Operational Technology Penetration Testing

Operational Technology Penetration Testing (OT pentesting) serves to simulate a cyber attack on your OT environment to pinpoint where your system is weak or vulnerable. At CyberPrism, we deploy a range of interlinked tools and techniques to test your system, identify where security gaps exist – and then work with you to close them.

Operational Technology Penetration Testing

Testing for vulnerabilities in operational technology (OT) is a critical process. It entails challenges which can usually be managed with expert support – but should never be ignored.

OT systems are often fragile from a pentesting perspective as many devices used in OT domains are unable to process anything other than the communications they were anticipating.

Some of these sensitive devices may not even recover from the testing process if they’ve been negatively impacted, and may require local intervention or even replacement.

However, there are elements in most OT systems that can be tested in exactly the same way as an IT device as long as it is possible to guarantee that test traffic intended for these devices is not seen by other more sensitive devices that may share the same network, or a network that is routable from the network under test. As interconnectivity in and between older systems, or those not built to or assessed to ISA/IEC 62443, may well be undocumented, testing against even these ‘safe’ devices can present an operational risk.

So what can be done to help ensure a safe and effective OT pentesting process in this context?

At CyberPrism we adjust our approach to reflect the fragility of the system under test and its proximity to other systems that could be impacted – all while focused on delivering a rigorous test exercise that delivers reliable results. Our techniques include:

> Often deploying a Process Engineer alongside the penetration tester so we can fully understand the operational risks. We discuss these with you so we can jointly define an approach that satisfies the risk appetite of all parties. There is no such thing as a zero-risk test in an operational system!

> Frequently testing half of a dual redundant system as long as the synchronisation path between the two halves is removed and the two halves are on physically separate networks. This ensures the operational ‘half’ will not be impacted by the testing.

> Working with you to understand how the network is arranged, and how any adjacent systems (not under test) are connected and protected. It may be that temporary disconnections are made prior to testing.

> Acknowledging when testing exceeds the risk appetite and opting for one of a number of alternatives instead:

> Table-top analysis based on architecture drawings and device information drawn from the asset register, or by querying devices using OEM tools intended for that purpose, rather than penetration testing tools that may try to enumerate the same data using non-device-supported methods.

> Passive pentesting, which can take several forms:**

  • Passive network traffic capture (PCAPs) and subsequent analysis.
  • Shadow system creation, often using your spare holding or training equipment and testing against the shadow system.
  • Very focused offline device testing, often driven by a comparison of the asset register with published Common Vulnerabilities and Exposures (CVEs). It can be important to test specific devices to confirm the relevance of CVEs to the system as built – CVEs may score too high or too low when devices are used in OT environments as they are often assigned based on IT imperatives and tend to be weighted towards confidentiality (IT) and not availability (OT).

Testing out of operational hours (non-continuous or batch processes), or immediately before planned shutdowns/outages, so that any negative impact arising from the testing will not have a significant effect on operations. This approach allows for aggressive testing, replicating the likely behaviors of an adversary once they have gained access, enumerated your system and decided to interfere with or deny control. Aggressive testing, where possible, provides the very best indication of what an attacker may be able to achieve and enables you to understand how best to protect your system.

Types of testing

> Black Hat: with no prior knowledge or supporting documentation, we connect into your network to perform reconnaissance and light-touch tests. This should identify any vulnerabilities that may allow access to your systems or data.

> Grey Hat: using technical documentation you provide, we carry out logical scans as both a non-authenticated user and a standard user.

> White Hat: using technical documentation, we access the network with administrator access subject to your support and agreement. This test requires your full support as administrator privileges are within your responsibility and domain. The outcome should be a review of the network, including Active Directory, server/workstation builds and a more in-depth analysis of patching and updates.

SPEAK TO AN EXPERT

Pentesting is not a single, standalone solution – it can encompass a variety of tests and services. Get in touch with us today and let us prepare a bespoke OT pentesting package to keep you one step ahead of the hackers.