Skip to main content

Yekta IT wins a European research project for OT penetration testing

Yekta IT is the only German company selected in Open Call 3 of the EU programme CYSSDE. The project is called OT-REX, runs for 18 months and covers plants in energy, rail and water.

The selection

CYSSDE, Open Call 3, and the project page

CYSSDE is a programme for penetration testing and vulnerability assessment, co-funded by the European Union and carried by the European Cybersecurity Competence Centre and its members. It does not hand out its money as a contract but through open calls, to the companies that then run the tests.

Open Call 3 drew more than 150 applications for thirteen places. The projects selected are supported over 18 months. One of them comes from Germany. Our project is called OT-REX, OT Resilience and Exploitation Testing, and works on industrial plants in power supply, rail and water. Thirteen assessments are planned across the programme. What the project covers is on its project page.

How we work

Attack and detection from one house

Rehearsed in the lab, then run on the plant Two panels with the same process line and the same three devices. In the laboratory the test may end in a failure; on the plant in operation the same procedure ends at the device it was aimed at. LAB REPLICA · SAME DEVICES MAY FAIL PLANT IN OPERATION MUST NOT STOP THE SAME PROCEDURE, RUN TWICE REHEARSED IN THE LAB, THEN RUN ON THE PLANT

A control room cannot be switched off because somebody wants to run a scan. A controller that has been in the field since 2009 sometimes answers a port scan differently from what its data sheet promises, and you find that out afterwards. An active test against a plant in operation is therefore not a procedure with a known outcome.

We rehearse the run in our own laboratory environments first and only then work on the plant. YekCity is one of them; alongside it stand rigs for further sectors. In the lab, the things that must not go wrong on the plant are allowed to. What finally runs in an operator network is a procedure that has been through once, not an attempt.

That rehearsal is the expensive part. It costs hardware, build time and people who know the sector, and all of it falls due before the first finding exists. Which is exactly why it is funded: for a single test the effort is hard to justify, across a programme it is not. Through the project we extend the laboratories with real industrial hardware, so that sector environments are reproduced rather than simulated.

Both sides we have in the house go into this. Offensive security supplies the attack paths and the test steps. Blue teaming answers the question of what the same attack would have looked like from the defending side. A finding on its own changes little in a plant as long as nobody knows what signal it raises in monitoring, so every test step comes with the detection pattern that belongs to it.

What comes out of it

What ends up in public

A programme like CYSSDE does not pay for reports. It pays for what the tests leave behind for everybody else: test steps that can be repeated, attack paths that work in more than one plant, and detection patterns an operator can take into their own monitoring. That goes out anonymised, beyond the circle of those directly involved.

For us there is what stays in the laboratory. Every sector environment we reproduce remains usable afterwards, for the next test, for exercises and for work on detection rules. Which is why the laboratory build is part of the project and not a by-product of it.

Next step

Questions about OT testing?

Telephone
0231 39814905
Mon–Fri · 9am–5pm CET
Location
Dortmund
Ruhrallee 9 · 44139
Questions about this?

Talk to our consultants.