Rialto runs on infrastructure few people think of as a cyber target - sorting lines, weighbridges, landfill-gas systems and connected fleets - and that is exactly why it is exposed. CyberFortify runs manual network, web, cloud and API penetration tests for the city's waste, recycling and environmental-services operators, aligned to NIST CSF, NIST 800-82 and the CIS Controls, with SOC 2 for the vendors behind them. Delivered remotely from our Gulf base on a daily overlap window, with on-site work where a tester needs to be on the plant floor. Fixed price, audit-ready reporting, free retest.
// 01 Why Rialto businesses need penetration testing
A truck rolls onto a Rialto weighbridge, a number appears, and that number becomes an invoice. Inbound loads move onto a material-recovery line where optical sorters, conveyors and programmable controllers separate what has value from what does not. Landfill-gas and water-reclamation systems run on the same kind of industrial control equipment, and a fleet of collection vehicles reports its position and routes back to a dispatch platform in real time. None of it looks like a bank, and that is the problem.
Waste and recycling grew up as a physical business, so its control systems, scales and telematics were connected for efficiency long before anyone modelled them as an attack surface. The failure modes are concrete. A material-recovery-facility control network reachable from the office LAN lets an intruder reach a PLC. A weighbridge whose readings can be altered between the scale and the billing system quietly changes what customers pay. A fleet-telematics or route platform with weak access control exposes where every vehicle is and where it is going. And environmental-compliance records - the figures submitted to regulators - are only trustworthy if the systems holding them cannot be edited without a trace.
A vulnerability scanner does not find these. It flags an unpatched server; it cannot tell you that a weighbridge indicator trusts any device on its subnet, that the IT and OT networks share a flat VLAN, or that a decommissioned vendor account still has remote access to a plant HMI. Those are exposure and business-logic problems, and confirming them takes a tester who understands both the protocol and the process behind it.
// 02 Compliance and regulatory drivers in Rialto
Waste and environmental operators sit under an unusual mix: industrial-control-system security guidance, measurement and billing integrity, and environmental-reporting duties - plus ordinary consumer-privacy and payment rules. These are the requirements we most often map evidence against.
NIST SP 800-82 & IEC 62443
The control systems behind MRF sorting lines, landfill-gas and water-reclamation plants need OT-specific testing. We work to NIST 800-82 and IEC 62443, prioritising safety and availability over intrusive proof.
NIST CSF & CIS Controls
Most operators anchor their security programme to NIST CSF and evidence the technical controls with the CIS Controls. Independent testing is how the Identify and Protect functions are shown to work.
Weighbridge & billing integrity
Scales decide revenue. We test the weighbridge, ticketing and billing chain for the tamper and desynchronisation flaws that turn a measurement error into a financial one - a control auditors increasingly ask to see tested.
EPA / CalRecycle / water-board reporting
The integrity of environmental-compliance records matters as much as the numbers. We test whether monitoring and reporting data can be altered before it reaches EPA, CalRecycle or regional water-board submissions.
SOC 2 for waste-tech vendors
Route-optimisation, telematics and billing-SaaS vendors selling into operators face security review before contract. SOC 2 reports rest on independent penetration testing evidence.
PCI DSS v4.0 & CCPA/CPRA
Where customer payments touch, Req 11.4 requires the cardholder environment to be penetration-tested and its segmentation proven. CCPA/CPRA governs the resident and account data behind billing and customer portals.
// 03 Penetration testing services for Rialto
Rialto engagements weight the seam between IT and OT, because that is where an office-network intrusion becomes a plant-floor one. Network and segmentation testing leads for facilities; web, cloud and API cover the billing, telematics and reporting platforms that sit above the machinery.
Network pen testing
External, internal and Active Directory testing, with IT-to-OT segmentation checks between office, plant-control and weighbridge networks.
Cloud pen testing
Identity, tenant isolation and storage exposure across the platforms hosting telematics, route optimisation and environmental-reporting data.
API pen testing
Telematics, scale-integration and billing APIs - broken object-level authorisation, scope enforcement and the integrity of weight and route data in transit.
Web application pen testing
Customer billing portals, operator dashboards and compliance-reporting apps, tested against the OWASP Top 10 and business-logic abuse.
Mobile app pen testing
Driver, dispatch and customer apps - local data storage, certificate handling and the fleet-tracking API traffic behind them.
Red teaming
Goal-based adversary simulation, including a ransomware scenario against a plant, testing whether an intrusion is detected before operations halt.
// 04 How we deliver to Rialto
We will not pretend otherwise: CyberFortify is a Gulf-based firm on UTC+3, and Rialto sits ten to eleven hours behind us. We have no California office and no local staff. What we have is a working pattern built around that gap: our late afternoon and evening is your morning, and we hold that window open daily for stand-ups, live triage and read-outs - which suits plants that start early. Testing continues while your site is closed, so results are waiting when the yard opens.
What runs remotely
External, web, cloud, API and mobile testing from our secure environment, plus passive OT discovery and configuration review - the large majority of billing, telematics and reporting scope. Confirmed findings land in a shared channel, and critical issues are escalated immediately.
What we do on-site
Internal network, wireless and IT-to-OT segmentation testing where a tester needs to be on the plant floor or at the weighbridge, plus any active control-system work staged around a maintenance window. We travel when it adds value and say so when it does not.
Every engagement opens with a free 30-minute scoping call and a fixed-price quote within the hour. For plant and control environments we agree test windows around production load and work by consequence, and a free retest proves the fixes.
// 05 Industries we secure in Rialto
Rialto's risk profile is shaped by a dense concentration of waste, recycling and environmental operations, the measurement systems that bill for them, and the fleets and vendors that connect them.
// 06 Our methodology
Rialto engagements follow the same audit-defensible process we run everywhere, tuned to the measurement and control systems at the centre of this market. Testing is grounded in the PTES and NIST SP 800-115, with control-system work referenced to NIST 800-82, exploitation mapped to MITRE ATT&CK - including the ICS matrix - and application work driven by OWASP. As a CREST Accreditation Pathway firm we lead with manual testing; automation supports the tester, never replaces one.
Scoping & rules of engagement
Targets, OT boundaries, weighbridge and billing scope, test accounts, safety limits and escalation paths agreed in writing first.
Fixed quote in 1hReconnaissance & threat modelling
Attack surface mapped from office LAN to plant floor - what reaches a controller, a scale or a telematics feed, and what each could change.
ATT&CK alignedManual exploitation
Weaknesses are exploited and chained under controlled conditions; anything that could affect a running line is proven safely against a replica or a maintenance window.
Safety-first exploitReporting & free retest
Executive summary, CVSS-scored detail and mapping to NIST 800-82, NIST CSF, CIS Controls, SOC 2 or PCI DSS - plus a free retest once fixes ship.
Audit-ready// 07 Why CyberFortify for Rialto
A scan-and-report vendor
Automated output rebadged as a penetration test, blind to a flat IT/OT network, unable to reason about a weighbridge that trusts its subnet or a vendor account still holding remote access to a plant HMI.
CyberFortify
A Gulf-based, CREST-pathway team candid about the time difference and structured around it. Manual exploitation aimed at the seam between office IT and plant OT, at billing-scale integrity and at compliance-data trust - findings mapped to your assessors' frameworks, fixed pricing and a free retest.
Rialto engagements most often pair a network and segmentation test with a cloud penetration test, since a plant's risk splits between the flat network in front of its controllers and the identity configuration behind its telematics and reporting platforms. Where a plant outage is an operational and environmental event, we add red teaming to test detection under a ransomware scenario.
// 08 Frequently asked questions
Can you test MRF and plant control systems without stopping a Rialto sorting line?
Yes. We treat material-recovery and plant OT as safety-critical, so active testing is agreed against your production calendar and we work by consequence, not curiosity. Passive discovery, configuration review and traffic analysis run against live PLCs, HMIs and sorting controls without touching them; anything that could affect a running line is staged for a maintenance window or a replica. The goal is to prove where an attacker could reach a controller and what they could change - not to trip your plant.
How do you test weighbridge and billing-scale integrity?
The weighbridge is where money is decided, so we test it as a financial control, not a sensor. We look at whether the scale indicator, the ticketing software and the billing system can be desynchronised: whether a recorded weight can be altered in transit or at rest, whether tare and override functions are authenticated and logged, and whether the network the scale sits on lets an outsider reach it. We also check that voided or edited transactions leave an audit trail an operator cannot quietly erase.
Which standards and regulations drive penetration testing for Rialto waste and environmental operators?
Plant and facility OT is measured against NIST SP 800-82 and IEC 62443, with the wider programme anchored to NIST CSF and the CIS Controls. Environmental-reporting integrity - the data behind EPA, CalRecycle and regional water-board submissions - is a control in its own right. Waste-tech and SaaS vendors add SOC 2; anywhere customer card payments touch, PCI DSS 4.0 Requirement 11.4 applies; and CCPA/CPRA governs the resident and account data behind billing and customer portals.
With our team in the Gulf, how does the time gap work for a Rialto engagement?
We will be plain about it: CyberFortify is a Gulf-based firm on UTC+3, ten to eleven hours ahead of Rialto, with no California office and no local staff. We run a deliberate daily overlap window - our late afternoon and evening is your morning - kept open for stand-ups, live triage and read-outs, which suits plants that run early shifts. Testing continues while your site is closed, so findings are usually waiting when the yard opens.
How fast can we get a quote for a Rialto engagement?
Book a free 30-minute scoping call and we return a fixed-price quote, usually within the hour and always within one business day. The report is written to hand straight to an auditor or a regulator, and a remediation retest is included once your fixes ship.