Why OT Pen Testing Is Not IT Pen Testing
In a typical IT penetration test, the tester can run aggressive Nmap scans, exploit vulnerabilities, crash and restart services, and use automated exploitation frameworks freely. The worst outcome of a misconfigured test is a crashed Windows server that reboots in 5 minutes. In an OT environment, the constraints are fundamentally different: a crashed PLC may trip a production process worth tens of thousands of dollars per minute of downtime, trigger a safety system response, or — in extreme cases — cause a physical consequence. A Modbus TCP packet with an unexpected function code can cause some PLCs to enter a fault state that requires on-site engineer intervention to clear. A malformed EtherNet/IP CIP packet has been demonstrated to crash older Rockwell ControlLogix controllers (e.g., CVE-2012-6435). The OT penetration tester must operate with a safety-first, minimum-footprint discipline that IT testers are not accustomed to.