OT and ICS Security Assessment

Operational technology cannot be assessed the way IT is. Active scanning that is routine on a corporate network can knock over a controller that was never designed to tolerate it — and on a building or plant network, that is not an inconvenience, it is an incident. This is the main reason OT environments go unassessed for years.

Our OT and ICS security assessment is deliberately passive: we work from captured traffic and configuration review. We do not scan, probe, inject packets or interact with your control network.

What We Assess

  • Asset discovery — what is actually on the network, which is frequently not what the documentation says.
  • Protocol exposure — BACnet, Modbus, DNP3, S7comm, EtherNet/IP, OPC UA and others, and what they reveal.
  • Segmentation reality — whether OT and IT are separated in practice or only on the diagram.
  • Remote access paths — how vendors and technicians get in, and what that grants them.
  • Authentication and credential exposure — shared accounts, default credentials, cleartext protocols.
  • Niagara and BAS configuration — user accounts, permissions, exposed services, station hardening.

Why Passive Is the Feature

“We will never touch your control network” is what makes the assessment possible at all. Facilities and plant teams have usually refused security assessment for good reason; removing the risk of disruption removes the objection.

The Advantage of Knowing Both Sides

Most security firms can read a packet capture. Far fewer can tell you what a malformed BACnet broadcast storm does to a building, or whether a Niagara station’s permission model is sane. Our sister practice SoftwarePile engineers these systems daily, so findings come with remediation that is actually implementable. More detail on the tooling is on our OT and network forensics page.

Tell us what you need assessed — and what must not be touched. We will scope it around that constraint.

Related services