← Manufacturers
OT and ICS Security Assessment for Manufacturing
In manufacturing the priority order inverts: availability and safety outrank confidentiality, and a scan that is routine on a corporate network can trip a controller. Assessment has to be designed around that, which is why generic IT penetration testing is the wrong instrument.
What IEC 62443 / OT security requires of manufacturers
- Zone and conduit architecture assessed against IEC 62443, including where the IT/OT boundary actually sits.
- Asset inventory covering undocumented devices and the engineering laptop that moves between zones.
- Vendor, integrator and employee remote-access paths into the plant — the route most incidents take.
- Compensating controls where patching is constrained by vendor validation or production schedules.
- OT-aware monitoring and incident response, including whether the SOC can interpret an OT alert at all.
Evidence assessors actually ask for
Documentation is rarely the blocker — evidence that controls genuinely operate is. These are the artefacts requested first in this sector.
- Zone and conduit model of the environment as it is, not as documented
- Asset inventory reconciled against passive network observation
- Remote access inventory with authentication and session controls
- Documented accepted risk where patching is not viable
- Evidence that OT alerts reach someone who can act on them
Where manufacturers usually come unstuck
- Running active scans against live control systems — an availability incident here is a safety incident.
- Segmentation that exists on the drawing but not in the switch configuration, the most frequent finding.
- Uncontrolled vendor remote access, usually undocumented and always privileged.

QSA Authorised
CEMEA · Asia Pacific · USA
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
