A highly automated distribution centre is a factory floor, and Tracy has some of the region's largest. CyberFortify runs manual, OT-safe OT/ICS, network, cloud and API penetration tests here, aimed at warehouse control and execution systems and the IT-to-OT segmentation around them, aligned to NIST 800-82, IEC 62443, NIST CSF and SOC 2. Delivered remotely from our Gulf base on a daily overlap window, with on-site work where a tester genuinely needs to be on the floor. Fixed price, audit-ready reporting, free retest.
// 01 Why Tracy businesses need penetration testing
Tracy sits at the edge of the Bay Area, where affordable land and interstate access have pulled in some of the region's largest and most automated fulfillment operations. Walk one of these centres and you are on a factory floor: conveyors and sorters routing cartons at speed, automated storage-and-retrieval systems pulling stock, and mobile robots moving between pick faces - all orchestrated by warehouse control and execution systems that never really pause.
That automation is what makes the security question physical. A warehouse-control system (WCS) drives the conveyors and sorters; a warehouse-execution system (WES) sequences the work above it; PLCs and controllers actuate the machinery underneath. When those systems bridge to corporate IT and to the cloud - for order feeds, labour data and analytics - the floor inherits the internet's threat model. The failure mode is not a leaked spreadsheet. It is a sorter that stops, a robot that behaves unexpectedly, or a shift that cannot ship, because a control decision was trusted when it should have been checked.
A vulnerability scanner does not find that class of problem. It flags an unpatched service; it cannot tell you that a commodity infection on a picking-station laptop routes straight onto the control VLAN, that an integrator's remote-access tool still holds standing credentials to the sortation PLCs, or that the historian bridging IT and OT trusts writes it should reject. Those are segmentation and authorisation questions, and answering them safely - around equipment that is moving product - takes a tester who understands both the protocol and the plant.
// 02 Compliance and regulatory drivers in Tracy
An automated distribution centre answers to operational-technology security guidance, the assurance frameworks its customers demand, and California privacy law over the data it holds. These are the requirements we most often map evidence against.
NIST SP 800-82 - OT security
The reference guidance for securing operational technology. We map WCS/WES, PLC and controller findings to its controls so the automation floor is assessed as OT, not treated like an office network.
IEC 62443
The industrial standard for segmenting a plant into zones and conduits. We validate that the warehouse floor is partitioned from corporate IT the way the model requires, and show where a conduit is missing or over-trusting.
NIST CSF & CIS Controls
Most Tracy operators anchor the wider programme to NIST CSF and the CIS Controls. Independent testing evidences the identify, protect and detect functions across the IT and OT estate together.
SOC 2 for automation vendors
Logistics-automation and software vendors selling WCS/WES, robotics or analytics into these centres face SOC 2 review before contract. Independent penetration testing is the evidence that report rests on.
PCI DSS v4.0 - where cards touch
Where payment or returns processing touches the environment, Requirement 11.4 calls for penetration testing of the cardholder environment and proof of segmentation from it under Req 11.4.5.
CCPA / CPRA
California's consumer-privacy regime adds rights, risk-assessment expectations and cybersecurity-audit duties over the customer, workforce and order data these operations hold alongside the machinery.
// 03 Penetration testing services for Tracy
Tracy engagements weight the automation floor and the boundary above it, because that is where a cyber event becomes an operations event. OT/ICS testing leads for the control systems; network testing proves the IT-to-OT segmentation; cloud and API cover the order feeds and analytics riding on top.
OT / ICS pen testing
WCS/WES, PLC and controller exposure, conveyor and sortation logic, robotics and AS/RS - tested with safe, non-disruptive methods around live material-handling equipment.
Network pen testing
External, internal and Active Directory testing, plus IT-to-OT segmentation and conduit validation between corporate, floor-control and safety environments.
Cloud pen testing
Identity, tenant isolation and service-account scope across the platforms carrying order feeds, labour data and warehouse analytics into and out of the floor.
API pen testing
Order, inventory and control-integration APIs between the WES, the ERP and the cloud - broken object-level authorisation, scope enforcement and token handling.
IoT & device testing
Handheld scanners, print-and-apply, sensors and mobile-robot endpoints - firmware, transport security and the traffic each device sends back to the control plane.
Red teaming
Goal-based adversary simulation, including a ransomware scenario that starts on IT and tries to halt the floor - testing whether the intrusion is detected before fulfillment stops.
// 04 How we deliver to Tracy
We will not pretend otherwise: CyberFortify is a Gulf-based firm on UTC+3, and Tracy sits ten to eleven hours behind us, with no California office and no local staff. What we have is a pattern built around that gap: our late afternoon and evening is your morning, and we hold that window open daily for stand-ups, live triage and read-outs. The same rhythm lets us line up any active OT probing with your quiet shifts, so testing rarely competes with a running floor.
What runs remotely
Passive OT traffic analysis, external and cloud testing, API and IoT work, and IT-side segmentation validation from our secure environment. Findings land in a shared channel as confirmed, and anything that could touch operations is escalated immediately.
What we do on-site
Internal floor-network, wireless and segmentation testing where a tester needs to be on the wire, and any active controller work run against a staging tier or a maintenance window in person. We travel when it adds value and say so when it does not.
Every engagement opens with a free 30-minute scoping call and a fixed-price quote within the hour. For live automation we agree test windows and explicit abort conditions around peak fulfillment, and a free retest proves the fixes.
// 05 Industries we secure in Tracy
Tracy's risk profile is shaped by dense, highly automated logistics: fulfillment at scale, the vendors who build the automation, and the cold-chain and manufacturing operations alongside them.
// 06 Our methodology
Tracy engagements follow the same audit-defensible process we run everywhere, tuned for live automation where safety comes first. Testing is grounded in the PTES and NIST SP 800-115, with OT work referenced to NIST 800-82 and IEC 62443, exploitation mapped to MITRE ATT&CK - including ATT&CK for ICS - and application work driven by OWASP. As a CREST Accreditation Pathway firm we lead with manual testing, and around material-handling equipment automation supports the tester, never drives traffic at a live controller.
Scoping & rules of engagement
Targets, control-network boundaries, zone and conduit map, test windows and explicit abort conditions agreed in writing first.
Fixed quote in 1hRecon & OT threat modelling
Attack surface mapped from passive capture and read-only enumeration - what bridges IT and OT, who can reach the controllers, and where segmentation is meant to hold.
ATT&CK for ICSSafe, controlled exploitation
IT-side and boundary weaknesses exploited and chained under controlled conditions; any active controller work confined to staging or a maintenance window - never live production traffic.
Non-disruptiveReporting & free retest
Executive summary, CVSS-scored detail and mapping to NIST 800-82, IEC 62443, NIST CSF or SOC 2 - plus a free retest once fixes ship.
Audit-ready// 07 Why CyberFortify for Tracy
A scan-and-report vendor
Automated output rebadged as a penetration test, run at IT assumptions, blind to the control plane - and quite capable of knocking a live conveyor or sorter offline because nobody scoped the OT risk.
CyberFortify
A Gulf-based, CREST-pathway team candid about the time difference and structured around it. Manual, OT-safe testing aimed at the WCS/WES, the controllers and the IT-to-OT segmentation between them, findings mapped to NIST 800-82 and IEC 62443, fixed pricing and a free retest.
Tracy engagements most often pair an OT/ICS assessment with an internal network and segmentation test, since a distribution centre's risk splits between the control systems and the boundary meant to keep commodity IT threats off the floor. Where a stopped floor is business-critical, we add red teaming to test detection under a ransomware scenario.
// 08 Frequently asked questions
Can you test WCS/WES and automation controllers without stopping a live distribution centre?
Yes - non-disruptive testing around live material-handling equipment is the core of the method here. We agree the rules of engagement in writing, work from passive traffic capture and read-only enumeration on the control network, and reserve any active probing of PLCs, conveyor and sortation controllers or robotics for maintenance windows or a lab and staging tier that mirrors production. We never send unvalidated traffic at a controller that is moving product, and every step has an agreed abort condition.
How do you test whether a commodity IT infection could reach the warehouse floor?
We test the IT-to-OT boundary as its own target rather than assuming the firewall between them holds. We map the actual paths from corporate IT into the automation network - flat VLANs, dual-homed engineering laptops, shared jump hosts, historian and data-store links - and prove, from a foothold on the IT side, whether a routine ransomware or worming infection could pivot onto the WCS/WES or the controllers below it. We validate the zones and conduits against an IEC 62443 model and show exactly which segmentation control fails and why.
Do you cover robotics, conveyor and sortation safety systems?
Yes. In an automated centre a cyber problem is a physical-operations and safety problem, so we examine the integrity of the systems that keep people and product safe: whether robotics and AS/RS controllers, conveyor and sortation logic, and their safety interlocks can be reached, reconfigured or commanded from the network, and whether safety-instrumented functions are isolated from the routable control plane. We test exposure and access paths without exercising the safety functions themselves, and report what an attacker could influence and what protects it.
With your team in the Gulf, how does the time gap work for a Tracy engagement?
Straight answer: CyberFortify is a Gulf-based firm on UTC+3, roughly ten to eleven hours ahead of Tracy, with no California office and no local staff. We hold a deliberate daily overlap window open - our late afternoon and evening is your morning - for stand-ups, live triage and read-outs, which also lets us line up any active OT work with your quiet shifts. Testing and analysis continue while your floor runs, so confirmed findings are usually waiting when your day begins.
How fast can we get a quote for a Tracy engagement?
Book a free 30-minute scoping call and we return a fixed-price quote, usually within the hour and always within one business day. The report is written to hand straight to an auditor or a customer's security team, mapped to NIST 800-82, IEC 62443, NIST CSF or SOC 2, and a remediation retest is included once your fixes ship.