Case study: OT penetration test in a power plant environment
A week on site, two OT specialists, one power plant. The access control system could be compromised, and together with open network sockets and internal OT-adjacent applications that made a continuous attack chain.
A mid-sized energy supplier wanted to know how realistic an attack on its power plant environment actually is. Two OT specialists tested for a week, in clearly delimited areas and without intervening in production controllers. What they found was a chain that starts at the access control system.
Brief, scope and constraints
A week on site, two specialists, clearly delimited test areas.
Client and environment
A mid-sized energy supplier; the test took place at one power plant site. The client wanted to know how realistic an attack on its power plant environment would actually be.
Duration and team
About a week on site, carried out by two OT security specialists. Preparation and reporting came on top.
Scope and constraints
The access control system, internal OT-adjacent applications, and selected OT network segments. Clearly agreed test areas, no intervention in production control systems.
Four questions that needed answering
The focus was on physical and technical routes to an initial access, the security of the access control system in use, internal applications related to OT systems, and segmentation and reachability within defined network areas.
The test was therefore deliberately broader than a pure network test. It was meant to answer whether physical and digital routes can be joined into a continuous attack chain.
The access control system was technically attackable
What was tested is a widely used access control system, anonymised here. The question was whether an attacker with limited prior knowledge and realistic means could gain administrative control or produce unauthorised access cards.
Within the agreed scope, the compromise went far enough that a new access card could have been created. The cause was a combination of inadequately secured administrative access, missing hardening on individual components, and structural weaknesses in the permission model. The exploitation was controlled, stopped immediately in agreement with the client, and documented.
The actual insight was not the successful access but that the physical security concept could be undone through a digital route.
Where the other routes were
Each manageable on its own. In combination they made a continuous chain.
Access to the internal network
The walk-through and the technical test found several possible entry points, among them freely accessible and live network sockets in certain areas. Functional, but not additionally secured.
OT-adjacent web applications
Several internal applications related to OT systems, not reachable externally but reachable internally. What we found were weaknesses in authentication, inadequate access controls and privileged function calls. Under controlled conditions, extended access could be obtained.
Segmentation
In agreed network areas we analysed carefully which communication paths actually exist, where the transitions between IT and OT zones lie, and which reachability was unexpected. Non-disruptive and limited to released areas.
How the chain came together
Each finding was manageable on its own. The value of the test lay in joining them.
Access control system compromised
Administrative control was obtained through inadequately secured administrative access. With it, producing a valid access card would have been possible.
Physical access to the site
With such a card, the first barrier the security concept provides falls away. From there an attacker moves through the building like any member of staff.
A network socket in the building
Freely accessible and live sockets in certain areas. Functional, not additionally secured, and therefore usable as an entry point into the internal network.
Privileges through internal applications
From the internal network, OT-adjacent web applications were reachable whose authentication and access control had weaknesses. Extended access was possible under controlled conditions.
Reach towards the OT
The segmentation analysis showed which communication paths actually exist and where reachability was unexpected. That made it possible to state how far the chain would have carried.
What the client had at the end
Within a week, several realistic attack routes could be evidenced: the technical compromise of the access control system, physically realisable entry points into the internal network, and a privilege escalation through internal applications that would have built on an initial access.
The report placed every finding technically, documented the steps reproducibly, and separated what had to be fixed immediately from what belongs in a maintenance window. For the management board there was a summary setting out the attack chain on one page.
What mattered most to the client was less the number of findings than the evidence that physical and digital routes are connected. Until then, access control and the network had been the responsibility of different departments.
What was not tested, and why
The scope was fixed beforehand. What lay outside it stayed outside.
No production controllers
No active testing took place on control and safety systems in production. Statements about them come from passive analysis and configuration review, not from intervention.
Released network areas only
The segmentation analysis was confined to areas agreed beforehand. Segments not released were neither reached nor assessed.
Stop on success
On the access control system the exploitation was stopped as soon as feasibility was evidenced. No card was created and no entry was taken.
What you can take from this for your own site
Three points transfer to most power plant and industrial sites.
First: access control is an IT system. In many organisations it belongs to facility management and therefore appears in no IT security review, although it has administrative access, a permission model and a network connection like any other application.
Second: live network sockets in generally accessible areas are a classic, because they were laid at some point for a purpose and never removed afterwards. They can be inventoried within a day.
Third: internal applications related to OT are rarely tested, because they are not reachable from the internet. That is exactly why they are often the lever that turns a foothold in the network into a serious escalation.
A similar project?
Referenzdetails nennen wir nach Freigabe und im persönlichen Gespräch.