of the environment.

This engagement was a stark reminder that OT risk doesn’t announce itself. It hides inside network diagrams that haven’t been updated, inside upgrade projects that didn’t include a security review, and inside the quiet assumption that critical systems are isolated because they’re supposed to be. Raxis OT penetration testing finds these assumptions before someone with bad intentions does.

FAQ: IoT Testing

What types of OT systems can Raxis test?

SCADA systems, distributed control systems (DCS), programmable logic controllers (PLCs), remote terminal units (RTUs), human-machine interfaces (HMIs), historian servers, safety instrumented systems (SIS), building automation systems, and the network infrastructure connecting them. If it controls a physical process, we can assess it.

Will OT penetration testing disrupt my operations?

No. Raxis prioritizes availability above all else. Every test is scoped and coordinated with your operations team, and our engineers use non-intrusive techniques wherever possible. Active testing against live systems is performed only with explicit coordination and your team standing by.

Can Raxis test OT systems on-site?

Yes. Many OT assessments require physical proximity to field devices and industrial networks. Raxis engineers can test on-site at your facility, or we can deploy our Raxis Transporter device for remote testing with onsite-quality results.

How is OT penetration testing different from a standard network pentest?

OT environments use industrial protocols, embedded controllers, and legacy systems that standard penetration testing tools and techniques aren't designed for, and can damage. OT pentesting requires specialized knowledge of industrial architectures, safety constraints, and the ability to test without disrupting physical processes.

How long does an OT penetration test take?

Timelines depend on environment size and scope. A focused architecture review or segmentation assessment may take 1–2 weeks. A comprehensive ICS penetration test covering network assessment, controller testing, and IT/OT boundary analysis typically runs 2–4 weeks. We'll provide a detailed timeline during scoping.

Do we need an OT pentest if we already do IT penetration testing?

Yes. IT penetration tests don't cover industrial protocols, control system devices, or the unique architecture of OT environments. More importantly, they don't test the IT/OT boundary, which is the most common attack vector for industrial breaches. OT penetration testing fills a critical gap that IT testing alone cannot address.

What’s the difference between OT and IoT penetration testing?

OT testing targets industrial control systems, SCADA, PLCs, DCS, and the networks that run physical processes in facilities. IoT testing focuses on connected devices, their firmware, wireless communications, and cloud integrations. Both are specialized disciplines, and Raxis offers each as a dedicated service line.

Request a quote

Tell Us What You Need Tested

We usually respond in one business day.

Please let us know what's on your mind. Include any details about your target environment, timeline, or compliance drivers.