Home / ICS & IoT Security

Control Systems  //  OT Networks  //  Connected Devices

Your plant floor was engineered to run.
Not to be attacked.

Industrial control systems were designed for availability and determinism, in an era when the network was assumed to be trusted. Then they were connected to everything. We assess that exposure without touching the process.

Everything that makes OT reliable makes it hard to secure.

IT security advice fails on a plant floor for structural reasons, not because operators are careless. A control engineer who refuses to patch mid-run is protecting the process exactly as designed. Security has to work with that constraint rather than argue with it.

// Availability Outranks Everything

You Cannot Just Reboot It

In an office, a patch window is an inconvenience. On a line, it's scrap product, a restart sequence measured in hours, and a batch record someone has to explain. Controls that assume you can reboot, force an agent, or pull a system offline for an afternoon are non-starters — which is why the answer in OT is almost always segmentation and monitoring instead.

Patch Windows Restart Sequences Batch Integrity
// Protocols That Trust By Default

No Authentication To Bypass

Modbus, DNP3, EtherNet/IP/CIP, PROFINET and S7comm were built for closed, trusted networks. Many have no authentication at all — a correctly formed command from anywhere with a network path is simply obeyed. There is no exploit to write and no credential to steal. Reachability is the vulnerability, which is why the assessment focuses on who can reach what.

Modbus / DNP3 EtherNet/IP PROFINET S7comm
// Hardware Outlives Support

Firmware Older Than The Threat

Control hardware routinely runs a decade or more past vendor support, and replacing it is a capital project rather than a security task. That is normal, not negligence. The work is to make the unpatchable system unreachable from anywhere it has no business being reached from, and to know immediately when something tries.

Unsupported Firmware Legacy Controllers Compensating Controls
// The Door Nobody Closed

Vendor Access, Always On

Integrators and OEMs need access to support what they installed, so they get it — and it frequently remains permanent, shared, unlogged, and outliving the contract that justified it. It is the most common path we find from the outside world to a controller, and the one most likely to be undocumented when we ask who holds the credentials.

Standing Remote Access Shared Credentials Cellular Backdoors Unlogged Sessions

Scoped around the process, never through it.

Both engagements are fixed price against a written scope, delivered by the same operator who performed the assessment. Rules of engagement are agreed in writing before anything starts.

[ 01 ]

ICS & OT Security Assessment

What does an OT security assessment cover?

An OT security assessment maps what is actually on your control network, how it is reachable from the business network and the outside world, and where the boundary between them fails. Sparrowhawk performs this passively — from traffic captures, configuration exports and interviews — so nothing probes a live controller, and delivers findings mapped to IEC 62443 zones and conduits with a remediation sequence your engineering team can actually execute.

Most OT environments have never been inventoried. The drawing on the wall is five years stale, three devices on the network predate everyone currently employed, and nobody can say with confidence which paths exist from the corporate VLAN to the floor. We answer those questions first, because every other control depends on them.

Passive Asset Discovery IT/OT Boundary Review Zone & Conduit Mapping Remote Access Audit
What's Included
  • Passive asset discovery and protocol inventory from a span or mirror port
  • IT/OT boundary and firewall rule-set review
  • Network segmentation assessment against the Purdue model
  • Vendor and third-party remote access pathway audit
  • Engineering workstation and HMI exposure review
  • Backup and recovery validation for controller logic and configurations
What You Walk Away With
  • A current asset inventory you did not have before
  • A reachability map: what can talk to the process, and from where
  • Findings mapped to IEC 62443 zones and conduits
  • Segmentation design that holds without breaking the process
  • Compensating controls scoped to equipment that cannot be patched
  • Executive summary your board and insurer can both read
[ 02 ]

IoT & Connected Device Review

Why do IoT devices matter if they are not critical systems?

Connected devices matter because they are rarely inventoried, almost never updated, and usually sit on the same flat network as systems that are critical. Cameras, badge readers, HVAC and building management controllers, networked printers and vendor-installed sensors routinely ship with default credentials and unauthenticated management interfaces, which makes them a dependable first foothold and a quiet pivot point toward everything else.

Nobody writes a security policy for the conference room TV. But it is on your network, it has a vendor cloud connection you did not configure, and it has not had a firmware update since it was installed. Attackers do not care whether a device is important — only whether it is reachable and weak.

Device Inventory Default Credentials Building Systems Network Isolation
What's Included
  • Discovery and classification of networked devices, including shadow deployments
  • Default and shared credential identification
  • Exposed management interface and unnecessary service review
  • Building management, access control and camera system assessment
  • Vendor cloud and cellular connectivity mapping
  • Firmware currency and vendor support status check
What You Walk Away With
  • A device inventory with owner, purpose and support status
  • A ranked list of devices that should not be where they are
  • Isolation plan: which VLAN each class of device belongs on
  • Procurement criteria so the next device does not repeat it
  • Evidence package for insurance and contract questionnaires

Passive by default. Active only on your signature.

The fastest way to lose a plant's trust is to scan something that should not have been scanned. Our default posture in OT is to observe, not to touch — and to put every exception in writing first.

  • Passive and read-only unless you authorize otherwise — traffic capture, configuration review and interviews before anything else
  • No agents on control systems — nothing is installed on PLCs, HMIs, historians or engineering workstations
  • Rules of engagement in writing — systems in scope, systems explicitly excluded, permitted windows, and who to call if something behaves oddly
  • Scoped around production windows, not through them — we plan to your schedule, including no-touch periods
  • Critical findings escalated by phone the same day — you never wait for a report to learn the process is exposed
  • Your engineers in the room — the people who run the process know things no capture will tell us, and they stay involved

Mapped to what your auditor expects.

Findings are expressed in the vocabulary the party asking already uses — so the report answers the question rather than requiring translation. One honest caveat: we assess and document against these frameworks. We are not a certification body and do not issue certification against any of them.

IEC 62443 NIST SP 800-82 NIST Cybersecurity Framework Purdue Enterprise Reference Architecture CISA ICS Advisories NIST SP 800-171

Nine years inside food manufacturing.

This is not a capability added to a slide deck because industrial work looked like a growth market. The principal consultant spent nine years securing converged IT and OT environments in food manufacturing — where a stopped line spoils product, a cook step cannot be paused for a patch, and the controller running it went out of support years ago.

  • We have been the ones woken up when production stopped, which is a different education than reading about it
  • We speak to engineers as engineers — your controls team will not be talked down to, and their objections are usually correct
  • No managed services, no reselling — we earn nothing on the hardware or software we recommend, so the recommendation is just the recommendation
  • Fixed price against a written scope — the cost is known before work begins and changes only if you change the scope in writing

Read: Industrial Controls Are A Risk To Your Business

Answers before you ask.

What is ICS and OT security?

ICS and OT security is the practice of protecting the industrial control systems that run physical processes — PLCs, HMIs, SCADA servers, drives and safety instrumented systems — along with the networks connecting them. It differs from IT security because availability and safety outrank confidentiality: a control system that stops is a line down or a process out of control, so the standard remedies are segmentation, monitoring and access control rather than patching and agent deployment.

Will an assessment disrupt our production process?

No. We default to passive and read-only techniques in OT, and nothing active happens without your explicit written authorization. Rules of engagement define which systems are in scope, which are excluded outright, what testing windows are permitted, and who to call if anything behaves unexpectedly. On most plant floors we gather what we need from network traffic, configuration exports and interviews, never by scanning a live controller.

Do you need to install software on our control systems?

No. We do not install agents on PLCs, HMIs, historians or engineering workstations. Asset discovery is done passively from a span or mirror port and from configuration you already hold. If an environment genuinely requires an active technique to answer a question that matters, we will tell you why, what the risk is, and let you decide — in writing, before it happens.

We have unsupported PLCs we cannot patch. Is that a dead end?

No, and it is the normal situation rather than the exception. Control hardware routinely outlives vendor support by a decade or more, and replacing it is a capital project, not a security task. The work is to make the unpatchable system unreachable from anywhere it does not need to be reached: segmentation, conduit rules between zones, brokered remote access and monitoring on the boundary. We scope compensating controls around the equipment you actually have.

How does this relate to IEC 62443 and NIST SP 800-82?

We map findings to IEC 62443 zones and conduits and to NIST SP 800-82 so they line up with whatever framework your customers, insurer or auditor expect to see. To be clear about what that means: Sparrowhawk is not a certification body and does not issue 62443 certification. We assess, document and give you evidence you can hand to the party asking for it.

What counts as IoT in a business environment?

Usually far more than people expect: IP cameras, badge readers and door controllers, building management and HVAC, networked printers, smart TVs in conference rooms, environmental sensors, and anything a vendor installed with its own cellular or cloud connection. These devices ship with default credentials, rarely get firmware updates, and frequently sit on the same flat network as everything else — which makes them a reliable first foothold.

If your network is worth protecting,
it's worth an honest assessment.

We provide technical security briefings for business owners, operations leaders, and IT teams who want a straight answer about where they stand. No sales pitch.

Request a Security Briefing

sparrowhawktech.com/contact  ·  Reply within one business day