Control Systems // OT Networks // Connected Devices
Industrial control systems were designed for availability and determinism, in an era when the network was assumed to be trusted. Then they were connected to everything. We assess that exposure without touching the process.
Why It's Different
IT security advice fails on a plant floor for structural reasons, not because operators are careless. A control engineer who refuses to patch mid-run is protecting the process exactly as designed. Security has to work with that constraint rather than argue with it.
In an office, a patch window is an inconvenience. On a line, it's scrap product, a restart sequence measured in hours, and a batch record someone has to explain. Controls that assume you can reboot, force an agent, or pull a system offline for an afternoon are non-starters — which is why the answer in OT is almost always segmentation and monitoring instead.
Modbus, DNP3, EtherNet/IP/CIP, PROFINET and S7comm were built for closed, trusted networks. Many have no authentication at all — a correctly formed command from anywhere with a network path is simply obeyed. There is no exploit to write and no credential to steal. Reachability is the vulnerability, which is why the assessment focuses on who can reach what.
Control hardware routinely runs a decade or more past vendor support, and replacing it is a capital project rather than a security task. That is normal, not negligence. The work is to make the unpatchable system unreachable from anywhere it has no business being reached from, and to know immediately when something tries.
Integrators and OEMs need access to support what they installed, so they get it — and it frequently remains permanent, shared, unlogged, and outliving the contract that justified it. It is the most common path we find from the outside world to a controller, and the one most likely to be undocumented when we ask who holds the credentials.
Engagements
Both engagements are fixed price against a written scope, delivered by the same operator who performed the assessment. Rules of engagement are agreed in writing before anything starts.
An OT security assessment maps what is actually on your control network, how it is reachable from the business network and the outside world, and where the boundary between them fails. Sparrowhawk performs this passively — from traffic captures, configuration exports and interviews — so nothing probes a live controller, and delivers findings mapped to IEC 62443 zones and conduits with a remediation sequence your engineering team can actually execute.
Most OT environments have never been inventoried. The drawing on the wall is five years stale, three devices on the network predate everyone currently employed, and nobody can say with confidence which paths exist from the corporate VLAN to the floor. We answer those questions first, because every other control depends on them.
Connected devices matter because they are rarely inventoried, almost never updated, and usually sit on the same flat network as systems that are critical. Cameras, badge readers, HVAC and building management controllers, networked printers and vendor-installed sensors routinely ship with default credentials and unauthenticated management interfaces, which makes them a dependable first foothold and a quiet pivot point toward everything else.
Nobody writes a security policy for the conference room TV. But it is on your network, it has a vendor cloud connection you did not configure, and it has not had a firmware update since it was installed. Attackers do not care whether a device is important — only whether it is reachable and weak.
How We Work
The fastest way to lose a plant's trust is to scan something that should not have been scanned. Our default posture in OT is to observe, not to touch — and to put every exception in writing first.
Frameworks
Findings are expressed in the vocabulary the party asking already uses — so the report answers the question rather than requiring translation. One honest caveat: we assess and document against these frameworks. We are not a certification body and do not issue certification against any of them.
Why Us
This is not a capability added to a slide deck because industrial work looked like a growth market. The principal consultant spent nine years securing converged IT and OT environments in food manufacturing — where a stopped line spoils product, a cook step cannot be paused for a patch, and the controller running it went out of support years ago.
Common Questions
ICS and OT security is the practice of protecting the industrial control systems that run physical processes — PLCs, HMIs, SCADA servers, drives and safety instrumented systems — along with the networks connecting them. It differs from IT security because availability and safety outrank confidentiality: a control system that stops is a line down or a process out of control, so the standard remedies are segmentation, monitoring and access control rather than patching and agent deployment.
No. We default to passive and read-only techniques in OT, and nothing active happens without your explicit written authorization. Rules of engagement define which systems are in scope, which are excluded outright, what testing windows are permitted, and who to call if anything behaves unexpectedly. On most plant floors we gather what we need from network traffic, configuration exports and interviews, never by scanning a live controller.
No. We do not install agents on PLCs, HMIs, historians or engineering workstations. Asset discovery is done passively from a span or mirror port and from configuration you already hold. If an environment genuinely requires an active technique to answer a question that matters, we will tell you why, what the risk is, and let you decide — in writing, before it happens.
No, and it is the normal situation rather than the exception. Control hardware routinely outlives vendor support by a decade or more, and replacing it is a capital project, not a security task. The work is to make the unpatchable system unreachable from anywhere it does not need to be reached: segmentation, conduit rules between zones, brokered remote access and monitoring on the boundary. We scope compensating controls around the equipment you actually have.
We map findings to IEC 62443 zones and conduits and to NIST SP 800-82 so they line up with whatever framework your customers, insurer or auditor expect to see. To be clear about what that means: Sparrowhawk is not a certification body and does not issue 62443 certification. We assess, document and give you evidence you can hand to the party asking for it.
Usually far more than people expect: IP cameras, badge readers and door controllers, building management and HVAC, networked printers, smart TVs in conference rooms, environmental sensors, and anything a vendor installed with its own cellular or cloud connection. These devices ship with default credentials, rarely get firmware updates, and frequently sit on the same flat network as everything else — which makes them a reliable first foothold.
Get Started
We provide technical security briefings for business owners, operations leaders, and IT teams who want a straight answer about where they stand. No sales pitch.
Request a Security Briefingsparrowhawktech.com/contact · Reply within one business day