Skip to content
StrikeCyberStrikeCyber
Manufacturing and Energy

OT Security Assessment for a Manufacturing and Energy Operator

A manufacturing and energy operator needed to know whether an attacker in its corporate network could reach production control systems.

Manufacturing and Energy sector
Manufacturing and Energy
Industry
Manufacturing and Energy
Services
Penetration Testing, Vulnerability Assessments
Engagement
IT and OT boundary assessment

The Challenge

The client operates industrial facilities where operational technology controls physical processes that run continuously. A cyber incident in that environment does not merely expose data; it can halt production, damage equipment or create a safety hazard. The operator's central question was straightforward and difficult to answer: if an attacker compromised the corporate network, could they reach the control systems?

The estate had the profile common to industrial operators. Control systems had been installed over decades, ran software that could not simply be patched, and had been progressively connected to corporate networks for remote monitoring and efficiency reporting. Each of those connections was individually reasonable. Nobody had assessed what they added up to.

Our Approach

StrikeCyber assessed the IT estate conventionally and the OT estate with the caution the environment demands, working alongside the operator's control engineers throughout.

  • Full assessment of the corporate IT environment, establishing what an attacker could achieve after an initial compromise.
  • Mapping every connection between corporate and control networks, including the ones absent from the network documentation.
  • Passive assessment of the OT environment, using traffic analysis and configuration review rather than active scanning, because active scanning of legacy control equipment carries genuine operational risk.

No technique was used against production control systems without the control engineers' agreement and a rollback plan. That constraint is not a limitation of the assessment; it is a condition of doing this work responsibly.

What We Found

  • Undocumented connectivity. Several network paths between corporate and control environments were not present in any diagram, including one created for a vendor project that had finished two years earlier.
  • Shared credentials across the boundary. Engineering workstations used credentials that were also valid in the corporate domain, so a corporate compromise directly yielded control network access.
  • A jump host without controls. The intended route between environments existed but had no session recording, no multi-factor authentication and local accounts that had not been reviewed.
  • Legacy protocols without authentication. Several control protocols in use provide no authentication by design, which is expected, but they were reachable from further inside the network than they should have been.

The Outcome

The operator removed the undocumented connections, rebuilt the jump host with multi-factor authentication and session recording as the single controlled route between environments, and separated engineering credentials from the corporate domain entirely. Network segmentation was tightened so the unauthenticated control protocols were reachable only from the systems that legitimately needed them.

A follow-up assessment confirmed that a compromise of the corporate environment no longer yielded a path into production control. Throughout the engagement and the remediation, production continued without interruption.

Why It Matters

The convergence of IT and OT delivers real operational value, and it also creates a route from an ordinary phishing email to a physical process. Industrial operators are a standing target for both ransomware crews and state-aligned actors, and CISA has repeatedly warned about exactly this boundary. Assessing it safely requires operators who understand that a technique appropriate for a web server can damage a controller. To assess your IT and OT boundary, get in touch.

FAQ

About this case study

Is this a real StrikeCyber engagement?

Yes. This manufacturing and energy case study is drawn from a genuine engagement, anonymised where needed to protect the client, showing the challenge, our approach and the outcome.

Can StrikeCyber deliver similar results for our organization?

Yes. The expert-led, prioritized approach behind this outcome applies across manufacturing and energy and other sectors and organization sizes. Scope a free consultation to discuss your environment.

How is client confidentiality protected?

Findings and client data are isolated to your organization and handled in access-limited environments we control in the United States. Nothing is published without the client's consent.

Ready to take the offensive?

StrikeCyber specializes in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

(877) 657-8496Free Consultation