Richmond runs on process plants where the worst cyber outcome is measured in safety and environmental consequence, not lost hours. CyberFortify runs manual, consequence-driven network, cloud, web and OT penetration tests here, focused on the DCS, PLCs and safety-instrumented systems and the boundary that protects them - aligned to IEC 62443, IEC 61511, OSHA PSM and NIST CSF. Nothing intrusive touches a live safety system without an agreed window. Delivered remotely from our Gulf base on a daily overlap, with on-site work where it genuinely helps. Fixed price, audit-ready reporting, free retest.
// 01 Why Richmond businesses need penetration testing
A refinery or chemical plant is a physical process held inside a safe envelope by layers of control. A distributed control system holds temperatures, pressures and flows where they belong; programmable logic controllers drive pumps, valves and compressors; and above it all sits a safety-instrumented system whose only job is to bring the process to a safe state when something goes wrong. That SIS is the last line of defence against a release, a fire or an explosion, and its value depends entirely on being independent and trustworthy.
Penetration testing in Richmond starts from the consequence model, because the stakes are not abstract. Manipulate a control setpoint and you can push a unit outside its safe operating window; defeat or blind a safety function and you remove the barrier that would otherwise stop an event reaching workers and the surrounding community. The distinctive concern is not uptime - it is the integrity and independence of the systems that keep a hazardous process from harming people and the environment.
The way in is rarely the plant floor directly. It is the IT-to-OT pivot: a phishing foothold on the corporate network, a flat path through a data historian or an unpatched jump host, a vendor remote-access tool left always-on, and then a route toward the control layer that segmentation should have blocked. A scanner will flag a missing patch on an engineering station; it cannot tell you that the same station can reach the safety PLC, or that the SIS shares a switch with basic process control. Those are architecture and trust questions, and answering them takes a tester who understands both the attack and the process behind it.
// 02 Compliance and regulatory drivers in Richmond
Richmond process operators answer to an industrial-security standards spine, a safety-consequence regime that treats a cyber path into safety functions as a process hazard, and a consumer-privacy statute over the corporate data alongside the plant. These are the requirements we most often map evidence against.
IEC 62443 - zones & conduits
The reference standard for industrial automation and control security. It frames the plant as zones with defined conduits between them, and independent testing evidences the segmentation and security levels it expects across the IT-to-OT boundary.
IEC 61511 (SIS)
The functional-safety standard for safety-instrumented systems in the process industries. Testing here centres on the independence and integrity of the SIS - that its ability to reach a safe state cannot be defeated from the control or corporate network.
OSHA PSM & EPA RMP / CalARP
Process Safety Management and the Risk Management Program - California's CalARP - govern facilities handling highly hazardous chemicals. A cyber route into a safety or control function is a process-safety hazard, and testing feeds the hazard analysis.
NIST 800-82 & NIST CSF
NIST SP 800-82 guides securing industrial control systems, and many operators anchor the programme to NIST CSF. Both rest on periodic independent assessment of the control environment.
CCPA / CPRA
California's consumer-privacy regime adds rights, risk-assessment and cybersecurity-audit duties over the corporate, contractor and personnel data an operator holds. Our privacy-regulation guidance sets out how it applies.
ISO 27001 & supply chain
EPC contractors, integrators and equipment vendors selling into Richmond plants face security review before contract. ISO 27001 A.8.29 evidence and supplier assurance rest on independent testing of the systems and remote access they provide.
// 03 Penetration testing services for Richmond
Richmond engagements weight the control environment and the boundary around it, because that is where a compromise turns into consequence. OT and network testing lead for plant operators; cloud and web cover the corporate systems and remote-access paths that reach into the process; the consequence model decides what stays passive.
Network & OT pen testing
IT-to-OT pivot testing, DCS and PLC exposure, historian and jump-host review, and segmentation checks between safety, control and corporate zones - passive on live process networks.
Cloud pen testing
Identity, tenant isolation and service-account scope across the platforms hosting remote-monitoring, analytics and vendor gateways that reach toward the plant.
Web application pen testing
Operator dashboards, contractor portals and remote-access front ends, tested against the OWASP Top 10 and business-logic abuse.
API pen testing
Telemetry, historian and integration APIs between corporate analytics and the control layer - authorisation, scope enforcement and data-exposure testing.
Mobile app pen testing
Field and operator apps - local data storage, certificate handling and the API traffic that links a phone to plant systems.
Red teaming
Goal-based adversary simulation from corporate foothold toward the OT boundary, testing whether an intrusion is detected before it reaches systems that matter.
// 04 How we deliver to Richmond
We will not pretend otherwise: CyberFortify is a Gulf-based firm on UTC+3, and Richmond sits ten to eleven hours behind us. We have no California office and no local staff. What we have is a pattern built around that gap and around the safety of your process: our late afternoon and evening is your morning, and we hold that window open daily for stand-ups, live triage and read-outs with your controls, safety and IT teams. Passive analysis and reporting continue while Richmond is offline, so results are waiting when your day starts.
What runs remotely
Corporate-network and cloud testing, web and API assessment, remote-access review, and passive OT analysis - traffic capture, configuration and firmware review, and architecture analysis - from our secure environment. Confirmed findings land in a shared channel and critical issues are escalated immediately.
What we do on-site
Internal, wireless and segmentation testing where a tester needs to be on the wire, plus turnaround-window work on control and safety systems with your process-safety team present. We travel when it adds value and say so when it does not.
Every engagement opens with a free 30-minute scoping call and a fixed-price quote within the hour. For control and safety environments we agree the consequence model and test windows before anything intrusive runs, and a free retest proves the fixes.
// 05 Industries we secure in Richmond
Richmond's risk profile is shaped by a concentration of refining and heavy process industry, a working port, and the contractors and utilities that serve them.
// 06 Our methodology
Richmond engagements follow the same audit-defensible process we run everywhere, tuned to the consequence model at the centre of a process plant. Testing is grounded in the PTES and NIST SP 800-115, extended with NIST 800-82 for the control environment, with exploitation mapped to MITRE ATT&CK - including the ATT&CK for ICS tactics - and application work driven by OWASP. As a CREST Accreditation Pathway firm we lead with manual testing, and on live process networks the guiding rule is do no harm: we decide what to touch by what could happen if it goes wrong.
Scoping & consequence model
Zones in scope, the safety and control assets, what stays passive, test windows and escalation paths agreed in writing with your process-safety team first.
Fixed quote in 1hReconnaissance & threat modelling
Attack surface mapped around the IT-to-OT boundary - who can reach the control and safety layers, from where, and through which conduit.
ATT&CK for ICSControlled exploitation
The corporate-to-OT pivot and segmentation are tested and chained under controlled conditions; anything intrusive on safety or control systems runs only in an agreed window, never on a live safety function.
Safety-firstReporting & free retest
Executive summary, CVSS-scored detail and mapping to IEC 62443, IEC 61511, PSM/CalARP, NIST 800-82 or NIST CSF - plus a free retest once fixes ship.
Audit-ready// 07 Why CyberFortify for Richmond
A scan-and-report vendor
An IT scanner pointed at an OT network, blind to the consequence model, unable to reason about SIS independence or a segmentation conduit - and reckless enough to probe a live safety system.
CyberFortify
A Gulf-based, CREST-pathway team candid about the time difference and disciplined about your process. Manual, consequence-driven testing of the IT-to-OT boundary and the integrity of your safety systems, findings mapped to IEC 62443, IEC 61511 and PSM, fixed pricing and a free retest.
Richmond engagements most often pair a network and OT assessment with a cloud penetration test, since the route toward the control layer usually runs through a remote-access or analytics platform. Where an intrusion reaching OT would be a safety event, we add red teaming to test whether detection fires before the boundary is crossed.
// 08 Frequently asked questions
Will you actively test a live DCS or safety-instrumented system at a Richmond plant?
No - not while it is running a process, and never without extreme care and an agreed window. Active testing of a live safety-instrumented system or a distributed control system can trip a shutdown or, worse, mask a real demand, so on production networks we work passively: traffic capture, configuration and firmware review, and architecture analysis. Intrusive testing is reserved for turnaround windows, engineering spares, offline cells or a test bench that mirrors the target. The methodology is consequence-driven - we decide what to touch by what could happen if it goes wrong.
How do you test the IT-to-OT boundary and the segmentation around the SIS?
We treat the corporate-to-control path as the primary attack route and test it as an attacker would pivot it: from a foothold on the business network, through the DMZ and any data historian, jump host or vendor gateway, toward the control layer. We verify that the safety-instrumented system is genuinely independent of the basic process control system rather than sharing switches, engineering workstations or credentials, and we test the conduits between safety, control and corporate zones for the segmentation IEC 62443 calls for. Flat networks, dual-homed historians and shared engineering laptops are the findings we see most.
Which standards and regulations drive OT penetration testing for Richmond process plants?
The spine is IEC 62443 for industrial automation and control security and IEC 61511 for the safety-instrumented systems that are the last line of defence against a release, fire or explosion. On the safety-consequence side, OSHA Process Safety Management and the EPA Risk Management Program - implemented in California as CalARP - govern how covered facilities manage catastrophic hazards, and a cyber path into safety functions is squarely in scope. We also map to NIST 800-82 for ICS, NIST CSF for the overall programme, and CCPA/CPRA for the corporate and personnel data alongside the plant.
With your team in the Gulf, how does the time gap work for a Richmond plant engagement?
Plainly: CyberFortify is a Gulf-based firm on UTC+3, ten to eleven hours ahead of Richmond, with no California office or local staff. We hold a deliberate daily overlap window - our late afternoon and evening is your morning - for stand-ups, live triage and read-outs with your controls, safety and IT teams. Passive analysis and reporting continue while your site is offline, so findings are usually waiting when your day begins, and any intrusive step happens only inside a window your process-safety team has agreed.
How fast can we get a quote for a Richmond OT engagement?
Book a free 30-minute scoping call and we return a fixed-price quote, usually within the hour and always within one business day. Scoping an OT engagement is deliberately careful - we agree the consequence model, the zones in scope and what stays passive before any testing starts. The report is written to hand straight to an auditor or your PSM file, and a remediation retest is included once your fixes ship.