Skip to content

Energetyka

|

CS.113

Comprehensive OT Technology Network Security Audit

Multi-phase TAN audit of an energy operator - from IT/OT segmentation testing to physical access attempts and retesting within 90 days.

Client

Critical energy infrastructure operator

Challenge

The Technology Network (TAN) of the energy operator was exposed to multiple attack vectors: unauthorized access from the IT network, VPN connection breaches, physical intrusion, and network segmentation gaps.

Approach

01

IT-to-TAN transition verification

Attack simulation from a compromised IT domain workstation - reconnaissance, scanning, Active Directory trust relationship testing.

02

Edge device audit

Examination of up to 5 devices at the IT/TAN boundary, including an in-depth penetration test of one of them.

03

VPN testing

External scanning of VPN infrastructure and simulation of credential compromise.

04

Physical access test

Plugging a device into a network port, network mapping, privilege escalation attempts, verification of 802.1X mechanisms and VLAN segmentation.

05

Reporting and retesting

Vulnerability classification per CVSS v3, prioritized remediation recommendations, and retesting within 90 days.

Results

7 weeks of audit execution across 6 phases
01

Complete security map of the Technology Network (TAN)

02

Prioritized remediation recommendations with CVSS v3 classification

03

Retesting confirming the effectiveness of implemented fixes

We'll discuss scope, methodology, and timeline.

Book a consultation

Free consultation, no strings attached.