We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Manufacturers

OT and ICS Security Assessment for Manufacturing

In manufacturing the priority order inverts: availability and safety outrank confidentiality, and a scan that is routine on a corporate network can trip a controller. Assessment has to be designed around that, which is why generic IT penetration testing is the wrong instrument.

What IEC 62443 / OT security requires of manufacturers

  • Zone and conduit architecture assessed against IEC 62443, including where the IT/OT boundary actually sits.
  • Asset inventory covering undocumented devices and the engineering laptop that moves between zones.
  • Vendor, integrator and employee remote-access paths into the plant — the route most incidents take.
  • Compensating controls where patching is constrained by vendor validation or production schedules.
  • OT-aware monitoring and incident response, including whether the SOC can interpret an OT alert at all.

Evidence assessors actually ask for

Documentation is rarely the blocker — evidence that controls genuinely operate is. These are the artefacts requested first in this sector.

  • Zone and conduit model of the environment as it is, not as documented
  • Asset inventory reconciled against passive network observation
  • Remote access inventory with authentication and session controls
  • Documented accepted risk where patching is not viable
  • Evidence that OT alerts reach someone who can act on them

Where manufacturers usually come unstuck

  • Running active scans against live control systems — an availability incident here is a safety incident.
  • Segmentation that exists on the drawing but not in the switch configuration, the most frequent finding.
  • Uncontrolled vendor remote access, usually undocumented and always privileged.

Related

OT/ICS assessmentManufacturing sectorIEC 62443 explainedArchitecture review
Scope this engagement →What it costs
PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

Ready to discuss your IEC 62443 / OT security requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →