Kern County is a mature field: thousands of small, old, scattered assets rather than one defensible site. CyberFortify runs manual network, web, cloud and API penetration tests for Bakersfield organisations, plus passive OT asset discovery and architecture review aligned to NIST CSF, NIST SP 800-82 and IEC 62443. Enterprise findings map to SOC 2 and CCPA/CPRA. Fixed price, free retest.
// 01 Why Bakersfield businesses need penetration testing
Count the things that can be reached, and the shape of the Kern County problem appears immediately. A century of drilling has left a landscape of pump jacks, tank batteries, gathering lines, separators, metering skids and injection plants spread across hundreds of square miles - automated in waves, decades apart, by crews solving the problem in front of them. An RTU installed in the 1990s still reports. A serial converter bolted on to make an old controller speak Ethernet still works. A cellular modem fitted to save a truck roll still answers. Much of it runs firmware from a vendor that no longer exists, on hardware that passed end-of-life years ago.
So the useful question for a Bakersfield operator is not whether the perimeter is strong. It is: how many forgotten devices are reachable, and what does each one still control? Discovery across telemetry backhaul, polling records, historian sources and remote-access paths routinely surfaces equipment nobody owns - a legacy controller on a decommissioned lease still on the radio network, an engineering laptop with saved credentials for half the field, a vendor dial-in that outlived the contract. Steam injection and enhanced-recovery systems raise the stakes, carrying real process consequence over the same shared, ageing links. Automated scanning answers none of this: unsafe to point at fragile field equipment, blind to what sits behind a cellular link it never sees.
// 02 Compliance and regulatory drivers in Bakersfield
Kern County operators sit under a US federal, state and voluntary stack rather than a single regulator. These are the obligations CyberFortify most often maps evidence against for organisations in Bakersfield.
NIST SP 800-82
The federal guide to industrial control system security anchors our OT work - inventory, segmentation, remote-access control and monitoring where availability and safety outrank all else.
NIST CSF
Findings map to Identify, Protect, Detect, Respond and Recover, giving boards and insurers one defensible view across a mixed IT and field-automation estate.
IEC 62443
Zones, conduits and security levels give scattered upstream assets a structure they usually lack, in language your automation engineers already use.
CISA guidance & TSA Security Directives
CISA critical-infrastructure guidance and the voluntary cross-sector performance goals set expectations on asset inventory and remote access; covered pipeline operators carry the applicable TSA Security Directives too.
CalGEM reporting integrity
Production, injection and environmental data submitted to CalGEM carries legal weight. We test the chain from instrumentation through historians for weak authentication and unlogged modification.
// 03 Penetration testing services for Bakersfield
Which service leads depends on what you run. Operators start with network testing and OT discovery; oilfield service firms lead with web and cloud; agriculture, logistics and processing businesses begin with the enterprise perimeter.
Network pen testing
External perimeter, internal Active Directory, remote-access review and IT/OT segmentation testing - the anchor assessment here.
API pen testing
Telemetry ingestion, historian and integration APIs - authorisation flaws, token abuse and over-trusted machine-to-machine connections.
Web application pen testing
Production dashboards, lease-management portals and reporting tools tested against the OWASP Top 10 and business-logic abuse.
Cloud pen testing
AWS, Azure and Google Cloud review for the analytics, historian replication and reporting workloads sitting outside the field network.
Red teaming
Goal-based simulation asking whether a corporate-side intrusion would be detected before it reached anything touching the field.
Mobile app pen testing
iOS and Android testing for the pumper, inspection and field-ticketing apps that carry credentials out to the lease road.
Where an organisation needs help interpreting the result rather than more findings, our compliance consulting and AI security testing practices pick up from there.
// 04 How we deliver to Bakersfield
Plain facts first: our team is based in the Gulf at UTC+3, and California sits ten to eleven hours behind us. We are not local to Bakersfield and we do not run a California office. What we do run is a deliberate daily overlap window - our late afternoon and evening is your morning - so stand-ups, escalations and read-outs happen live with a real tester. Work continues overnight your time, so findings are usually waiting when you start.
What runs remotely
External perimeter, web, cloud, API and remote-access testing, plus OT asset discovery from telemetry, historian and polling data you provide - the large majority of an engagement.
What needs someone on the ground
Internal network and wireless testing, passive capture at field aggregation points and inspection of remote cabinets. We travel where it genuinely changes the answer, scheduled well in advance.
Every engagement opens with a free 30-minute scoping call and a fixed-price quote within the hour. Safety constraints, change-control windows and escalation paths for anything OT-adjacent are agreed in writing up front, with a free remediation retest once fixes ship.
// 05 Industries we secure in Bakersfield
Kern County's economy runs on energy, farming and the movement of both. CyberFortify tests across the sectors that define the risk profile here:
// 06 Our methodology
Bakersfield engagements follow the audit-defensible process CyberFortify runs everywhere, with an OT posture built for fragile, unpatchable equipment. IT testing is grounded in the Penetration Testing Execution Standard and NIST SP 800-115, with exploitation mapped to MITRE ATT&CK including the ICS matrix. OT work is passive by default: asset discovery, traffic capture at aggregation points, configuration and architecture review against NIST SP 800-82 and the IEC 62443 zone-and-conduit model. Active, exploit-driven testing stays on the IT estate and on non-production or offline segments. As a CREST Accreditation Pathway firm we lead with manual testing - automation is never turned loose on live field equipment.
Scoping & rules of engagement
Targets, IT/OT boundaries, safety constraints, test windows and escalation paths agreed in writing before anything is touched.
Fixed quote in 1hAsset discovery & threat modelling
The reachable estate is enumerated - telemetry paths, legacy controllers, remote access, forgotten links - then reconciled against your own inventory.
Discovery firstControlled exploitation
Weaknesses chained on the IT side, boundary controls validated toward the field under agreed conditions, false positives removed by hand.
Safety-firstReporting & free retest
Executive summary, CVSS-scored detail and NIST CSF, SP 800-82 and IEC 62443 mapping - then a free retest once fixes ship.
Audit-ready// 07 Why CyberFortify for Bakersfield
A scan-and-report vendor
Tool output rebadged as a pen test - dangerous to point at ageing field equipment, silent about the devices it never discovered, thin on the evidence an auditor or insurer will ask for.
CyberFortify
A CREST-pathway team that treats discovery as the first deliverable, tests the IT estate by hand, keeps the OT side passive unless you say otherwise, and maps findings to NIST CSF, SP 800-82, IEC 62443, SOC 2 and CCPA/CPRA. Fixed pricing, honest scheduling, free retest.
Bakersfield engagements often pair network testing with a red team simulation to establish whether an intrusion would be noticed at all.
// 08 Frequently asked questions
Do you test oilfield control systems around Bakersfield?
Yes, within strict safety limits. On the OT side we work passively: asset discovery, traffic capture at aggregation points, configuration and architecture review against the IEC 62443 zone-and-conduit model and NIST SP 800-82. Active, exploit-driven testing is confined to the IT estate and to non-production or offline segments. Nothing is exploited against a live wellsite, gathering line or injection control system without agreed, controlled conditions signed off by your operations team.
We do not know how many field devices we have. Can you still test?
That is the normal starting point in a mature field, and discovery is the first deliverable rather than a blocker. We build an inventory from your telemetry aggregation points, historian and polling records, cellular and radio backhaul, remote-access paths and engineering workstations, then reconcile it against what your team believes exists. The gap between the two lists is usually the most valuable finding of the engagement.
Which standards do you map findings to for a Bakersfield operator?
NIST CSF for the overall programme, NIST SP 800-82 and IEC 62443 for industrial control systems, and CISA critical-infrastructure guidance including the voluntary cross-sector performance goals. Pipeline operators add the applicable TSA Security Directives. On the enterprise side we map to SOC 2 criteria, ISO 27001 A.8.29 and CCPA/CPRA obligations, and to PCI DSS 4.0 where card data is handled.
You are based in the Gulf. How does that work across ten or eleven hours of time difference?
We are not local to Bakersfield and we do not claim a California office. Our team works from UTC+3, so we hold a deliberate daily overlap window - our late afternoon and evening is your morning - for stand-ups, escalations and read-outs. Testing then progresses overnight your time, and you get findings waiting when you start work. Anything critical is escalated immediately rather than held for the next call.
Can testing help protect the production and environmental data we report to the state?
Yes. Production, injection and environmental figures submitted to CalGEM and other agencies originate in field instrumentation and pass through historians, reporting databases and often a spreadsheet or two before submission. We test that chain for weak authentication, excessive write access and unlogged modification, so you can show the numbers you filed are the numbers your instruments recorded.