Blog · K.11 · Industry

Penetration testing for manufacturing

On a factory floor, downtime is measured in money per minute — and that's exactly what makes manufacturers a favourite ransomware target. Worse, decades-old control systems that were never meant to be networked now sit one misconfigured firewall away from the corporate IT an attacker phishes into. The whole game is the IT/OT boundary. Here's why factories get hit, what to test, and how to test live production without breaking it.

ManufacturingIT/OTSCADARansomwareOTCC
Manufacturing: Ransomware & Downtime · IT/OT Convergence · Legacy Unpatched OT · ERP / MES / SCADA · IT→OT Boundary · Safe, Passive-first OT Testing Manufacturing: Ransomware & Downtime · IT/OT Convergence · Legacy Unpatched OT · ERP / MES / SCADA · IT→OT Boundary · Safe, Passive-first OT Testing
// TL;DR

Manufacturers are heavily targeted because downtime is extraordinarily costly (ideal for ransomware extortion) and factories increasingly connect legacy, unpatchable OT to corporate IT. The central risk — and the focus of a test — is IT/OT convergence: can an attacker who phishes into the office network reach the plant? A test spans corporate IT, ERP/MES, the IT/OT boundary and segmentation, and (carefully) the OT/SCADA environment. OT testing is passive-first and read-only, with active testing agreed and ideally run against a test rig or maintenance window — the plant team involved throughout. Drivers include OT controls like NCA OTCC, the PDPL, supply-chain contracts, insurers, and the raw cost of downtime. Full detail below.

// 01 Why manufacturing is a prime target

Manufacturing has climbed to the top of most-attacked-sector rankings for one blunt reason: downtime is unbearable. A halted production line loses money every minute, so attackers know a ransomware hit creates enormous pressure to pay fast — it's extortion with a countdown. Alongside ransomware, factories are targeted for intellectual property (product designs, processes, formulations) and are increasingly exposed by connectivity: Industry 4.0 links once-isolated machinery to networks and the internet. Much of that machinery runs legacy control systems never designed to be networked or patched, so it carries old, well-documented vulnerabilities in an environment where an outage isn't just costly — it can be a safety event. That combination makes factories both valuable and fragile.

// 02 IT/OT convergence — the core risk

The defining security problem of modern manufacturing is IT/OT convergence: the merging of corporate IT (email, ERP, business systems) with operational technology (the SCADA systems, PLCs and controllers that run the plant). Historically the two were separate — an “air gap.” Today they touch, deliberately or accidentally, and that creates a path from the exposed office network into the fragile production environment. The classic kill chain is: phish an employee → land on the IT network → pivot across a weak boundary → reach OT and hold production hostage. So the heart of a manufacturing test is the boundary: is the segmentation between IT and OT real and effective, or can a foothold in the office reach the factory floor? Where do the two environments unexpectedly connect?

// 03 What to test

01

Corporate IT

The external and internal network, email, identity and Active Directory — the usual entry point.

02

ERP & MES

Business and manufacturing execution systems — often SAP — that bridge IT and the plant.

03

IT/OT boundary

The segmentation, firewalls and data flows between corporate IT and the OT network.

04

OT / SCADA

The control systems — approached conservatively, passive-first.

// 04 Testing live production safely

“Can you pentest my factory without stopping it?” is the first question, and the answer shapes the whole engagement. Corporate IT can be tested normally. The OT side is approached conservatively, because industrial equipment can be brittle and an outage carries production and safety consequences. A competent OT engagement is weighted toward passive and read-only techniques — architecture and configuration review, network traffic inspection, and IT/OT boundary testing — with any active testing agreed in advance and, where possible, run against a test environment or a planned maintenance window. The plant and controls-engineering team stay involved throughout. The goal is a clear picture of exposure without becoming the very incident you're trying to prevent — the same discipline we bring to oil, gas and energy OT.

// 05 Regulatory & commercial drivers

Several forces push manufacturers to test. Handlers of operational technology and critical systems may fall under national OT and critical-infrastructure controls — such as the NCA OTCC in Saudi Arabia — and broader national cybersecurity frameworks. Those processing personal data answer to the regional PDPLs. Manufacturers in regulated supply chains (defence, energy, pharmaceuticals, food) inherit customer and sector-specific requirements. And even absent a single mandating regulator, insurers increasingly require evidence of testing, enterprise customers demand it, and the sheer cost of downtime makes a proactive test cheap by comparison. Map your specific obligations with the requirements finder; engagements follow our methodology, reported to the frameworks you answer to.

// 06 Frequently asked questions

Why is manufacturing a target?

Downtime is extraordinarily costly, making factories ideal ransomware targets, and they increasingly connect legacy OT to corporate IT and the internet. Attackers halt production to extort payment, steal IP and designs, and exploit IT/OT convergence to reach the plant. Much industrial equipment was never designed to be networked or patched, presenting old vulnerabilities where an outage means financial and safety impact.

What is IT/OT convergence and why does it matter?

It's the merging of corporate IT with the OT that runs the plant (SCADA, PLCs, control systems). It creates a path from the exposed IT network into the fragile OT environment. A test focuses on this boundary — whether a compromise of the office network can reach production, whether IT/OT segmentation is real and effective, and where the two unexpectedly touch.

Is it safe to test a live factory?

OT must be tested carefully because industrial systems can be fragile and outages have safety and production consequences. A competent engagement is weighted to passive and read-only techniques — architecture review, configuration analysis, traffic inspection, boundary testing — with active testing agreed in advance and ideally against a test environment or maintenance window. IT is tested normally; OT conservatively, with the plant team involved.

What regulations apply in the GCC?

Handlers of OT and critical systems may fall under national OT controls like the NCA OTCC and broader cybersecurity frameworks. Personal-data processors are subject to the regional PDPLs, and manufacturers in regulated supply chains face customer and sector requirements. Even absent a single regulator, insurers, enterprise customers and downtime cost drive testing.

// 07 Related reading

UG

Usama Gul

Founder & Penetration Testing Lead, CyberFortify

Tests manufacturing environments across the GCC — corporate IT, ERP/MES and the IT/OT boundary — with a passive-first, plant-team-involved approach to OT so exposure surfaces without risking production.

Running a factory?

We'll test your corporate IT, ERP/MES and the IT/OT boundary — and approach OT passive-first with your plant team — so exposure surfaces without ever risking production.

Scope a manufacturing test → OT / ICS testing →