OT Security & IoT
OT Security: Penetration Testing for Industrial Controls & IoT Protect production. Minimize attack surface.
OT Security requires different methods than classical IT Security. We test ICS/SCADA systems, PLCs, HMIs, and IoT devices per IEC 62443 - with a Safety-First approach that never puts your production at risk.
Trusted by our clients
- 500+
- Pentests completed
- ICS/SCADA
- Expertise
- 24h
- Fixed-price quote
- KRITIS
- Experience
Understanding OT Security
OT Security is not IT Security
Industrial control systems follow different principles than office IT - with physical consequences when things go wrong. Security audits must account for this.
IT Security
Office networks, servers, cloud
Priority: Confidentiality
- CIA Triad with Confidentiality first - data protection and access control in focus.
Regular patching
- Updates can be applied quickly, maintenance windows are short and frequent.
Standard protocols
- TCP/IP, HTTP/S, TLS - well documented, broad tool support for security testing.
Short lifecycles
- Systems are replaced every 3-5 years, new security features can be introduced promptly.
Digital consequences
- Data loss, operational disruption - serious, but without immediate physical danger.
OT Security
ICS, SCADA, PLC, field devices
Priority: Availability & Safety
- AIC Triad - Availability and Safety override confidentiality. Downtime is not an acceptable state.
Patching barely possible
- 24/7 operations, lack of vendor patches for legacy systems, impact on certifications.
Proprietary protocols
- Modbus, PROFINET, OPC UA, BACnet, DNP3 - many designed without authentication or encryption.
Lifecycles of 15-25 years
- PLCs and control systems operate for decades. Security problems accumulate over time.
Physical consequences
- Machine damage, production downtime, environmental harm, risk to personnel - real consequences demand different testing methodology.
OT Security requires fundamentally different testing methods. Classical IT pentest tools can crash OT systems. AWARE7 exclusively uses OT-specialized tools and methods - passive, coordinated with your OT engineers, Safety-First.
OT Network Segmentation
Purdue Enterprise Reference Architecture: Where We Test
The Purdue Model defines the network hierarchy in industrial facilities. We test at all levels - and in particular check whether the boundaries between them are truly secure.
Enterprise Network
Systems
External internet, WAN connectivity, remote access infrastructure
AWARE7 Tests
Firewall rules, VPN configuration, external attack surface, internet exposure
Business Planning & Logistics
Systems
ERP systems, MES, production planning, historian servers
AWARE7 Tests
Database access, ERP interfaces, remote desktop services, historian security
Demilitarized Zone (DMZ)
Systems
Data historian, jump server, data diodes, remote access gateway
AWARE7 Tests
DMZ configuration, data diode implementation, jump server hardening, inbound communication rules
Site Operations
Systems
Site-wide SCADA servers, historian, OT domain controller
AWARE7 Tests
SCADA server hardening, Active Directory OT integration, protocol compliance, network segmentation
Area Supervisory Control
Systems
HMI stations, SCADA workstations, engineering workstations
AWARE7 Tests
HMI web interfaces, engineering station access rights, Modbus/OPC UA security, HMI OS hardening
Basic Control
Systems
PLCs, Remote Terminal Units (RTU), Distributed Control Systems (DCS)
AWARE7 Tests
Authentication, default credentials, firmware version, Modbus/PROFINET communication, CPU stop protection
Process
Systems
Sensors, actuators, valves, pumps, drives - physical process
AWARE7 Tests
Communication to field devices, unsecured fieldbus protocols, physical access, tamper protection
Testing Areas
What we test in your OT environment
Four core areas, systematically analyzed - from field device firmware to network segmentation.
ICS/SCADA Security Testing
Systematic security analysis of industrial control systems - from the protocol level to the application layer.
Protocol analysis: Modbus TCP, OPC UA, PROFINET, BACnet, DNP3
PLC authentication and access rights
HMI web interfaces for web vulnerabilities (XSS, SQLi, Auth Bypass)
SCADA server hardening and OS security
Engineering workstation security
Historian database access and permissions
IoT Device Penetration Testing
Complete security analysis of IoT devices - hardware, firmware, communication, and cloud backend.
Firmware extraction via JTAG, UART, SPI flash, or update channel
Firmware analysis: hardcoded credentials, CVEs, cryptography
Hardware interfaces: JTAG debugging, UART console, I2C/SPI
Wireless protocols: BLE, Zigbee, LoRa, Z-Wave, WiFi (802.11)
Cloud backend and API security
Update mechanism: signature verification, downgrade attacks
OT Network Segmentation
Testing whether your IT/OT separation truly prevents exploitable lateral movement.
IT/OT boundary: validation of firewall rules and ACLs
VLAN isolation and inter-VLAN routing checks
Data diode verification and unidirectionality testing
Remote access security: VPN, jump servers, remote maintenance
DMZ configuration per IEC 62443 Zone/Conduit model
Lateral movement simulation: from IT into the OT network
Firmware Reverse Engineering
Deep binary analysis of embedded firmware - from simple IoT devices to PLC firmware.
Binary analysis: Ghidra, Binwalk, FACT_core, Radare2
Hardcoded credentials: passwords, API keys, certificates
Known CVEs in deployed libraries (Busybox, OpenSSL, etc.)
Bootloader security: Secure Boot, JTAG protection
Update signature verification and downgrade protection
Cryptographic implementations and key management
Critical Infrastructure
Critical Infrastructure Operators: OT Security as a Legal Obligation
NIS-2 Directive Article 21 and sector-specific regulations require operators of critical infrastructure to implement demonstrable security measures - OT penetration tests are a central instrument for this evidence.
Energy
Power supply, gas pipelines, district heating, fuel distribution networks
Water
Drinking water supply, wastewater treatment, water quality monitoring
Healthcare
Hospitals, laboratories, medical device manufacturers, pharmaceutical companies
Transport
Rail, airports, ports, traffic management systems
Digital Infrastructure
Data centers, CDN, DNS resolvers, internet exchange points
Food
Food production, distribution, logistics above threshold values
NIS-2 Article 21 Requirements
NIS-2 Directive (2022/2555) significantly expands the circle of affected entities. Organizations must implement appropriate and proportionate technical and organizational security measures, report significant incidents within 24-72 hours, and regularly assess their security posture.
Sector-Specific Obligations
Critical infrastructure operators must demonstrate "appropriate organizational and technical precautions," report significant incidents, and conduct security audits at regular intervals. Our reports are tailored to these evidence requirements and support you with supervisory authorities.
Our Critical Infrastructure Value
AWARE7 has successfully supported several critical infrastructure operators from the energy, water, and healthcare sectors through OT assessments. Our reports are aligned with regulatory requirements and help document your compliance with NIS-2 and sector-specific standards.
IEC 62443
IEC 62443 Security Levels: Our Testing Framework
IEC 62443 is the international standard for the security of industrial automation and control systems. We map all findings to this standard.
Casual / Unintentional
Protection against unintentional or accidental violations - basic security mechanisms
Intentional / Simple
Protection against simple, targeted attacks with general knowledge and limited resources
Advanced
Protection against attackers with specific ICS knowledge, moderate resources and motivation
State-Sponsored / APT
Protection against highly motivated, state-sponsored actors with extensive resources
Zone & Conduit Model
IEC 62443 defines security zones and the communication channels between them (conduits). We verify whether your zone/conduit definition matches reality and whether conduits meet the defined security requirements.
Zone boundary verification: do firewalls match the zone definition?
Conduit security analysis: TLS, authentication, authorization
Inter-zone communication: only allowed protocols and ports?
Undocumented connections: expose direct IT/OT connections
Component & System Tests
IEC 62443 distinguishes between security requirements for individual components (Component Level) and the overall system (System Level). We test at both levels.
Component level: PLC, HMI, SCADA server per IEC 62443-4-2
System level: overall facility per IEC 62443-3-3
Security Assessment Report with IEC 62443 mapping
Recommendations for SL uplift per zone and component
Pricing & Packages
Transparent Fixed Prices for OT Security
No hourly overruns, no hidden costs - your budget is plannable.
IoT Device Assessment
5-10 business days
1-5 IoT devices (same type)
Firmware extraction & analysis
Hardware interface tests (JTAG, UART)
Wireless protocol analysis
Cloud backend & API security
Detailed final report
Most chosen
OT Network Assessment
10-15 business days
1 production site
Network analysis (passive + active)
ICS/SCADA protocol testing
PLC & HMI security analysis
IT/OT segmentation verification
Purdue Model compliance check
IEC 62443 mapping in report
Critical Infrastructure Full Assessment
15-25 business days
Multiple sites / large facilities
Full ICS/SCADA + IoT testing
Firmware analysis of all relevant devices
Red team: attack simulation incl. social engineering
Critical infrastructure compliance evidence report
IEC 62443 Security Level Assessment
Executive briefing for CISO/management
Individual Assessment
Multiple sites, specific plant types (energy supply, water treatment, hospitals), combined IT/OT assessments, or retainer models - we will provide you with a tailored quote.
Safety-First Methodology
No test ever endangers your production
OT penetration testing requires the utmost care. AWARE7 has developed its own methodology that enables security-effective tests without endangering operations.
Passive Network Reconnaissance
All tests begin with passive analysis: we listen to network traffic and map devices, protocols, and communication relationships without sending active packets. No requests, no active scans - purely passive via packet capture and protocol analysis. This can also be performed on a mirror port of the switch, without direct network participation.
Test Environment Validation
Where possible, we first conduct critical active tests in a test environment or on dedicated test devices before testing in the production environment. For Siemens S7, a separate PLC test stand can be set up. If no test stand is available, we define with your OT engineers which tests can safely be conducted in production.
Coordinated Maintenance Windows
Active tests in the production environment are conducted exclusively in agreed maintenance windows - typically at night or on weekends, when the plant is stopped or running at minimum capacity. OT technicians and plant operators are on-site throughout the entire test period. All tests are approved in writing in the test plan beforehand.
Rollback & Recovery
Before each active test, we document the baseline state of the affected systems (firmware version, configuration, program backup). A defined rollback procedure is established for each test step. In the unlikely event of an unintended disruption, we can restore the baseline state within minutes.
OT-Specialized Tools
We exclusively use OT-compatible tools. Classical IT pentest tools such as Nessus, Metasploit, or aggressive Nmap scans can damage or crash OT systems. Instead, we use specialized OT security tools designed for industrial environments that understand the specific protocols.
In-house Development · Open Source
Open Operational Technology Testing Guide
AWARE7 has developed the OOTTG - an open security testing standard specifically for OT environments. The guide defines systematic testing procedures for industrial control systems and forms the methodological foundation of our OT penetration tests.
Read OOTTGWhy AWARE7 for Your OT Security
What sets us apart from other providers
Pure awareness platforms don't test systems. Pure consulting firms are too far removed. AWARE7 combines both: we hack your infrastructure and train your employees: tailored to mid-sized companies, personal, without enterprise overhead.
Research and teaching as our foundation
20 %Around 20% of our revenue comes from research projects for the BSI and the BMBF. Our studies, published at ACM and Springer conferences, analyse millions of websites and tens of thousands of phishing emails. Three of our executives are professors at German universities at the same time.
Digital sovereignty: no compromises
100 %From first contact to final report, your data is stored on our own servers in Germany - no US cloud providers, no third-country transfers. Our AI also runs on our own hardware in Germany - with locally operated open-source models. Client and project data never reach external AI services. All staff are permanently employed, covered by social insurance and bound by uniform legal obligations.
More on digital sovereigntyFixed price within 24h: predictable project timelines
Within 24 hours you receive a binding fixed-price quote without hourly rate risk. A well-practised team and standardised processes ensure a clear schedule with a defined start and end date.
Your dedicated contact
A personal project manager accompanies you from the first meeting to the retest. You book appointments directly with your contact person and keep the same contact throughout the project.
Peer-reviewed publications
Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations
ACM AsiaCCS 2025
Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
A Platform for Physiological and Behavioral Security
NSPW 2025
Jan Hörnemann
Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem
IEEE/IFIP DSN 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Understanding Regional Filter Lists: Efficacy and Impact
PoPETS 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Who is AWARE7 the right partner for?
Mid-sized companies with 50-2,000 employees
Companies that need real security, without paying for a DAX-corporation provider. Fixed price, clear scope, one point of contact.
IT managers & CISOs
Who have to argue convincingly in-house and need a report in boardroom language for that, not just technical findings.
Regulated industries
Critical infrastructure, healthcare, financial services: NIS-2, ISO 27001, DORA. We know the requirements and deliver evidence that auditors accept.
References
Client references
These case studies are available in German.
Process
Three steps to your OT Security Assessment
Initial Consultation & Scope Definition
In a free initial consultation, we discuss your plant, the systems and protocols in use, your critical infrastructure relevance, and jointly define the exact test scope with you and your OT engineers - including safety constraints and maintenance windows.
Fixed-Price Quote in 24 Hours
Based on the scope document, you will receive a binding fixed-price quote within 24 hours. No hourly overruns, no additional charges - your budget is securely plannable.
OT Pentest with Safety-First Approach
We conduct the test following our Safety-First approach: passive, coordinated with your OT technicians, in agreed maintenance windows. The result: a comprehensive report with IEC 62443 mapping and critical infrastructure compliance documentation.
What is OT Security and how does it differ from IT Security?
Can a penetration test disrupt my plant's ongoing operations?
What is the difference between IEC 62443 and ISO 27001 for OT environments?
What requirements does NIS-2 place on critical infrastructure operators for OT security?
How do you test OT systems safely without risking production outages?
Which OT protocols can you analyze?
How long does an OT Security Assessment take?
What does a firmware analysis of IoT devices include?
What does OT network segmentation mean and why is it so important?
What does an OT Security Penetration Test cost?
Aus dem Blog
Weiterführende Artikel
Active Directory Red Team: Kerberoasting, Golden Ticket und DCSync
AD-Angriffe aus Pentester-Sicht: Kerberoasting, Golden Ticket, DCSync und BloodHound - mit Schutzmaßnahmen für jeden Angriffsvektor.
LLM Security: Prompt Injection, Jailbreaking und KI-Red-Teaming
LLM Red Teaming: Prompt Injection, Jailbreaking, Training-Data-Poisoning und OWASP Top 10 for LLM Applications - mit Defense-Strategien.
Lateral Movement erkennen und stoppen: Angreifer im Netzwerk abfangen
Lateral Movement erkennen: Pass-the-Hash, Kerberoasting, PsExec und WMI - SIEM-Erkennungsregeln und Präventionsmaßnahmen nach dem Initial Access.
Your production is too valuable to wait
Every second industrial organization lacks a dedicated OT Security strategy. A single successful attack on your control systems can mean weeks of production downtime. Let us minimize your attack surface together.
Free · 30 minutes · No obligation
IEC 62443
Testing Framework
ISO 27001
Certified
NIS-2
Art. 21 Compliant
KRITIS
Experience
OSCP
Certified Testers
ICS/SCADA
Specialized