Pen testing · Commerce & industry
Penetration Testing for Manufacturers & Industrial IoT
Our penetration testing shows a manufacturer how an attacker would reach the systems production depends on — corporate IT, ERP and customer portals, vendor remote access and the IT/OT boundary — under rules of engagement built around one constraint: nothing we do may stop the line. Active techniques stay on the IT side; the OT side is examined through architecture review and passive methods, scheduled into maintenance and shutdown windows. Engagements are usually triggered by an OEM audit, an insurer's questions or a segmentation project that needs proof it worked.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What an OT-aware test has to examine in a plant
Testing a manufacturer is less about finding any vulnerability and more about tracing the specific paths that end at the production floor.
The corporate network attackers land on
Email, endpoints, file servers and domain infrastructure — the environment ransomware actually encrypts in manufacturing incidents, and the launch point for everything downstream.
Zoning between business and production
Whether the separation on the network diagram exists in packets: can a compromised office workstation reach the SCADA VLAN, the historian, or an engineering workstation with controller programming software installed?
Every remote path into the plant
Vendor VPN accounts, Ewon and cellular gateways, TeamViewer and AnyDesk installs on machine PCs, and your own staff remote access — enumerated, tested for MFA and exposure, and checked against who is supposed to hold them.
ERP, EDI and customer-facing applications
The web-reachable surfaces of your ERP, supplier and customer portals, warranty registration sites and EDI integrations, where a flaw exposes both operations and the data OEM auditors ask about.
The internet-facing footprint you forgot
Externally exposed services accumulate over years — a remote-desktop port opened for a vendor, a gateway with a public address. We map what the internet can see before an attacker inventories it for you.
Fragile legacy on the floor
Unpatchable Windows boxes running HMIs and old servers holding recipes get identified and risk-rated through configuration and architecture review — never through blind scanning that could hang them mid-shift.
Regulatory map
Why testing is expected of manufacturers now
No statute orders a plant to run a penetration test, but the documents that govern your revenue increasingly assume one has happened.
Cyber Centre OT protection guidance
ITSAP.00.051 calls for zoning OT away from remote access, MFA-protected VPNs, least privilege and risk-based patching. Testing is how you verify those controls hold under pressure instead of trusting the diagram.
The Cyber Centre's OT threat assessment
Its bulletin describes internet-connected OT being actively probed and cybercriminals triggering OT shutdowns from the IT side — exactly the attack paths a scoped test traces before someone hostile does.
NIST SP 800-171 for CUI environments
If customer drawings or defence data make you a CUI handler, SP 800-171 is your baseline and its security-assessment requirements make periodic technical testing part of demonstrating the controls work.
CMMC assessment timelines
With the DFARS rule effective since November 10, 2025 and C3PAO assessments entering solicitations from November 10, 2026, defence suppliers want independent findings and fixes in hand well before an assessor arrives.
PIPEDA safeguards for the data you hold
Warranty and direct-sales databases carry a safeguard obligation proportionate to sensitivity. A test of the portals and networks holding that data is straightforward evidence you took it seriously.
What goes wrong
What testing finds before an attacker does
The findings that matter in this sector are rarely exotic. They are the mundane gaps that connect a phishing email to a stopped line.
The flat network behind the diagram
Office and plant traffic sharing one broadcast domain, so any compromised laptop can talk to controllers. This is the single most consequential finding we can deliver to a plant, and among the most common.
Standing vendor access without MFA
Machine-builder VPN accounts that never expire, shared support credentials, and remote tools listening on machine PCs. The BRP incident began at a third-party service provider — the supply-chain door is a proven entry point.
Gateways facing the internet
Cellular and Ewon-class devices installed for machine monitoring that answer to the public internet, sometimes without IT ever knowing they exist. We find them from outside, the way an attacker would.
Identity bridges into OT
Domain accounts and synchronized credentials valid on both sides of the boundary — the lateral-movement route the Cyber Centre specifically flags — which turn one phished password into plant-floor reach.
Exploitable ERP and portal flaws
Injection points, broken access control and stale integrations in the applications that carry orders, ASNs and warranty data — issues an OEM security audit will also probe, on their schedule rather than yours.
Our pen testing for manufacturers & industrial iot
How the test is scoped around production
Deliverables follow our standard testing service — vulnerability exploration, response observation, improvement guidance and standards awareness — with rules of engagement written for an environment where a bad packet can idle a shift.

Joint scoping with your controls engineer
Before anything runs, we sit with IT and the automation owner to classify every address range: in scope for active testing, passive observation only, or untouchable. PLCs, drives and safety systems land in the last category by default.
Active testing on the IT side
External and internal network testing, phishing-resistance checks where wanted, and application testing of ERP portals, EDI endpoints and warranty sites — run during agreed windows with a live escalation contact.
Boundary and segmentation validation
Controlled attempts to cross from business zones toward production zones, proving whether firewall rules, VLANs and conduits actually block the paths ransomware uses.
Passive OT-side assessment
On the plant network we listen rather than probe: traffic capture, configuration review, and architecture walkthroughs against Cyber Centre guidance and IEC 62443 concepts referenced in customer contracts. No blind scanning of controllers, ever.
Remote-access and exposure review
Enumeration of every inbound path — vendor VPNs, remote-desktop tools, gateways, your own access — with each tested or reviewed for authentication strength and necessity.
Findings you can hand to an OEM
A prioritized report separating line-stopping risks from housekeeping, mapped to the expectations your customers and insurers reference, with a debrief for both leadership and the people doing the fixing.
How the engagement runs
Running the engagement without touching uptime
The sequencing exists to protect production first and produce evidence second.
Step 1
Scope, windows and kill criteria
We agree targets, testing hours (often nights, weekends or a planned shutdown week for anything near the floor), the untouchable list, and the phone-someone-now rule if anything looks unstable.
Step 2
External reconnaissance and testing
We map and test your internet-facing footprint — portals, gateways, remote access — from outside, which carries no risk to plant operations and often yields the most urgent findings.
Step 3
Internal and boundary testing
Inside the corporate network we test what an intruder could reach, then attempt the IT-to-OT crossing under the agreed constraints, with your team watching detection and response in real time.
Step 4
OT review in the plant's own window
Passive collection and configuration review on the production network happen when operations says so — commonly during scheduled maintenance or the July or holiday shutdown.
Step 5
Report, debrief and retest path
You receive prioritized findings with practical fixes, a session for leadership and one for IT, and the option to verify remediations once changes are made.
What it costs
What moves the price of a manufacturing pen test
Scope drives cost: the size of your external footprint, the number of internal networks and plants, how many applications (ERP portals, EDI, warranty sites) are included, and how much OT-side review you want. Constraint-heavy scheduling — night windows, shutdown-week work, an on-call automation engineer — adds coordination time that a pure office-network test would not need.
A focused external test with a boundary review is a much smaller engagement than a multi-plant internal assessment with application testing. Tell us your plant count, targets and the audit or renewal date you are working against, and we will quote the scope that answers it — no more.
Manufacturers & Industrial IoT: Pen testing questions, answered
Yes, because we never point active tools at controllers. Production equipment is classified untouchable at scoping; anything on the OT side is assessed through passive traffic analysis, configuration review and architecture walkthroughs. Active techniques run only on corporate systems and on boundary controls, inside agreed windows, with an escalation contact who can pause work instantly. Industrial devices can fall over from a port scan an office server would shrug off — the methodology exists because of that fact.
That is usually the heart of the engagement. We enumerate every inbound route — machine-builder VPN accounts, Ewon and cellular gateways, TeamViewer or AnyDesk on machine PCs, and staff access — then verify which are reachable from the internet, which lack MFA, and which grant more reach than the vendor's job requires. Boundary testing then shows whether someone on the office network can cross into production zones. Findings map directly to the Cyber Centre's OT guidance your insurer and customers lean on.
Yes — application testing of exactly those surfaces is a common pre-audit scope. We probe your ERP's web front ends, supplier and customer portals, warranty registration flows and EDI integration points for authentication, access-control and injection weaknesses, then hand you findings ordered by severity with time to fix before the auditor arrives. Walking into an OEM review with a recent test report and closed findings changes the tone of the entire conversation.
Shutdown weeks are when the riskier, more valuable work happens: boundary-crossing attempts run with lines already down, passive capture on the production network, review of engineering workstations and historian servers, and physical checks of cabinets and network drops that cannot be inspected mid-production. Plants typically book this months ahead of a July or December window, since the same week is competing with maintenance, upgrades and vendor visits.
Retest the boundary as soon as the project closes — that is the proof the investment worked, and the artifact insurers and OEM auditors actually want to see. After that, the sensible cadence follows change rather than the calendar: a new plant connection, an ERP migration, a new vendor gateway or an IIoT rollout each justify a scoped check, with a fuller test on a recurring cycle sized to your contract and renewal commitments.
More for manufacturers & industrial iot
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.