Introduction
Unfortunately, some of the most useful lessons in life get learnt the hard way, and that is certainly what happened in this OT penetration testing case study.
This case study involves a critical operational technology (OT) facility that was confident its most important systems were cut off from the outside world when, in fact, they were not, and the distance between that belief and reality cost the operator dearly.
We have kept the organisation and identifying details out of this account, but the pattern behind it is one we often encounter, which is why the organisation in question consented to our releasing this article in the hope that others don’t make the same mistake.
The Problem: A Critical OT Facility That Trusted Its Air Gap
The operator in question ran an industrial environment where downtime was simply not an option. Their control systems kept essential operations running, and, like many teams in that position, they were wary of letting anyone test them in case something went wrong.
This reasoning is common in OT penetration testing, and we can completely understand why. OT penetration testing is nothing like any other kind of penetration testing. So, their logic was that if testing might cause disruption, and disruption was unacceptable, then surely the safest option was to leave the environment well alone.
They also believed their most sensitive systems were air gapped, fully cut off from the corporate network and the internet. On paper, that separation was their main line of defence, and that, as far as the team was concerned, an attacker could not physically reach the control environment, so there seemed little point in probing it.
Unfortunately, a path existed between the business side and the supposedly isolated control network, and an attacker found it. Ransomware made its way into the environment that was meant to be untouchable and brought operations to a stop.
The very thing they had been protecting by refusing to test was the thing that ended up going down.
Related Reading: OT Penetration Testing: A Complete Guide to Securing Operational Technology
The Solution: Specialist OT Penetration Testing, Done Carefully
Unsurprisingly, after the incident, the operator’s view changed. Security testing stopped being something to avoid and became something they wanted done properly, which was when Fortifi was brought in.
As we’ve already mentioned, testing a live OT environment is a world away from testing an office network, and charging in with automated tools is a one-way trip to more problems.
So, Kieran, Fortifi’s founder and head of penetration testing, personally ran the engagement with the care these environments demand. The work was done on-site and methodically, with the operator’s own engineers involved, and nothing was run against a sensitive device without prior agreement.
By reviewing the architecture and the firewall rules intended to enforce the air gap, Fortifi could map where the control network was actually connected to everything else. This is the fastest way to expose the difference between the separation an operator believes they have and the separation that actually exists, and it puts no live equipment at risk in the process.
Related Reading: ICS & SCADA Penetration Testing: How to Test Live OT Systems Safely
The Result: A True Picture of the Risk
The testing gave the operator something they had never had before, which was an honest map of their exposure. The routes that had allowed ransomware in were identified, along with the weaknesses that had accumulated after years of leaving the environment untouched.
None of it came as a shock once it was set out plainly, and all of it could be prioritised and put right.
Just as important, the operator shifted away from hoping nothing would happen and towards managing their OT security risks on purpose. Testing became part of how they ran and changed their systems, rather than a step they were too nervous to take.
The uncomfortable truth is that every one of those findings could have surfaced before the attack rather than after. A single OT penetration test, carefully carried out by a provider like Fortifi, would have shown that the air gap had holes long before anyone with malicious intent went looking.
What Other OT Operators Can Learn
Assumed isolation is one of the most common and most dangerous beliefs in OT cybersecurity. If left alone, it’s normal for air gaps to degrade over time as the business around them evolves.
Whether a remote connection gets added for a maintenance contract, or a new system bridges two networks for the sake of convenience, and the gap closes up without anyone updating the mental picture of how things are wired.
The nervousness around OT penetration testing is understandable, but leaving an OT environment unexamined does not make it secure. It only means that if something does get in, you find out the hard way, and at the worst possible moment.
So, if you are relying on security you have never had verified, that is the assumption worth testing first. Fortifi’s OT penetration testing service is built to assess these environments safely, with the experience to know precisely how far is too far.
Talk to Fortifi about testing your OT environment.