Skip to main content
Energy · OT penetration test

Case study: OT penetration test in a power plant environment

A week on site, two OT specialists, one power plant. The access control system could be compromised, and together with open network sockets and internal OT-adjacent applications that made a continuous attack chain.

Eine Woche im Kraftwerksumfeld Zwei OT-Spezialisten, ein Kraftwerksstandort, und Befunde, die nach Schwere geordnet und reproduzierbar dokumentiert sind. POWER PLANT SITE >_ 1WEEK ON SITE 2OT SPECIALISTS CRITICAL2 HIGH5 MEDIUM9 LOW14 FINDINGS WITH REPRO STEPS ENERGY · OT PENETRATION TEST IN A POWER PLANT

A mid-sized energy supplier wanted to know how realistic an attack on its power plant environment actually is. Two OT specialists tested for a week, in clearly delimited areas and without intervening in production controllers. What they found was a chain that starts at the access control system.

Project frame

Brief, scope and constraints

A week on site, two specialists, clearly delimited test areas.

Client and environment

A mid-sized energy supplier; the test took place at one power plant site. The client wanted to know how realistic an attack on its power plant environment would actually be.

Duration and team

About a week on site, carried out by two OT security specialists. Preparation and reporting came on top.

Scope and constraints

The access control system, internal OT-adjacent applications, and selected OT network segments. Clearly agreed test areas, no intervention in production control systems.

Starting position

Four questions that needed answering

The focus was on physical and technical routes to an initial access, the security of the access control system in use, internal applications related to OT systems, and segmentation and reachability within defined network areas.

The test was therefore deliberately broader than a pure network test. It was meant to answer whether physical and digital routes can be joined into a continuous attack chain.

Finding 1

The access control system was technically attackable

Test der physischen Sicherheit Leser und Tuer, dahinter ein Besprechungsraum mit einer aktiven Netzwerkdose. Der Weg ins Netz fuehrt durch die Tuer. ENTRY READER MEETING ROOM NETWORK SOCKET ENTRY, LOCKS, NETWORK PORT PHYSICAL SECURITY

What was tested is a widely used access control system, anonymised here. The question was whether an attacker with limited prior knowledge and realistic means could gain administrative control or produce unauthorised access cards.

Within the agreed scope, the compromise went far enough that a new access card could have been created. The cause was a combination of inadequately secured administrative access, missing hardening on individual components, and structural weaknesses in the permission model. The exploitation was controlled, stopped immediately in agreement with the client, and documented.

The actual insight was not the successful access but that the physical security concept could be undone through a digital route.

Findings 2 to 4

Where the other routes were

Each manageable on its own. In combination they made a continuous chain.

Access to the internal network

The walk-through and the technical test found several possible entry points, among them freely accessible and live network sockets in certain areas. Functional, but not additionally secured.

OT-adjacent web applications

Several internal applications related to OT systems, not reachable externally but reachable internally. What we found were weaknesses in authentication, inadequate access controls and privileged function calls. Under controlled conditions, extended access could be obtained.

Segmentation

In agreed network areas we analysed carefully which communication paths actually exist, where the transitions between IT and OT zones lie, and which reachability was unexpected. Non-disruptive and limited to released areas.

Sequence

How the chain came together

Each finding was manageable on its own. The value of the test lay in joining them.

1

Access control system compromised

Administrative control was obtained through inadequately secured administrative access. With it, producing a valid access card would have been possible.

2

Physical access to the site

With such a card, the first barrier the security concept provides falls away. From there an attacker moves through the building like any member of staff.

3

A network socket in the building

Freely accessible and live sockets in certain areas. Functional, not additionally secured, and therefore usable as an entry point into the internal network.

4

Privileges through internal applications

From the internal network, OT-adjacent web applications were reachable whose authentication and access control had weaknesses. Extended access was possible under controlled conditions.

5

Reach towards the OT

The segmentation analysis showed which communication paths actually exist and where reachability was unexpected. That made it possible to state how far the chain would have carried.

Result

What the client had at the end

Within a week, several realistic attack routes could be evidenced: the technical compromise of the access control system, physically realisable entry points into the internal network, and a privilege escalation through internal applications that would have built on an initial access.

The report placed every finding technically, documented the steps reproducibly, and separated what had to be fixed immediately from what belongs in a maintenance window. For the management board there was a summary setting out the attack chain on one page.

What mattered most to the client was less the number of findings than the evidence that physical and digital routes are connected. Until then, access control and the network had been the responsibility of different departments.

Limits

What was not tested, and why

The scope was fixed beforehand. What lay outside it stayed outside.

No production controllers

No active testing took place on control and safety systems in production. Statements about them come from passive analysis and configuration review, not from intervention.

Released network areas only

The segmentation analysis was confined to areas agreed beforehand. Segments not released were neither reached nor assessed.

Stop on success

On the access control system the exploitation was stopped as soon as feasibility was evidenced. No card was created and no entry was taken.

What transfers

What you can take from this for your own site

Three points transfer to most power plant and industrial sites.

First: access control is an IT system. In many organisations it belongs to facility management and therefore appears in no IT security review, although it has administrative access, a permission model and a network connection like any other application.

Second: live network sockets in generally accessible areas are a classic, because they were laid at some point for a purpose and never removed afterwards. They can be inventoried within a day.

Third: internal applications related to OT are rarely tested, because they are not reachable from the internet. That is exactly why they are often the lever that turns a foothold in the network into a serious escalation.

Next step

A similar project?

Referenzdetails nennen wir nach Freigabe und im persönlichen Gespräch.