New The 2026 Continuous Validation Methodology Paper is now available. Read the paper →

VORNAC OT Pentesting

Adversarial validation for industrial control systems: PLCs, RTUs, SCADA, DCS, and safety instrumented systems. Proven without stopping the line. Every finding mapped to its IEC 62443 zone and conduit and packaged as the §8a BSIG Nachweis your BSI auditor accepts. German data centers, German jurisdiction.

See the method.

In 2017, TRITON became the first malware ever written to reach into the safety system that stops an explosion.

OT failures are measured in downtime, ruined batches, and lives, not leaked rows. A test that trips a controller is not a finding, it is the breach. We prove the exploit without ever becoming it.

0
Unplanned downtime from testing.

Passive-first discovery. Active steps run only inside an approved change window, with a plant engineer at the console and a safe-state rollback armed.

0
Safety functions tripped.

The SIS is validated by design review and on a replica, never by injecting into a live safety loop. That is the lesson from TRITON.

0
Packets to live controllers without your written sign-off.

Nothing touches Level 0–1 on the running plant unless you approved it. German data centers, German jurisdiction. No US Cloud Act exposure.

An IT pentest pointed at a plant isn’t a test. It’s an incident waiting for a trigger.

OT is the inverse discipline. Safety and availability outrank confidentiality, systems run 20–30 years without a reboot, and a routine port scan can crash a controller older than the engineer maintaining it.

The IT playbook, pointed at OT

  • Top priorityConfidentiality of data. The classic CIA triad.
  • DiscoveryActive scans and aggressive enumeration against everything in range.
  • Where it runsLive production. “Just don’t break it.”
  • Change modelReboot and patch freely on a monthly cadence.
  • Evidence producedA generic CVE / CVSS list.
  • Top prioritySafety over availability, both over confidentiality. A stopped process, or a tripped safety function, is the breach.
  • DiscoveryPassive protocol capture first. An Nmap-style sweep can hang a 20-year-old PLC, so nothing is probed until it is mapped.
  • Where it runsLab bench, digital twin, or hardware-in-the-loop replica first; supervised on-site only inside an approved window.
  • Change modelNo free reboots. Vendor-locked firmware, proprietary protocols, patch windows measured in years.
  • Evidence producedFindings per IEC 62443 zone and conduit, SL-T vs SL-A gaps, packaged as the §8a BSIG Nachweis.

Proven safely, without risking the plant.

We understand the plant before we touch it. We act only with your sign-off. Nothing active happens on a live asset without an agreed window and a named authority’s approval.

Scope by Purdue level & set the safety envelope

Levels in scope (L0–L3.5), maintenance windows, the named safety authority, emergency-stop and rollback contacts, rules of engagement and abort criteria. All agreed before anything begins.

Passive reconnaissance & Purdue mapping

SPAN/TAP capture, asset and firmware inventory, passive dissection of Modbus, DNP3, S7comm, OPC-UA, PROFINET, EtherNet/IP and IEC 60870-5-104. We reconstruct your zones and conduits with zero packets injected into live control.

Safety-gated validation

Every exploit chain is proven first on a lab bench, digital twin, or hardware-in-the-loop replica. Supervised active testing runs only inside an approved window, plant engineer at the console, device health and safe-state watched live. The SIS is never tested on the running plant.

Audit-ready delivery

Exploit-proven findings mapped to IEC 62443 zones and conduits and packaged as the §8a BSIG Nachweis. Immutable log. Remediation ranked by physical consequence, not raw CVSS. Stored in German data centers.

Every OT incident is a descent.

Attackers rarely start on the plant floor. They enter the enterprise and move down the Purdue model, level by level, until a command reaches something physical. The same map §8a BSIG asks you to produce is the map we test against, drawn as IEC 62443 zones and conduits.

  1. Phase IBusiness & OT analysis
  2. Phase IITest plan & safety envelope
  3. Phase IIIExecution: passive → safe-active → twin
  4. Phase IVReporting & §8a Nachweis
L5 Enterprise Zone

Corporate Network

Corporate WAN, internet-facing services, cloud tenants, central IT and identity. The primary initial-access vector: VPNs, remote access, phishing, supply chain.

VORNAC postureSpillover source · tested from the IT side
L4 Enterprise Zone

Site Business Systems

Site ERP, production scheduling, business logistics, local mail and file servers. The usual ransomware foothold that then hunts for a path downward.

Colonial Pipeline · 2021DarkSide hit IT / billing only. OT was never infected. The operator shut the line as a precaution.
VORNAC postureSpillover source · tested from the IT side
L3.5 IT / OT DMZ · Regulated Conduit

Industrial DMZ

Firewalls, data diodes, jump hosts, replicated historians, remote-access brokers, patch-staging. The boundary that keeps IT ransomware out of OT. One dual-homed host collapses it.

VORNAC posturePrimary active test boundary · prove or disprove the conduit
L3 Operations Zone

Site Operations

MES, plant historians, batch and production management, OT domain controllers, patch and AV servers. Shared Active Directory becomes a single point of failure for the whole estate.

VORNAC postureSupervised active · in an approved window
L2 Control Zone

Area Supervisory Control

HMIs, SCADA servers, DCS operator stations, engineering workstations, alarm systems. Mostly Windows, frequently unpatched. A compromised EWS is the classic pivot to push rogue logic down to L1.

Stuxnet · 2010Engineering-workstation pivot; rogue logic pushed onto Siemens S7 PLCs.
VORNAC postureSupervised active · in-window
L1 Control Zone

Basic Control

PLCs, RTUs, IEDs and DCS controllers. Control protocols are unauthenticated. An attacker can download malicious logic or firmware directly.

Industroyer2 · 2022Substation breaker operation over IEC 60870-5-104. Detected and blocked. PIPEDREAM / INCONTROLLER · 2022Modular PLC toolkit (Modbus, CODESYS, OPC-UA). Caught before any destructive use.
VORNAC posturePassive + lab / twin
SIS Safety Zone · own conduit

Safety Instrumented System

SIL-rated logic solvers and safety networks. The last line that brings the process to a safe state. IEC 62443 / IEC 61511 isolate it in its own zone, never as ordinary L1.

TRITON / TRISIS · 2017Targeted a Triconex safety controller; it failed and tripped the plant to a safe state.
VORNAC postureDesign review + replica · never live
L0 Process

Field / Process (I/O)

The physical process itself: sensors, transmitters, actuators, valves, motors, drives. No authentication; manipulation has direct physical and safety consequences and is hard to detect.

VORNAC posturePassive only · proven on a twin
Physical process A valve forced open · a rotor driven to overspeed · a safety interlock quietly bypassed.
  • IEC 62443 zone & conduit findings
  • SL-T target vs achieved SL-A gap, per zone
  • §8a BSIG Nachweis evidence package
  • Attack-detection validation (§8a Abs. 1a)
  • Remediation ranked by physical consequence

The full industrial estate. Field bus to enterprise seam.

From a sensor on the line to the vendor VPN. Every layer an attacker actually uses to reach the process.

PLCs, RTUs, IEDs & drives

Passive protocol analysis, firmware review, logic-integrity and unauthenticated-write checks against the controllers that move the process.

HMI, SCADA & DCS

Authentication, project-file integrity, unsigned logic-download paths, and operator-view manipulation on the stations that run the plant.

Safety instrumented systems

Non-disruptive validation of the safety / basic-process separation (the boundary TRITON went after) on SIL-rated logic solvers in their own zone.

Engineering workstations & logic

Project-file and logic-download abuse (the path both Stuxnet and TRITON used to reach controllers) across the vendor toolchains.

IT/OT DMZ, conduits & remote access

Firewalls, data diodes, jump hosts, historians, vendor VPN and removable media. Segmentation and conduit enforcement per IEC 62443-3-2.

Building & site systems

BACnet building management, power and UPS, physical access. The soft underbelly that quietly bridges into the OT network.

The physical consequence is different in every plant.

What “reaching L0” means depends on what your L0 controls: a breaker, a dosing pump, a safety interlock, a robot cell.

Your obligation. Our evidence.

KRITIS and NIS2 don’t ask whether you feel secure. They ask you to prove it, on the regulator’s cadence, in the regulator’s language. VORNAC produces the proof.

One engagement. Evidence in every auditor’s format.

Built on the standard your auditor tests you against.

ISO 27001

Built on ISO 27001

BSI

Aligned with BSI & KRITIS

CISSP

CISSP certified

OSCP

OSCP certified

Every test, finding, and report is stored and processed exclusively in German data centers, under German jurisdiction. No US Cloud Act exposure, no third-country transfers.

Prove your OT is secure.
Without stopping the line.

A 30-minute scoping session. We map your Purdue levels, your maintenance windows, and the exact tests we would run, before anything touches a live asset.

See the method.