Location · Penetration Testing in Khafji, Saudi Arabia

Penetration testing in Khafji - offshore assets, two parents, one operation.

CyberFortify delivers manual, exploit-driven penetration testing to the offshore, joint-venture and border-logistics operators of Khafji - the northern Gulf city where production comes from platforms out at sea and the operation is run on behalf of two parent organisations. We test the links that reach the platforms and the boundaries that keep each parent's data its own, mapping every finding to the NCA Operational Technology controls and IEC 62443.

Aligned with: NCA OTCC · NCA ECC · IEC 62443 · PDPL · OWASP · PTES · NIST 800-115
OTCC
Remote access aligned
Offshore
Link-aware testing
JV
Data separation tested
Free retest
Serving Khafji: Offshore platforms & production facilities · shore bases & marine support · joint operations & partitioned entitlement · production accounting & allocation · metering & custody transfer · the border crossing & logistics · utilities · contractors & service companies Serving Khafji: Offshore platforms & production facilities · shore bases & marine support · joint operations & partitioned entitlement · production accounting & allocation · metering & custody transfer · the border crossing & logistics · utilities · contractors & service companies
// Executive summary

Khafji runs on assets you cannot drive to and books you cannot mix up. Production sits offshore behind microwave and satellite links, and the operation is conducted for two parent organisations whose entitlement and commercial records must stay separate and correctly attributed. CyberFortify runs manual network and IT testing plus safe, boundary-focused OT assessment here, aligned to the NCA OTCC and ECC, IEC 62443 and the Saudi PDPL. Fixed price, audit-ready reporting, free retest.

// 01 Why Khafji operators need penetration testing

Distance is the security control nobody chose. A platform kilometres offshore has no security team on board and no spare engineer to walk to a cabinet. When something goes wrong on a shore-side network, someone reaches the rack in minutes; offshore, the honest answer is measured in weather windows and boat schedules. That asymmetry is what an attacker buys by going after the connection rather than the facility.

The connection is the surface. Microwave and satellite links carry telemetry, control traffic and vendor sessions out to the platform and back, usually older than the security architecture wrapped around them. We look at what terminates the link at each end, whether its authentication can be bypassed or replayed, whether crew traffic shares a circuit with process data, and whether a foothold on a shore-side jump host converts into reach across the water. Commissioning-era vendor paths tend to survive for years, governed far more loosely than anyone assumes.

The second problem has nothing to do with geography. Khafji's operations are conducted for two parent organisations, which puts one question at the centre of the security model: whose data is whose. Entitlement records, production volumes and allocation splits each belong to a specific party, yet the systems handling them were built for operational convenience rather than strict separation. Integrity is the sharper edge: allocation figures decide what each party is owed, and a scanner cannot tell you whether those numbers could be altered, back-dated or reassigned. A penetration test can.

// 02 Compliance and regulatory drivers in Khafji

Khafji operators carry the Kingdom's industrial control set, with joint-operation governance adding obligations no single-owner site faces. These are the requirements we most often map evidence against here.

R.01 · Remote access

NCA OTCC - secure remote access

The OTCC is explicit about controlling and monitoring remote connectivity into OT environments. For an offshore asset that is the whole ballgame, so we evidence how the link, its authentication and its session controls hold up under attack.

R.02 · Zones & conduits

IEC 62443

Zones and conduits are the natural language for an offshore estate: the platform is a zone, the link a conduit, the shore base another zone. We test whether the boundaries on the diagram exist in the network.

R.03 · JV separation

Entitlement & allocation record integrity

A joint operation must keep each parent's entitlement, production and commercial data separated and correctly attributed. We test whether access controls enforce that split, and whether allocation records could be altered or misattributed without trace.

R.04 · Critical infrastructure

NCA ECC & essential-service expectations

Upstream production is strategically significant infrastructure, bringing the Essential Cybersecurity Controls and the periodic technical-assurance expectations attached to essential services.

R.05 · Personal data

Saudi PDPL

Crew manifests, rotation schedules, medical records and border-crossing documentation are personal data under the PDPL. We test the systems holding them and the contractor platforms processing them on your behalf.

R.06 · Governance

ISO 27001 A.8.29 & NIST CSF

A.8.29 requires security testing in development and acceptance, and joint operations often need one ISMS satisfying two parents' audit programmes. Independent testing supplies the evidence behind both.

// 03 Penetration testing services for Khafji

Khafji engagements usually open on the remote-connectivity path and the applications carrying production and entitlement data. Offshore operators prioritise link and segmentation testing; shore bases, logistics firms and service companies weight web, cloud and API work more heavily.

A.02

Network pen testing

External perimeter, Active Directory, shore-to-platform link architecture, IT/OT segmentation and vendor remote-access testing - the core Khafji assessment.

A.05

API pen testing

Production-reporting, allocation and partner integrations tested for broken object-level authorisation - the flaw that lets one party read or write another's records.

A.01

Web application pen testing

Production-accounting portals, reporting platforms and contractor systems tested against the OWASP Top 10 and multi-tenant business-logic abuse.

A.07

Red teaming

Goal-based simulation asking the offshore question: would an intrusion be detected on shore before it reached the link?

A.04

Cloud pen testing

Configuration-aware testing of historian replicas, analytics and reporting workloads - and the tenancy boundaries separating each parent's view.

A.03

Mobile app pen testing

iOS and Android testing for crew rotation, permit-to-work and field apps used across the offshore and shore-base workforce.

// 04 How we deliver to Khafji

Khafji keeps our exact clock - Arabia Standard Time, UTC+3 - so findings are discussed the same day they land. IT-side testing runs remotely; anything touching the link, the shore base or the platform estate is scheduled with your operations, HSE and OT teams around crew rotation, marine logistics and change control.

What runs remotely

External perimeter, web, cloud and API testing from our secure environment during Khafji business hours, with Arabic or English read-outs and immediate escalation of anything critical.

What we do on-site

Internal network, shore-base DMZ, wireless, segmentation and link-boundary review at your facility, coordinated so no live production or offshore control path is touched outside agreed conditions.

Every engagement opens with a free 30-minute scoping call. For offshore and joint-venture work we fix in writing the safety constraints, the permitted techniques and which parent organisation approves and receives what - alongside the fixed-price quote and a free remediation retest.

// 05 Industries we secure in Khafji

Khafji's economy is offshore production, the shore-side operation supporting it, and the border traffic alongside. We test across the sectors that define the city's risk profile:

Offshore productionPlatforms · remote links · telemetry
Joint operationsEntitlement · allocation · reporting
Shore bases & marineSupply · crew logistics · vessels
Production accountingMetering · historians · reconciliation
Border & logisticsCrossing systems · freight · customs
Utilities & contractorsPower & water · service companies · maintenance

// 06 Our methodology

Every Khafji engagement follows the same audit-defensible process CyberFortify runs worldwide, with OT safety and distance built into each step. IT testing is grounded in the Penetration Testing Execution Standard (PTES) and NIST SP 800-115, with exploitation mapped to MITRE ATT&CK and its ICS knowledge base; OT work follows the IEC 62443 zone-and-conduit model and stays non-disruptive. As a CREST Accreditation Pathway firm, we lead with manual testing and never turn automation loose on a control system we cannot physically reach.

01

Scoping & safety agreement

Targets, link boundaries, offshore constraints, permitted techniques, parent approvals and escalation paths agreed in writing before testing begins.

Fixed quote in 1h
02

Reconnaissance & threat modelling

Attack surface mapped against the two paths that matter here: reach across the link, and reach into the wrong parent's data.

ATT&CK for ICS
03

Controlled exploitation

Weaknesses exploited on the IT side and validated at the OT and link boundary under agreed, safe conditions - production is never the target.

Process-first
04

Reporting & free retest

Executive summary, CVSS-scored technical report and OTCC and IEC 62443 mapping, structured so each parent receives what it is entitled to - then a free retest once fixes ship.

Audit-ready

// 07 Why CyberFortify for Khafji

An IT-only scan vendor

A team that treats an offshore operation like an office network - unsafe near OT, indifferent to who owns which record, delivering findings neither an OTCC assessor nor a joint-venture audit committee can use.

CyberFortify in the Gulf

A Gulf-based, CREST-pathway team that respects the plant and understands the paperwork. Manual exploitation on the IT side, safe boundary validation on the OT side, explicit testing of entitlement separation, findings mapped to NCA OTCC and IEC 62443, fixed pricing and a free retest.

Khafji engagements typically pair network and segmentation testing of the shore-to-platform path with an API assessment of the reporting and allocation interfaces both parents rely on.

// 08 Frequently asked questions

Can you test systems on an offshore platform without going offshore?

Most of the work does not need a helicopter. The path to an offshore facility runs through the shore-side network, the jump hosts, the vendor access paths and the link carrying traffic out to the platform - all of it testable from the beach. We assess the link architecture, the authentication in front of it and the segmentation behind it, then review the platform-side design from documentation and configuration rather than probing live equipment. Where an offshore visit adds real value, we schedule it around crew rotation.

How do you handle a joint operation run for two parent organisations?

We treat the separation itself as a test objective. Entitlement and commercial records belong to different parents, so we check whether the access model enforces that - whether an account granted for one parent's reporting can read the other's, whether shared platforms leak through exports, backups or reporting tools, and whether the audit trail shows who saw what. Findings are written so each parent's security function can act without exposing the other's detail.

Could an attacker change production or allocation figures?

That is exactly what we scope for. Metering output, production accounting and allocation records move through a chain of systems - historians, reconciliation databases, spreadsheets, reporting platforms - and the weakest link is rarely the meter. We trace that chain, test the interfaces writing to it, and establish whether a figure could be altered, back-dated or attributed to the wrong party unnoticed.

Is testing safe when crews are on rotation and response is slow?

Yes, because we plan for the constraint rather than around it. Production is never the target: we lead with passive analysis and architecture review on the OT side, run active testing on the IT estate and non-production segments, and agree every permitted technique with your operations and safety teams in writing beforehand. Nothing touching a live process happens outside agreed conditions, and remote-link work is scheduled so a competent crew is on shift throughout.

How quickly can we get a quote for a Khafji engagement?

After a free 30-minute scoping call - which for offshore and joint-venture work includes agreeing safety constraints and which parent approves what - we return a fixed-price quote, usually within one hour and always within one business day. Every engagement includes a free remediation retest once fixes ship.

Ready for a pen test in Khafji?

Book a free 30-minute scoping call. Our Gulf-based team will recommend the right model and quote a fixed-price engagement - usually within the hour.

Schedule scoping call → Contact CyberFortify →