How to Scope IT-OT Penetration Testing Safely

Contributors

Shantanoo Govilkar
Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions
Image
Scope-IT-OT-Penetration-Testing

Scoping a penetration test in an IT environment is a problem of boundary definition. Scoping one in an operational technology (OT) environment is a problem of consequence management. The question is not just what to test, but what happens if something goes wrong during testing. 

On a factory floor, the answer to that question can involve production shutdowns, safety incidents and equipment damage. Getting scope right is not a formality. It is the difference between a useful engagement and a crisis. The stakes are not theoretical: in Fortinet’s 2025 State of Operational Technology and Cybersecurity Report, 50% of organizations surveyed reported one or more cybersecurity incidents in the past year.

The Core Tension You Have to Resolve First

OT environments run on availability. A historian server, a distributed control system (DCS) controller or a human-machine interface (HMI) going offline for ten minutes during testing can stop a production line, trigger alarms across a plant or, in the worst case, affect safety instrumented systems. Security testing that causes that outcome is not a success, regardless of what it finds. The risk is documented, not hypothetical. NIST records a natural gas utility whose pen testers, hired to test the corporate IT network, strayed into a segment connected to the supervisory control and data acquisition (SCADA) system. The test locked up SCADA and stopped gas delivery to customers for four hours. NIST also records a ping sweep that hung a control system in a chip plant and destroyed $50,000 worth of wafers.

At the same time, testing that excludes everything sensitive produces a false picture of your security posture. The systems that are hardest to test are often the ones most likely to be targeted. Resolving this tension requires a scoping methodology that is honest about what can be tested safely and what requires a different approach.

IT-OT-Pen-Test-Scoping-Decision-Flow

Building the Scope From Your Asset Inventory

You cannot scope what you cannot see. The starting point for any IT-OT pen test scope is a current, accurate asset inventory. That means every device on the OT network, not just what appears in a configuration management database (CMDB) or network diagram that was last updated two years ago. Passive discovery techniques, such as traffic mirroring and protocol analysis, can build that inventory without sending a single packet to a live device. The visibility gap is the norm, not the exception: Dragos found that 80% of its 2022 service engagements had a lack of visibility across OT networks. 

Once you have the inventory, categorize assets by criticality and testability. Safety instrumented systems are excluded without exception. Any system with a direct connection to physical process control requires a specific justification for active testing, documented approval from operations leadership and a rollback plan. Engineering workstations and historian servers that sit at the IT-OT boundary are typically testable with appropriate controls in place.

OT-Asset-Risk-Classification-Guide

Passive First, Active Only Where It Is Safe

The safest and most informative starting point in any OT environment is passive reconnaissance. Monitoring network traffic at a span port or tap reveals what is communicating, what protocols are in use, what credentials are passing in cleartext and what the real network topology looks like versus the documented one. This produces actionable findings with no risk to production systems.

Active testing should follow only where it has been explicitly approved, the blast radius of a failure is contained, and the operations team has been briefed. That means testing in maintenance windows where possible, with operations staff available to respond, and with a clear abort condition defined in advance. The rules of engagement for an OT pen test are not a legal formality. They are an operational safety document.

What the Scope Document Must Include

A well-constructed IT-OT pen test scope document covers more ground than its IT equivalent. Beyond the standard system list and IP ranges, it needs to define the testing methodology per zone, the conditions under which active testing is permitted, the change control requirements before the engagement starts and the communication chain if something unexpected occurs during testing. This zone-based structure follows IEC 62443 from the International Electrotechnical Commission, and Special Publication 800-82 from the National Institute of Standards and Technology (NIST) gives matching guidance for testing operational technology.

Both the security team and operations leadership should review and sign off on the scope document. Security teams sometimes scope engagements without fully consulting the people who run the plant. That leads to surprises during the engagement that damage trust between security and operations and make future testing harder to approve. 

Validating Your Scope Before the Engagement Starts

Even experienced teams miss things in OT scope reviews. Vendor remote access paths that are not in the asset register. Wireless access points installed for temporary maintenance that were never removed. Cloud connections from process historians that were set up by the OT vendor and are not documented anywhere in the security team's records.

A structured scope review process that specifically looks for these categories of missing scope reduces the risk of an engagement that either causes an incident or produces an incomplete picture. The goal is to go into the engagement knowing what you are testing, what you are deliberately excluding and why. Expect the review to find something: in the same Dragos engagement data, 53% of engagements included a finding of external connections into the OT network from equipment makers, IT networks or the internet.

Scope is where an OT engagement succeeds or fails. Book a scoping workshop and walk into your next test with the asset inventory, zone map and test boundaries settled before anyone sends a packet.

Get the latest insights straight from our desk to your inbox.

Other Featured Articles

Explore More
FDA-510K-and-PMA-Cybersecurity-Testing

A Medical Device Maker's Guide to FDA Cybersecurity Testing for 510(k) & PMA

The FDA doesn't publish a pen testing checklist but its guidance, 524B requirements, and reviewer expectations add up to one.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
Pharma-Pen-Testing-FDA-Complianc

Pharma Pen Testing: Why FDA and IP Risk Need Different Scoping

Standard pen test scoping frameworks weren't built for pharma.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
FDA-524B-Medical-Device-Cybersecurity-Testing

FDA 524B Is Here: What Medical Device Makers Must Test Now

Section 524B made medical device cybersecurity a legal requirement, not a guideline.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
CMMC-2-0-Pen-Testing-Requirements

Why CHIPS Act Manufacturers Can't Rely on CMMC Pen Testing Alone

Semiconductor manufacturers face dual compliance obligations under CMMC 2.0 and the CHIPS Act and a standard pen test satisfies neither fully.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
C3PAO-Audit-Evidence-Mapping

Why Pen Test Evidence Fails C3PAO Assessments (and How to Fix It)

Completing a pen test isn't enough for CMMC.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
PTaaS-vs-Annual-Pen-Testing

PTaaS vs. Annual Pen Testing: Why Manufacturers Are Switching

Annual penetration testing produces documentation, not security.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
Map-OT-Attack-Surface

Map Your OT Attack Surface Before the Next Audit

Don't wait for an auditor to tell you what you missed.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
Scope-IT-OT-Penetration-Testing

How to Scope IT-OT Penetration Testing Safely

Learn how to safely scope IT-OT penetration testing engagements.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
Manufacturing-Penetration-Testing-Frequency

How Often Should Manufacturers Run OT Penetration Testing?

Annual pen testing fits a budget cycle but it doesn't reflect how fast manufacturing environments actually change.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
21-CFR-Part-11-and-cGMP-Requirements

Pharmaceutical Pen Testing: What 21 CFR Part 11 and cGMP Require

21 CFR Part 11 and cGMP don't mention penetration testing but the controls they require depend on it.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
RD-and-Regulated-Systems-Penetration-Testing-Scopes

Pharmaceutical Pen Testing: Why R&D and GxP Need Different Scopes

R&D and GxP regulated environments have different risk profiles, compliance requirements, and testing constraints.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
Nation-State-Cyber-Threats-in-Pharma

Why Pharmaceutical Pen Testing Must Address Nation-State Threats

Nation-state actors treat pharma like critical infrastructure targeting formulation data, synthesis routes, and clinical IP with patience and precision.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
IT-OT-Boundary-Ransomware-Risk

How Ransomware Crosses the IT-OT Boundary (And How to Stop It)

Ransomware operators target the IT-OT boundary deliberately and they know manufacturing economics well.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
Where-Industry-4-0-Exposed-OT

Where Industry 4.0 Left Your OT Attack Surface Wide Open

Industry 4.0 connected OT environments were never built for. Learn why traditional IT security tools fall short and what OT penetration testing reveals that audits miss.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
What-AS4-Actually-Solves-Banner-Image

What AS4 Actually Solves: Real Outcomes Companies See After Migration

Discover what AS4 actually solves for modern businesses. Learn the real outcomes companies achieve after migration, from stronger security to better B2B integration performance.

 

EDI Solutions Group
Marketing Group view
AS4-migration-pitfalls-Banner-image

7 Migration Pitfalls That Derail AS4 Upgrades (and How to Avoid Them)

Avoid costly AS4 upgrade mistakes. Discover 7 migration pitfalls that delay projects, create risk, and disrupt B2B messaging, plus practical ways to avoid them.

EDI Solutions Group
Marketing Group view
pen-testing-in-cloud-enviroment-banner-image

How to Perform Penetration Testing in Cloud Environments (AWS, Azure, and GCP) - 2026 Edition

A practical guide to cloud penetration testing across AWS, Azure, and GCP. Learn methods, tools, and best practices to identify vulnerabilities and improve security.

Cybersecurity Solutions Group
Marketing Group view
when-to-switch-legacy-edi-to-as4

5 Signs It's Time to Move Legacy EDI Environment to AS4 Protocol

Partner onboarding delays, compliance gaps, and rising maintenance costs are signals your EDI infrastructure is reaching its limits. Learn the five signs it is time to evaluate a move to AS4.

EDI Solutions Group
Marketing Group view
How-to-Design-Custom-Chatbots-Banner-Image

How to Design Custom Chatbots That Cannot “Make Stuff Up”

Confident AI answers without traceable sources create institutional risk. Learn how Grounded RAG architecture retrieves real documents first and attaches verifiable citations to every response.

Data and AI Solutions Group
Marketing Group view
Conversational-AI-blog-banner

How Citation-Backed Conversational AI Improves Public Access and Internal Decision-Making

AI without source citations creates real liability. Learn how citation-backed AI brings traceable sources, version awareness, and audit-ready outputs to every institutional decision.

Data and AI Solutions Group
Marketing Group view
Network-penetration-testion-blog-banner

How to Perform a Successful Network Penetration Test: Comprehensive Guide for 2025

Learn how to perform a successful network penetration test to identify vulnerabilities, simulate real cyberattacks, and strengthen your organization’s network security.

Cybersecurity Solutions Group
Marketing Group view
Penetration-testing-banner-image

What Is Penetration Testing? A 2026 Expert Guide

A 2026 expert guide to penetration testing for security leaders and IT teams seeking proactive defense, compliance, and stakeholder trust.

Cybersecurity Solutions Group
Marketing Group view
ot-ransomware-prevention-banner-image

OT Ransomware Prevention: Practical Best Practices for Industrial Cybersecurity

Explore enterprise grade OT ransomware prevention strategies, including segmentation, identity control, threat informed detection, and resilient recovery design to protect industrial operations fro

Cybersecurity Solutions Group
Marketing Group view
OT-Ransomware-Risks-and-Response-Banner

10 Myths About OT/ICS Security That Put Your Business at Risk

Think your OT network is secure? Learn the 10 most dangerous myths about OT and ICS cybersecurity that leave industrial operations exposed to attacks.

Cybersecurity Solutions Group
Marketing Group view
OT-ransomeware-risk-and-responses-banner-image

OT Ransomware Risks and Response for Industrial Systems

Learn why OT environments face higher ransomware risk, how attackers gain access, and how effective detection and response reduce operational impact.

Cybersecurity Solutions Group
Marketing Group view
AI-Risk-Assessment-Best-Practices-Banner

AI Risk Assessment: Risk Types, Best Practices & More

Explore AI risk types, essential assessment frameworks, and proven best practices to mitigate threats in AI deployment. Learn actionable strategies for secure AI systems today.

Cybersecurity Solutions Group
Marketing Group view
AI Risk Assessment Banner Image

AI Risk Assessment: Everything You Need to Know

Learn essential processes, methodologies, risk types, regulatory requirements, and practical implementation strategies for safe AI deployment.

Cybersecurity Solutions Group
Marketing Group view
Whitepaper: Ransomware Threat Management

Whitepaper: Ransomware Threat Management

Ransomware continues to be a real threat to business operations across all industries, no organization is safe from this threat.

Laszlo S. Gonc
CISSP, First Senior Fellow, DivIHN Cybersecurity Center of Excellence view
Cybersecurity Incident Response Preparedness

Cybersecurity Incident Response Preparedness

An incident response framework provides a structure to support incident response operations. A framework typically provides guidance on what needs to be done, but not on how it is done.

Laszlo S. Gonc
CISSP, First Senior Fellow, DivIHN Cybersecurity Center of Excellence view
Internet of Things

IoT Medical Device Cybersecurity

Healthcare data and medical devices would be aggressively targeted by ransomware attacks since early 2017 has proven to be true

Laszlo S. Gonc
CISSP, First Senior Fellow, DivIHN Cybersecurity Center of Excellence view
Back
to Top