Pittsburg turns fuel into electricity and raw material into steel, and both run on control systems that cannot simply be switched off to be tested. CyberFortify runs manual OT/ICS, network, cloud and web penetration tests here, aligned to NIST CSF, IEC 62443 and NIST SP 800-82, with NERC CIP evidence for bulk-electric-system assets. Delivered remotely from our Gulf base on a daily overlap window, with on-site work where a tester genuinely needs to be on the plant floor. Fixed price, audit-ready reporting, free retest.
// 01 Why Pittsburg businesses need penetration testing
A thermal power plant is critical infrastructure. When a unit drops offline unexpectedly, the loss is not confined to one company - it lands on the grid, on the balancing authority and on everyone downstream of it. That makes the plant's control systems a target class of their own: distributed control systems that run the boiler and balance-of-plant, governor and excitation controls on the turbine and generator, and the protection and interconnection equipment that decides when a breaker opens.
Pittsburg concentrates that risk on the East Bay Delta waterfront - large gas-fired generation, a steel mill and heavy-industry operations, all energy-intensive and safety-critical. These sites were engineered for availability and long asset life, not for an adversary. Historians, engineering workstations and HMIs that once lived on isolated networks now touch business systems for reporting, and vendors reach in remotely to service turbines, drives and control platforms. Each convenience is also a path, and the failure mode here is not a leaked record - it is a manipulated control action, a defeated safety function or a generator forced off the grid.
A vulnerability scanner does not understand any of this. It flags an unpatched server; it cannot tell you that the IT-to-OT firewall permits an engineering protocol it should block, that a relay's engineering-access password is shared across a substation, or that a compromised jump host reaches the turbine-control network in two hops. Those are architecture and authorisation questions, and confirming them safely takes a tester who knows what a trip does before going near it.
// 02 Compliance and regulatory drivers in Pittsburg
A Pittsburg site can sit under a federal reliability regime for the grid, an international standard for its industrial controls, and California's consumer-privacy statute for its corporate data all at once. These are the requirements we most often map evidence against.
NERC CIP - critical-infrastructure protection
Generation and interconnection assets on the bulk electric system carry mandatory CIP obligations - electronic security perimeters, remote-access control, systems security and configuration management. Independent testing is how many operators evidence CIP-005, CIP-007 and CIP-010.
FERC reliability context
FERC approves and enforces the reliability standards NERC writes, so a generation operator's security programme is ultimately part of a federal reliability posture, not just an internal control set.
IEC 62443 - zones & conduits
The zone-and-conduit model and security levels of IEC 62443 give plant and mill control systems a defensible segmentation architecture. We test whether the boundaries described on paper hold under attack.
NIST CSF & NIST SP 800-82
NIST SP 800-82 tailors security to operational technology, and many Pittsburg operators anchor the wider programme to the NIST Cybersecurity Framework. Both rest on periodic, independent technical assessment.
CCPA / CPRA
California's consumer-privacy regime adds rights, risk-assessment expectations and cybersecurity-audit duties across the corporate and customer data an energy or industrial company holds outside the plant.
PCI DSS v4.0 & SOC 2
Billing and customer-payment environments must penetration-test the cardholder scope under Req 11.4, and technology vendors selling into utilities and industrial operators face SOC 2 review before contract.
// 03 Penetration testing services for Pittsburg
Pittsburg engagements weight operational technology over office IT, because the consequential risk lives on the plant floor. OT/ICS testing leads for generation and heavy industry; network and segmentation testing proves the IT-to-OT boundary; cloud and web cover the corporate and remote-access surfaces that increasingly reach into the plant.
OT / ICS pen testing
Plant DCS, turbine and generator controls, PLCs, drives and historians - tested with passive analysis, configuration review and consequence-aware, non-disruptive methods.
Network pen testing
External, internal and Active Directory testing, plus segmentation checks across the IT-to-OT boundary and between plant, substation and corporate zones.
Cloud pen testing
Identity, tenant isolation and service-account scope across the platforms hosting reporting, remote-monitoring and vendor-access services.
Web application pen testing
Customer, operations and remote-monitoring portals tested against the OWASP Top 10 and business-logic abuse.
IoT & device testing
Industrial sensors, gateways and connected instrumentation - firmware, protocol and hardening review across the waterfront estate.
Red teaming
Goal-based adversary simulation modelling an intrusion that pursues the OT network, testing whether it is detected before a control system is reached.
// 04 How we deliver to Pittsburg
We will not pretend otherwise: CyberFortify is a Gulf-based firm on UTC+3, and Pittsburg sits ten to eleven hours behind us. We have no California office and no local staff. What we have is a working pattern built around that gap: our late afternoon and evening is your morning, and we hold that window open daily for stand-ups, live triage and read-outs with your plant and OT engineers. Analysis continues while your control room is quiet, so results are waiting when your shift starts.
What runs remotely
Corporate IT, external, cloud, web and IT-to-OT boundary testing from our secure environment, plus passive OT traffic and configuration analysis on captures and exports you provide. Findings land in a shared channel as confirmed, and anything touching safety or generation is escalated immediately.
What we do on-site
Internal, wireless and segmentation testing on the plant and substation network, and any hands-on OT work where a tester must be on the wire - always inside agreed windows and rules of engagement. We travel when it adds value and say so when it does not.
Every engagement opens with a free 30-minute scoping call and a fixed-price quote within the hour. For live generation and heavy-industry environments we agree test windows around dispatch and production load, and a free retest proves the fixes.
// 05 Industries we secure in Pittsburg
Pittsburg's risk profile is shaped by thermal power generation, a steel and heavy-industry base, and the industrial waterfront that supplies both.
// 06 Our methodology
Pittsburg engagements follow the same audit-defensible process we run everywhere, tuned to control systems that must keep running. Testing is grounded in the PTES and NIST SP 800-115, with OT work aligned to NIST SP 800-82 and IEC 62443, exploitation mapped to MITRE ATT&CK - including the ICS matrix - and application work driven by OWASP. As a CREST Accreditation Pathway firm we lead with manual testing - automation supports the tester, never replaces one, and never runs unattended against live plant.
Scoping & rules of engagement
BES Cyber System scope, OT zones, safety boundaries, forbidden actions, test windows and escalation paths agreed in writing first.
Fixed quote in 1hReconnaissance & threat modelling
Attack surface mapped from IT to the OT boundary to the control network - remote and vendor access, protocols in use, and the paths that reach a turbine, relay or process.
ATT&CK ICS alignedConsequence-aware exploitation
Weaknesses are exploited and chained where it is safe to do so; near live generation and safety functions we prove exposure through passive and read-only means, or on a bench or agreed outage.
Non-disruptiveReporting & free retest
Executive summary, CVSS-scored detail and mapping to NERC CIP, IEC 62443, NIST 800-82 or NIST CSF - plus a free retest once fixes ship.
Audit-ready// 07 Why CyberFortify for Pittsburg
A scan-and-report vendor
Automated output rebadged as a penetration test, aimed at IT and blind to OT - unable to reason about a protection relay, an engineering protocol or what a control action does to a unit carrying grid load.
CyberFortify
A Gulf-based, CREST-pathway team candid about the time difference and structured around it. Consequence-aware exploitation focused on the IT-to-OT boundary, plant DCS, turbine control and protection systems, findings mapped to NERC CIP and IEC 62443, fixed pricing and a free retest.
Pittsburg engagements most often pair an OT/ICS assessment with a network and segmentation test, since a plant's risk splits between the control systems themselves and the boundary that is meant to hold attackers away from them. Where an outage would be a reliability or safety event, we add red teaming to test whether an intrusion reaching for OT is detected in time.
// 08 Frequently asked questions
How do you test a plant DCS and turbine controls without risking live generation?
Consequence-first. We scope every engagement around what must never move: a turbine trip, a load rejection or an unplanned generation loss. Active exploitation is confined to IT, the IT-to-OT boundary and any lab, engineering or standby segment we can isolate, while the live DCS, turbine-governor and generator-control networks are examined through passive traffic analysis, configuration and architecture review, and read-only validation agreed in the rules of engagement. Where a control action would prove a finding, we demonstrate it on a test bench or during an agreed outage, never against a unit carrying grid load.
Can you assess NERC CIP scope and the grid-interconnection and protection systems?
Yes. For a bulk-electric-system asset we work to your NERC CIP scoping: electronic security perimeters, the CIP-005 remote-access path, CIP-007 systems security and CIP-010 configuration baselines, and the identification of BES Cyber Systems and their Electronic Access Points. We test the interconnection and protection layer as its own target - relay engineering-access, the substation and control-house network, and the pathways that could let a change to protection settings or breaker logic reach equipment that trips a unit off the grid. Findings are written to support your CIP evidence and audit posture.
Do you also test steel-mill and heavy-industry process-control systems?
Yes. A working waterfront runs energy-intensive, safety-critical processes on their own controllers, drives, historians and HMIs. We test the segmentation between mill or plant process control and the corporate network, the exposure of PLCs and drive systems, historian integrity and the way engineering workstations and removable media move between zones. The IEC 62443 zone-and-conduit model and NIST SP 800-82 guide the work, and we prioritise anything that could halt an energy-intensive process or defeat a safety function.
With your team in the Gulf, how does the time gap work for a Pittsburg engagement?
We are straight about it: CyberFortify is a Gulf-based firm on UTC+3, roughly ten to eleven hours ahead of Pittsburg, with no California office and no local staff. We run a deliberate daily overlap window - our late afternoon and evening lands on your morning - held open for stand-ups, live triage and read-outs with your plant and OT engineers. Testing and analysis continue while your control room is quiet, so confirmed findings are usually waiting at the start of your shift.
How fast can we get a quote for a Pittsburg engagement?
Book a free 30-minute scoping call and we return a fixed-price quote, usually within the hour and always within one business day. The report is written to hand straight to an auditor or NERC CIP assessor, and a remediation retest is included once your fixes ship.