logo

The Value of Penetration Testing ICS/OT Environments

ID: dbecd7a2-9666-527c-8b81-051ffebc38e5

STIX ID: report--dbecd7a2-9666-527c-8b81-051ffebc38e5

Feed Name: Dragos Blog

Date Published: 2022-03-01

Date Updated: 2026-04-27

...
...

**Executive summary:** This blog outlines when and how organizations should pursue penetration testing for ICS/OT environments, recommending that tests be performed only after foundational activities like architecture reviews and site assessments; it promotes an "assumed breach" approach to maximize value within limited testing time, emphasizes OT-specific safety and availability tradeoffs (including use of defanged exploits), and explains that tests aim to validate mitigations and reveal potential operational impacts such as loss of view, loss of control, loss of confidence, impaired process control, and inhibited response functions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.