Adversarial validation for industrial control systems: PLCs, RTUs, SCADA, DCS, and safety instrumented systems. Proven without stopping the line. Every finding mapped to its IEC 62443 zone and conduit and packaged as the §8a BSIG Nachweis your BSI auditor accepts. German data centers, German jurisdiction.
OT failures are measured in downtime, ruined batches, and lives, not leaked rows. A test that trips a controller is not a finding, it is the breach. We prove the exploit without ever becoming it.
Passive-first discovery. Active steps run only inside an approved change window, with a plant engineer at the console and a safe-state rollback armed.
The SIS is validated by design review and on a replica, never by injecting into a live safety loop. That is the lesson from TRITON.
Nothing touches Level 0–1 on the running plant unless you approved it. German data centers, German jurisdiction. No US Cloud Act exposure.
OT is the inverse discipline. Safety and availability outrank confidentiality, systems run 20–30 years without a reboot, and a routine port scan can crash a controller older than the engineer maintaining it.
We understand the plant before we touch it. We act only with your sign-off. Nothing active happens on a live asset without an agreed window and a named authority’s approval.
Levels in scope (L0–L3.5), maintenance windows, the named safety authority, emergency-stop and rollback contacts, rules of engagement and abort criteria. All agreed before anything begins.
SPAN/TAP capture, asset and firmware inventory, passive dissection of Modbus, DNP3, S7comm, OPC-UA, PROFINET, EtherNet/IP and IEC 60870-5-104. We reconstruct your zones and conduits with zero packets injected into live control.
Every exploit chain is proven first on a lab bench, digital twin, or hardware-in-the-loop replica. Supervised active testing runs only inside an approved window, plant engineer at the console, device health and safe-state watched live. The SIS is never tested on the running plant.
Exploit-proven findings mapped to IEC 62443 zones and conduits and packaged as the §8a BSIG Nachweis. Immutable log. Remediation ranked by physical consequence, not raw CVSS. Stored in German data centers.
Attackers rarely start on the plant floor. They enter the enterprise and move down the Purdue model, level by level, until a command reaches something physical. The same map §8a BSIG asks you to produce is the map we test against, drawn as IEC 62443 zones and conduits.
Corporate WAN, internet-facing services, cloud tenants, central IT and identity. The primary initial-access vector: VPNs, remote access, phishing, supply chain.
Site ERP, production scheduling, business logistics, local mail and file servers. The usual ransomware foothold that then hunts for a path downward.
Colonial Pipeline · 2021DarkSide hit IT / billing only. OT was never infected. The operator shut the line as a precaution.Firewalls, data diodes, jump hosts, replicated historians, remote-access brokers, patch-staging. The boundary that keeps IT ransomware out of OT. One dual-homed host collapses it.
MES, plant historians, batch and production management, OT domain controllers, patch and AV servers. Shared Active Directory becomes a single point of failure for the whole estate.
HMIs, SCADA servers, DCS operator stations, engineering workstations, alarm systems. Mostly Windows, frequently unpatched. A compromised EWS is the classic pivot to push rogue logic down to L1.
Stuxnet · 2010Engineering-workstation pivot; rogue logic pushed onto Siemens S7 PLCs.PLCs, RTUs, IEDs and DCS controllers. Control protocols are unauthenticated. An attacker can download malicious logic or firmware directly.
Industroyer2 · 2022Substation breaker operation over IEC 60870-5-104. Detected and blocked. PIPEDREAM / INCONTROLLER · 2022Modular PLC toolkit (Modbus, CODESYS, OPC-UA). Caught before any destructive use.SIL-rated logic solvers and safety networks. The last line that brings the process to a safe state. IEC 62443 / IEC 61511 isolate it in its own zone, never as ordinary L1.
TRITON / TRISIS · 2017Targeted a Triconex safety controller; it failed and tripped the plant to a safe state.The physical process itself: sensors, transmitters, actuators, valves, motors, drives. No authentication; manipulation has direct physical and safety consequences and is hard to detect.
From a sensor on the line to the vendor VPN. Every layer an attacker actually uses to reach the process.
Passive protocol analysis, firmware review, logic-integrity and unauthenticated-write checks against the controllers that move the process.
Authentication, project-file integrity, unsigned logic-download paths, and operator-view manipulation on the stations that run the plant.
Non-disruptive validation of the safety / basic-process separation (the boundary TRITON went after) on SIL-rated logic solvers in their own zone.
Project-file and logic-download abuse (the path both Stuxnet and TRITON used to reach controllers) across the vendor toolchains.
Firewalls, data diodes, jump hosts, historians, vendor VPN and removable media. Segmentation and conduit enforcement per IEC 62443-3-2.
BACnet building management, power and UPS, physical access. The soft underbelly that quietly bridges into the OT network.
What “reaching L0” means depends on what your L0 controls: a breaker, a dosing pump, a safety interlock, a robot cell.
Energy & grid
KRITISRemote breaker operation and protection-relay manipulation. The Industroyer playbook. Ending in a regional blackout.
Water & wastewater
KRITISHMI takeover and a chemical-dosing setpoint change. Unsafe water leaving the plant.
Chemical & process
NAMUR · IEC 61511Safety-system targeting and interlock defeat, TRITON-class. An uncontrolled reaction, release, or hard shutdown.
Automotive & manufacturing
TISAXLine and robot-cell control abuse. Line-down at seven figures an hour, or silent quality sabotage.
Building & facility
Adjacent OTPower, cooling and access control. A plant or data hall down without ever touching the process.
Sector-specific programs for critical infrastructure and automotive.
KRITIS and NIS2 don’t ask whether you feel secure. They ask you to prove it, on the regulator’s cadence, in the regulator’s language. VORNAC produces the proof.
§8a BSIG · KRITIS
Implement state-of-the-art measures and file a Nachweis of their effectiveness to the BSI at least every two years.
Exploit-proven zone-and-conduit findings, compiled as your §8a Nachweis evidence package.
§8a Abs. 1a · Angriffserkennung
KRITIS operators must run systems to detect attacks. Introduced by IT-SiG 2.0 and carried into the BSIG.
Validation that your OT detection actually fires on real attack paths, not just that a sensor is installed.
NIS2 · NIS2UmsG (revising the BSIG)
Widened scope, manufacturing now included, with Article 21 risk-management and testing-effectiveness duties and management accountability.
Supervised OT test reports evidencing that your controls hold under a real attack.
IEC 62443-3-2 / 3-3
Segment the plant into zones and conduits and set a target Security Level (SL-T) for each.
Per-zone SL-T target vs achieved SL-A gap findings, mapped to the exact conduit.
NAMUR NA 163
The German process industry’s security risk-assessment worksheet for safety-related process control, supporting IEC 61511.
Tested reality fed back into your process-control and SIS risk assessment.
One engagement. Evidence in every auditor’s format.
Every test, finding, and report is stored and processed exclusively in German data centers, under German jurisdiction. No US Cloud Act exposure, no third-country transfers.
A 30-minute scoping session. We map your Purdue levels, your maintenance windows, and the exact tests we would run, before anything touches a live asset.