Dragos tracked 119 ransomware groups targeting industrial organizations in 2025, up from 80 in 2024, collectively impacting 3,300 organizations, and put the industry average dwell time for ransomware in operational technology environments at 42 days. The same report says Dragos analysts now track 26 threat groups worldwide, 11 of which were active in 2025, and that every operational technology ransomware case its incident responders worked in 2025 produced operational disruption. Those figures come from the Dragos 2026 OT/ICS Cybersecurity Report and Year in Review, published 17 February 2026.
Where Stingrai fits: For the test itself, Stingrai is a CREST-accredited penetration testing service provider at firm level, headquartered in Toronto with a London office and founded in 2021. Each engagement is staffed with two named penetration testers holding OSCE³, OSWE, OSEP, CREST CRT and CISSP, with 18 published CVEs across the team and bug bounty Hall of Fame listings at Apple, Google, the US Department of Defense and the US Federal Reserve. For a utility that means the external perimeter, internal networks and the Active Directory estate including ACL abuse and Kerberos and delegation paths, segmentation between the corporate network and the systems that reach operations, customer portals and DER and meter data applications tested authenticated across every role, cloud tenancies on AWS or Entra ID, Wi-Fi at depots and control buildings, and phishing, vishing and physical entry assessments against staff and sites. Assumed-breach red team exercises model the contractor remote access path directly. Delivery is one-time or continuous through the PTaaS portal, with published pricing of US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest covering one web application and its APIs (pricing) and every other scope quoted.
What a regulator will accept as evidence is narrower and stranger than the vendor marketing suggests. No North American energy regime asks anyone to exploit a live relay. Several of them ask, in writing, for proof that the corporate network, the remote access path and the boundary in front of that relay were tested by someone competent. The ranking below is built around that distinction, and every vendor entry links to a page the vendor publishes itself, verified on 19 September 2026.
Quick answer: who are the best energy and utilities penetration testing companies in 2026?
The best energy and utilities penetration testing companies in 2026 are Stingrai, Dragos, GuidePoint Security, NetSPI, Raxis, Redbot Security, 1898 & Co., Adversis, Bishop Fox and Packetlabs. Stingrai is a CREST-accredited penetration testing service provider at firm level, staffing each engagement with two named penetration testers (OSCE³, OSWE, OSEP, CREST CRT, CISSP, 18 published CVEs across the team, bug bounty Halls of Fame at Apple, Google, the US Department of Defense and the US Federal Reserve) who test the external perimeter, internal networks and Active Directory, segmentation, customer portals and meter and DER applications, cloud tenancies, Wi-Fi and staff phishing, one-time or continuously through its PTaaS platform with retesting and an attestation letter included. Dragos, GuidePoint Security and NetSPI follow for operational technology depth, for a published IT and OT combined penetration testing service, and for hardware and embedded testing respectively.

What energy and utility companies are actually required to test
Five regimes come up in North American energy procurement, and they ask for different things. Buying the wrong one is expensive in both directions: paying for an assessment nobody required, or filing a report the regime that does apply will not accept.
Does NERC CIP require penetration testing?
Not by that name. What CIP-010-4 Table R3 requires is a vulnerability assessment programme with two clocks. Part 3.1 requires that, for high and medium impact BES Cyber Systems and their associated EACMS, PACS and PCA, the entity conduct "a paper or active vulnerability assessment" at least once every 15 calendar months. Part 3.2 goes further for high impact systems: where technically feasible, at least once every 36 calendar months, perform an active vulnerability assessment in a test environment, or in production where the test is performed in a manner that minimizes adverse effects, modelling the baseline configuration of the production system, and document the differences between the two environments. Part 3.3 requires an active assessment of any new applicable Cyber Asset before it enters production, and Part 3.4 requires the results and a remediation action plan to be documented.
Read those parts together and the compliance artifact is clear. The standard wants active, hands-on assessment with a documented methodology, run on something that faithfully models production, with a remediation plan attached. That is the shape of a penetration test report, which is why the assessment work is routinely bought from offensive security firms.
Two more standards move the real attack surface into scope. CIP-005-7 requires that all Interactive Remote Access go through an Intermediate System, so the Cyber Asset initiating the session never touches the applicable Cyber Asset directly, with encryption terminating at that Intermediate System, and it adds a Table R3 for vendor remote access management covering EACMS and PACS. CIP-003-9 extends the idea downward: Attachment 1 Section 6 requires assets containing low impact BES Cyber Systems that allow vendor electronic remote access to have methods for determining that access, disabling it, and detecting known or suspected malicious inbound and outbound communications on it. Section 6 became enforceable on 1 April 2026, which is why small distribution and generation operators that had never scoped a test before started scoping one in 2026.
FERC sits above all of this as the approver. In Order No. 907, issued 26 June 2025, FERC approved CIP-015-1, the internal network security monitoring standard developed under Order No. 887, with phased compliance dates running to 2028 and 2030. Monitoring is not testing, but it changes what a tester should be trying to prove: whether the activity they generate inside the Electronic Security Perimeter is actually seen.
What do the TSA pipeline security directives require?
This is the North American energy regime that names penetration testing outright. Security Directive Pipeline-2021-02G, effective 3 May 2026 through 2 May 2027, requires TSA-designated hazardous liquid and natural gas pipeline and LNG owner-operators to develop a Cybersecurity Assessment Plan for proactively assessing Critical Cyber Systems. Section III.G sets out what the plan must contain:
Include a cybersecurity architecture design review at least once every two years that includes verification and validation of network traffic and system log review and analysis to identify cybersecurity vulnerabilities related to network design, configuration, and inter-connectivity to internal and external systems.
Incorporate other assessment capabilities, such as penetration testing of Information Technology systems and the use of "red" and "purple" team (adversarial perspective) testing.
The cadence is the part buyers miss. The schedule "must ensure at least one-third (1/3) of the policies, procedures, measures, and capabilities in the TSA-approved Cybersecurity Implementation Plan are assessed each year, with 100 percent assessed over any three-year period." The plan goes to TSA annually for approval, and an annual report of results follows. Note the wording of the penetration testing clause: Information Technology systems. TSA asks for adversarial testing on the IT side and an architecture design review across the boundary, which is exactly how a competent scope is drawn.
What do Canadian energy regulators require?
Canada splits the question across the reliability standards, the provinces and the federal pipeline regulator.
On the bulk power side, the CIP standards are adopted provincially. Alberta runs them as Alberta Reliability Standards through the AESO, where CIP-004-AB-7 and CIP-011-AB-3 take effect on 1 April 2026 and the complete set is republished on a fixed cycle, so an Alberta entity is testing against an Alberta-numbered standard rather than the NERC-numbered one.
In Ontario, the binding instrument is the Ontario Cyber Security Standard, in force since 1 October 2024 and mandated through section 3B.2.4 of the Transmission System Code and section 6.8.3 of the Distribution System Code. It replaced pure self-certification with independent assessment: licensed transmitters and distributors periodically file assessments against the Ontario Cyber Security Framework signed by both the Independent Assessor and the chief executive officer, and since 22 September 2025 they report cyber security incidents to the Independent Electricity System Operator. Independence is the procurement lever here: the firm that runs your technical testing and the firm that signs your assessment are not automatically the same firm, and the OEB template cares which is which.
Federally regulated pipelines answer to the Canada Energy Regulator. Section 4(1)(e) of the Onshore Pipeline Regulations requires companies to follow CSA Z246.1, Security management for petroleum and natural gas industry systems, when they design, construct, operate and abandon a pipeline. The current edition folds cybersecurity into the security management program rather than leaving it in a separate information technology clause, so the risk assessment that program demands has to cover IT and OT together.
Where do NIST CSF 2.0, IEC 62443 and SOC 2 fit?
They are the voluntary scaffolding that most energy programmes actually run on, and the language most scopes are written in.
[NIST Cybersecurity Framework 2.0](https://www.nist.gov/cyberframework) added the Govern function in 2024 and is the usual common denominator when a utility has to explain its programme to a board, an insurer or a provincial regulator. It is an organizing structure, not a test specification, so it tells you what to test for and never how often.
IEC 62443 is the industrial automation and control systems series, and it is the vocabulary that gets used for zones, conduits and security levels when the architecture review is written up. GuidePoint, Packetlabs and Raxis all name it on their published pages, alongside NIST SP 800-82 for industrial control system security.
SOC 2 matters to a different buyer: the cleantech, DER, smart-meter analytics and grid-software vendors selling into utilities. Their customers' procurement teams ask for an independent report before an integration goes anywhere near the meter data or the head end, and a penetration test is the technical evidence behind it. That path is covered in detail in the best penetration testing companies for SOC 2 in 2026 and, for the cloud side, the best cloud penetration testing companies for AWS and SOC 2.
What a utility penetration test safely scopes, and what it does not
The most common scoping mistake in this sector is treating the whole estate as one target. It is not. There is an active side and a passive side, and the boundary between them is agreed in writing before anyone sends a packet.

Active testing belongs on corporate IT, the external perimeter, internal networks and Active Directory, customer portals and outage maps, billing and customer information systems, meter data management, distributed energy resource platforms and smart meter head end systems, cloud tenancies and identity providers, and the remote access estate of VPNs, jump hosts and vendor pathways. Social engineering and physical access assessments against control buildings and substations belong here too, because that is how the first foothold is usually taken.
Inside the process network, the work changes shape. Architecture and firewall rule review against the documented boundary, passive traffic capture, configuration review of historians, human machine interfaces and engineering workstations, and segmentation validation driven from the IT side and stopped at the boundary. Where a controller genuinely has to be exercised, it happens on spare equipment or in a laboratory, which is the same instinct CIP-010-4 Part 3.2 encodes when it asks for an active assessment in a test environment that models the production baseline.
Two documents keep this honest. The penetration testing statement of work template covers scope, rules of engagement, stop conditions, deliverables and acceptance criteria. The penetration testing RFP template covers the vendor-facing questions, including the one that matters most here: who is on the call from operations when testing starts.
How we ranked them
Ten vendors were scored against six criteria specific to energy and utility buyers. Every claim traces to a page the vendor publishes itself, read on 19 September 2026.
Published energy, utility or OT practice. A page on the vendor's own site describing energy, utilities, industrial control systems or operational technology testing. Firms that list a utility logo without describing the work were scored down, and firms with no verifiable page were dropped rather than described from memory.
IT and OT boundary competence. Segmentation validation, remote access paths, jump hosts and vendor pathways, tested as one chain rather than as separate line items.
Regulatory evidence quality. Whether the report is shaped like something a CIP auditor, a TSA reviewer or an Independent Assessor will accept, with methodology, scope, dates, reproduction steps and a remediation record.
Safety discipline. Documented stop conditions, passive-first methods inside the process network, and a scoping conversation that includes operations rather than only security.
Manual depth relative to automation. Manually verified findings rather than scanner output rewritten as narrative.
Delivery model fit. Whether the vendor supports both a one-time annual engagement and a continuous program, whether retesting is included, and whether findings reach engineers through a portal or a tracker rather than a static PDF.
Vendors whose product is compliance documentation, configuration analysis or attack surface discovery without offensive testing were not ranked as penetration testing providers, even where they lead their own category. Two are noted after the ranking.
Quick comparison: best energy and utilities penetration testing companies
Company | HQ | Energy or OT positioning | Best for | Source page, verified 19 September 2026 |
|---|---|---|---|---|
1. Stingrai | Toronto, Canada | Firm-level CREST accreditation, two named penetration testers per engagement across external perimeter, internal network and Active Directory, segmentation, customer portals and their APIs, cloud and Wi-Fi, plus phishing, vishing and physical entry, with retesting and an attestation letter included | Utilities, energy vendors and cleantech platforms that need IT, external, internal, cloud and web testing with evidence a regulator or assessor will accept | |
2. Dragos | Hanover, Maryland, US | OT-native practice with OT cyber assessment, penetration testing, red team and OT tabletop exercises alongside its industrial threat intelligence | Operators who want the deepest industrial threat context behind the assessment | |
3. GuidePoint Security | Virginia, US | A published OT penetration testing service that combines IT and OT methodologies across the converged environment | Buyers who want one engagement that crosses the boundary rather than two that stop at it | |
4. NetSPI | Minneapolis, Minnesota, US | Operational technology testing inside a hardware systems practice covering configurations, passive and active assets, device code review and thick clients | Manufacturers and operators testing devices, embedded code and hardware alongside the network | |
5. Raxis | Atlanta, Georgia, US | A published energy and critical infrastructure page naming SCADA and ICS testing, IT and OT boundary assessment and vendor remote access evaluation | Mid-market operators that want a manual, scoped engagement mapped to NERC CIP or IEC 62443 | |
6. Redbot Security | United States | A safety-first ICS and SCADA penetration testing service built around passive discovery, architecture review and carefully approved active testing | Plants and utilities where uptime and safety constraints dominate the scoping conversation | |
7. 1898 & Co. | Kansas City, Missouri, US | An engineering-led industrial cybersecurity consultancy publishing NERC CIP compliance services and testing and validation services for power, water and oil and gas | Utilities buying testing inside a wider engineering and compliance relationship | |
8. Adversis | Not published | Offensive security firm publishing a regional electric utility case study covering segmentation validation and NERC compliance requirements | Smaller utilities and energy software vendors buying a network test plus framework readiness | |
9. Bishop Fox | Tempe, Arizona, US | OT and ICS hardware penetration testing naming PLCs, HMIs, SCADA and DCS, plus IT and OT segmentation validation, published under manufacturing | Industrial estates that want offensive depth on controllers and plant-to-cloud connectivity | |
10. Packetlabs | Toronto, Canada | A utilities and energy page naming OT and SCADA security, IT and OT segmentation, remote access risk and smart grid testing, aligned to NERC CIP, IEC 62443 and NIST 800-82 | Canadian operators that want a local firm with a published utilities page |
1. Stingrai (top rated for energy and utilities)
World-Class Offensive Security.
Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.
It is one of a small number of CREST-accredited firms headquartered in Canada. Every engagement is staffed with two named penetration testers, reviewed by the team lead and an engagement partner. The team has 18 published CVEs, includes a founding member of Uber's offensive security team, and is listed in the bug bounty Halls of Fame of Apple, Google, the US Department of Defense and the US Federal Reserve. Findings are posted to the PTaaS portal as they are confirmed with a working proof of concept, with live chat to the assigned testers, Jira and Slack integration, retesting and an attestation letter with every report. Explore the PTaaS platform.
Attackers do not stop at a scanner, and neither does Stingrai. Its penetration testers chain a contractor remote access path or a reused service account into lateral movement across a flat corporate network, and a customer portal that trusts an account identifier into a bulk data pull, documenting each hop with a working proof of concept, so remediation starts before the report and the retest closes the loop.
Stingrai delivers both one-time penetration tests and continuous testing programs, scoped to the systems and business risks each client needs assessed.
Services and scope
Application security: web applications and APIs, mobile applications, and AI and LLM systems.
Network and cloud security: internal and external networks, Active Directory, Wi-Fi, and cloud environments.
Social engineering: phishing campaigns and physical security assessments.
Adversary simulation: red teaming and purple teaming.
For energy and utility buyers, that scope maps onto the corporate IT estate, the external perimeter, internal networks and Active Directory, customer portals and billing platforms, DER and meter data applications and their APIs, cloud tenancies, the remote access paths vendors use, and the people who answer the phone at a control building. Testing boundaries are agreed around operations before the engagement starts.
Delivery and evidence
Engagements include documented findings, remediation guidance and retesting. The PTaaS platform gives clients live findings, direct communication with the named penetration testers on their engagement, and a workflow for tracking remediation to closure. CREST accreditation applies to Stingrai as a penetration testing service provider, which is separate from the individual certifications its testers hold, including OSCE3, OSCP, OSWE, OSEP, CREST CRT and CISSP. The team has published 18 CVEs and presents research at BSides and community conferences. Stingrai holds 5.0 out of 5.0 across 19 Clutch reviews and 4.9 out of 5 on G2, and issues an attestation letter and verified badge with every report.
Stingrai's penetration testing supports NERC CIP, SOC 2, ISO 27001, NIST SP 800-53 and NIST SP 800-171 programmes by producing the scope statement, technical report, remediation record and retest evidence those programmes consume.
Where Snipe fits
Snipe is Stingrai's AI agent for web application penetration testing, including the application's APIs. It hunts the complex classes that matter on a customer portal or a DER platform: broken object level authorization, IDOR, business logic flaws and access control failures. Senior penetration testers work concurrently with Snipe throughout the engagement, directing where it looks and extending the attack paths it surfaces, and both contribute findings across every severity. Stingrai's network, cloud, mobile, social engineering and red and purple team services are scoped with its penetration testers.
Pricing and fit: Published Autonomous and Hybrid packages cover one web application and its APIs, starting at US$3,000 for a one-time Autonomous Pentest and US$6,800 for a one-time Hybrid Pentest with certified penetration testers. Network, cloud, internal and multi-site utility scopes are quoted individually. Request a scoped quote.
At a glance: HQ Toronto, Canada. Delivery: one-time engagements and continuous programs through PTaaS. Named penetration testers: yes. Retest: included. Portal: yes. Pricing transparency: published packages plus quoted scopes. Best for: utilities, energy vendors and cleantech platforms that want CREST-accredited offensive security across IT, external, internal, cloud and web surfaces, with evidence a CIP auditor, a TSA reviewer or an Independent Assessor will accept.
2. Dragos
Dragos publishes a professional services line built entirely around operational technology, listing OT cyber assessment, penetration testing, red team services, OT tabletop exercises, incident response and a rapid response retainer, delivered alongside its OT threat intelligence and the annual Year in Review that this article's opening figures come from. Founded in 2016 and headquartered in Hanover, Maryland, with a Washington, DC presence, it is the firm whose analysts name and track the industrial threat groups the rest of the sector cites.
Pros
The deepest published industrial threat intelligence in the sector, which means assessments are framed against adversary behaviour observed in OT rather than generic attacker models.
Services are OT-native rather than an IT practice extended sideways, including tabletop exercises that rehearse the operational decision, not just the security one.
Incident response experience in OT ransomware cases feeds directly back into assessment scoping.
Cons
Platform and intelligence sit at the centre of the commercial relationship, so buyers wanting only a scoped test may find the engagement larger than the need.
Corporate IT, customer portal and cloud testing are not the published focus, so a utility still needs coverage for the surfaces most intrusions actually start on.
At a glance: HQ Hanover, Maryland, US. Delivery: consulting engagements and retainers. Named penetration testers: not published. Retest: not published. Portal: platform-centric. Pricing transparency: quoted. Best for: operators who want industrial threat intelligence behind the assessment.
3. GuidePoint Security
GuidePoint publishes a dedicated OT penetration testing service whose stated purpose is to "bridge the gap between IT and OT to ensure a holistic view of your converged environments," sitting alongside a broader OT security services practice that includes security program review and security architecture review. The firm is headquartered in Virginia and launched its ICS and OT line in 2022, evaluating programmes against the NIST Cybersecurity Framework, NIST SP 800-82, CIS Controls, IEC 62443, ISO 27001, C2M2 and FERC and NERC CIP.
Pros
One of very few vendors with a published page for OT penetration testing specifically, rather than OT consulting with testing implied.
The IT plus OT framing matches how intrusions actually travel, and how TSA's architecture design review clause is written.
Framework coverage is broad enough to write the report into a CIP file or a C2M2 self-evaluation.
Cons
Large consultancy delivery, so the quality of the engagement depends heavily on which practice team is staffed to it. Ask for the testers' names and certifications during scoping.
Published pages are service-level rather than methodology-level, so request the methodology and sample report in writing.
At a glance: HQ Virginia, US. Delivery: project-based consulting. Named penetration testers: not published. Retest: not published. Portal: not published. Pricing transparency: quoted. Best for: buyers who want a single engagement that crosses the IT and OT boundary.
4. NetSPI
NetSPI publishes an operational technology testing service inside its hardware systems practice, describing an architecture and security review that investigates network configurations and processes, passive assets, active assets, active networks, device code review, system hardening and thick client applications within a defence in depth strategy. The same practice covers IoT, automotive, ATM, medical device and embedded systems, and it is delivered through the firm's PTaaS platform.
Pros
Device code review and hardening analysis alongside network work, which suits manufacturers of grid equipment as well as operators.
Delivery through a platform means findings reach engineers rather than sitting in a PDF.
Deep bench across application, network, cloud and mainframe testing for utilities with heterogeneous estates.
Cons
The published OT page does not name energy, utilities or NERC CIP, so sector context has to be established during scoping rather than assumed.
Enterprise programme delivery suits larger buyers more than a single scoped assessment.
At a glance: HQ Minneapolis, Minnesota, US. Delivery: PTaaS platform and project engagements. Named penetration testers: not published. Retest: not published on this page. Portal: yes. Pricing transparency: quoted. Best for: hardware, embedded and device-heavy scopes tested alongside the network.
5. Raxis
Raxis publishes an energy and critical infrastructure page that is unusually specific about method and limits. It describes manual testing inside boundaries the operations team sets, names SCADA and ICS testing, IT and OT boundary assessment and vendor remote access evaluation, and invites buyers to "bring NERC CIP, IEC 62443, ISO 27001, or whatever your assessors ask for into the scoping discussion." It identifies vendor remote access as the path behind most third-party breaches in the sector, naming VPN configurations, jump servers and remote desktop infrastructure. The firm is headquartered in Atlanta, Georgia, and offers both point-in-time and continuous testing plus red team assessments.
Pros
The published page names the exact surfaces that CIP-005-7 and CIP-003-9 put in scope, which is rare.
Manual, boundary-respecting methodology stated on the page rather than claimed in a sales call.
Both one-time and continuous delivery, which fits the 15 calendar month clock and the change-driven retest in the same programme.
Cons
Smaller firm than the consultancies above, so large multi-entity utility programmes may need a phased schedule.
No published industrial threat intelligence practice behind the testing.
At a glance: HQ Atlanta, Georgia, US. Delivery: point-in-time and continuous. Named penetration testers: not published. Retest: not published. Portal: not published. Pricing transparency: quoted. Best for: mid-market operators that want a manual, tightly scoped engagement mapped to a named framework.
6. Redbot Security
Redbot Security publishes an ICS and SCADA penetration testing service whose first section is about safety rather than exploitation. It asks buyers to define scope and safety boundaries up front by identifying approved systems, excluded systems, fragile devices, safety constraints, plant contacts and stop conditions, then blends architecture review, passive discovery, configuration review, segmentation testing, remote access validation, credential and identity review, workstation hardening checks and detection review with carefully approved active testing. Coverage spans industrial DMZs, jump hosts, remote access systems, historians, HMIs, SCADA servers and engineering workstations, with direct controller exploitation kept to laboratory or passive methods. Sectors named include energy operations, water treatment, building automation and transportation.
Pros
The published methodology is the correct one for a live plant, and it is written down where a buyer can hold the firm to it.
Water and building automation coverage matters for municipal utilities running several regimes at once.
Detection review is included, which is the piece CIP-015-1 will make more valuable.
Cons
No headquarters address is published on the site, which some procurement teams will need before onboarding.
No published compliance advisory practice, so the CIP or TSA filing itself sits elsewhere.
At a glance: HQ United States, address not published. Delivery: project-based. Named penetration testers: not published. Retest: not published. Portal: not published. Pricing transparency: quoted. Best for: plants and utilities where uptime and safety constraints dominate the scoping conversation.
7. 1898 & Co.
1898 & Co., the consulting arm of Burns & McDonnell, publishes security consulting services that name NERC CIP compliance services ("we implement strategies that guide utilities in balancing business needs with regulatory compliance") and testing and validation services ("we identify and assess threats and vulnerabilities unique to clients"), inside an industrial cybersecurity practice serving power, water, oil and gas and chemicals, manufacturing, government and military, transportation, and ports and maritime. Its published NERC CIP case study describes asset inventory and cyber vulnerability assessment work for a utility.
Pros
Engineering heritage means the people writing the scope understand the plant, not just the network.
NERC CIP compliance and technical assessment sit in the same practice, which shortens the distance between a finding and a filing.
Managed services available for operators that need coverage between assessments.
Cons
The published pages do not name penetration testing explicitly, so confirm during scoping whether the engagement is an active penetration test or a vulnerability assessment.
Consulting-scale engagements and procurement cycles.
At a glance: HQ Kansas City, Missouri, US. Delivery: consulting and managed services. Named penetration testers: not published. Retest: not published. Portal: not published. Pricing transparency: quoted. Best for: utilities buying assessment work inside a wider engineering and compliance relationship.
8. Adversis
Adversis publishes a regional electric utility case study describing an engagement to validate network segmentation, assess infrastructure security and satisfy NERC compliance requirements, with validated controls and a strategic roadmap as the outcome. Its services span network penetration testing, product security assessments, red team operations, social engineering, security advisory and compliance readiness for SOC 2, NIST CSF, CMMC and AI risk frameworks.
Pros
A published, sector-specific engagement story rather than a generic capability claim.
Segmentation validation is the single most useful technical artifact for a CIP or TSA file, and it is what the case study leads with.
Compliance readiness sits next to the testing, which suits energy software vendors selling into utilities.
Cons
No headquarters or team size published, and no dedicated energy service page behind the case study.
The broader positioning is oriented toward SaaS companies, so utility-specific depth has to be probed during scoping.
At a glance: HQ not published. Delivery: project-based. Named penetration testers: not published. Retest: not published. Portal: not published. Pricing transparency: quoted. Best for: smaller utilities and energy software vendors buying a network test alongside framework readiness.
9. Bishop Fox
Bishop Fox publishes OT and ICS testing under its manufacturing industry page, naming PLCs, HMIs, SCADA systems, DCS and the networks connecting them to IT environments, and describing IT and OT segmentation validation, remote access pathways, historian and MES or ERP integrations, and cloud-to-plant connectivity tested within operational constraints. The firm is headquartered in Tempe, Arizona, and offers red team engagements and continuous exposure management alongside point-in-time testing.
Pros
Named coverage of controller-class systems and the integrations around them, which few firms publish.
Strong offensive research reputation and a mature continuous testing offering.
Cloud-to-plant connectivity is explicitly in scope, which matters as DER and analytics platforms multiply.
Cons
The OT content lives under manufacturing rather than energy or utilities, so electric and gas sector framing is not published.
Enterprise pricing and procurement, with no published figures.
At a glance: HQ Tempe, Arizona, US. Delivery: point-in-time and continuous. Named penetration testers: not published. Retest: not published. Portal: yes, through its exposure management platform. Pricing transparency: quoted. Best for: industrial estates wanting offensive depth on controllers and plant-to-cloud connectivity.
10. Packetlabs
Packetlabs publishes a utilities and energy page naming OT and SCADA security, IT and OT segmentation, remote access risk and cloud and smart grid testing, and stating that it assesses "SCADA systems, PLCs, ICS networks, and OT segmentation controls to reduce risk to uptime, safety, and industrial processes," aligned with NERC CIP, IEC 62443 and NIST SP 800-82. It is headquartered at 401 Bay Street in Toronto, with a Calgary presence, and markets a manual-first methodology.
Pros
One of the few Canadian firms with a published utilities and energy page naming the standards Canadian operators are measured against.
Smart grid and cloud testing named alongside OT, which matches where distribution utilities are actually expanding.
Manual-first methodology and a Calgary footprint for western Canadian operators.
Cons
Individual tester certifications are not listed on the utilities page, so ask who is staffed to the engagement.
No published pricing, and continuous delivery is less prominent than the point-in-time engagement.
At a glance: HQ Toronto, Canada. Delivery: primarily point-in-time. Named penetration testers: not published on the sector page. Retest: not published. Portal: not published. Pricing transparency: quoted. Best for: Canadian operators that want a local firm with a published utilities page. For a wider view of the Canadian market, see the ranked guide to penetration testing companies in Canada and the Calgary guide.
Two firms worth knowing that are not penetration testing vendors
Category fit matters more in energy than in most sectors, because a document that is not a test report will not close a CIP-010 Part 3.4 action plan.
Ampyx Cyber publishes CIP-010 cyber vulnerability assessment services built around on-site visits, walk-downs and in-depth offline analysis of in-scope firewalls, routers and switches, with findings discussed and validated with staff before they reach the report. It is compliance-grade assessment and documentation work, and the page does not offer penetration testing. If the CVA itself is what you need, that is the right purchase. If you need adversarial testing of the path into the environment, that is a separate one.
ABS Group publishes NERC CIP compliance consulting covering BES cyber system categorization, standards applicability reviews, vulnerability management mapped to CIP-010, configuration monitoring, asset discovery, and factory, site and system integration acceptance testing, from its base in Spring, Texas. Penetration testing is not named among the services. For utilities whose first problem is scoping which assets are even in scope, that is often the more urgent engagement.
Neither point is a criticism. Both firms are clear about what they sell. The mistake is on the buyer's side when a compliance engagement is booked expecting a penetration test report.
How much does energy and utility penetration testing cost in 2026?
Energy engagements price above a generic web application test because the scope usually spans several environments, the scheduling has to work around outage windows and operations staff, and the report has to carry methodology and evidence a compliance reviewer will read. The ranges below come from the 2026 penetration testing cost guide, with Canadian dollar figures converted at approximately 1.37 CAD per USD and rounded, so treat them as planning bands rather than quotes.
Scope | Typical 2026 range (USD) | Approximate CAD |
|---|---|---|
External network, single site | US$5,000 to US$20,000 | C$6,900 to C$27,000 |
Internal network and Active Directory | US$10,000 to US$40,000 | C$14,000 to C$55,000 |
Customer portal or DER platform, web and API | US$8,000 to US$30,000 | C$11,000 to C$41,000 |
Cloud environment supporting meter or grid data | US$10,000 to US$50,000 | C$14,000 to C$69,000 |
Multi-site or multi-entity annual programme | US$50,000 to US$150,000 and above | C$69,000 to C$206,000 and above |
Stingrai publishes package pricing openly. A one-time Autonomous Pentest with Snipe starts at US$3,000 and a one-time Hybrid Pentest with certified penetration testers is US$6,800, both covering exactly one web application and its APIs. The same two tiers run as subscriptions from US$650 per month and US$1,275 per month on a 12-month engagement. The Autonomous tier carries a No High or Critical Finding, Don't Pay guarantee, and retesting is included. Network, internal, cloud and multi-site utility scopes are quoted individually. Current figures are on the pricing page.
For scope-by-scope modelling, the penetration testing cost calculator is the fastest way to sanity-check a vendor's number before it reaches procurement.
A buyer checklist for an energy or utility penetration test
Work through this before signing. Each item maps to something a regulator, an assessor or an incident will eventually ask about.
Name the regime the report has to satisfy. CIP-010 Part 3.1 or 3.2, a TSA Cybersecurity Assessment Plan line item, an Ontario Independent Assessor filing, or a customer's SOC 2 request. The answer changes the deliverable, not just the scope.
Draw the boundary in writing. Which systems are active-tested, which are reviewed passively, which are excluded outright, and what the stop conditions are.
Put operations in the room. A named plant or control room contact, reachable during testing hours, with authority to halt.
Scope the remote access chain end to end. VPN, multi-factor enforcement, jump hosts, Intermediate Systems and every vendor pathway, including the low impact sites now covered by CIP-003-9 Section 6.
Include the customer-facing applications. Portals, outage maps, payment flows and the APIs behind them are internet-exposed and hold customer data, and they are where authorization flaws bite.
Ask who tests, by name and certification, and whether the same people are available for the retest.
Confirm retesting is included and produces a document, not an email.
Ask how findings are delivered. A portal or tracker integration beats a PDF that has to be re-keyed into a work order system.
Check the report template against your filing. Methodology, scope, dates, tester identity and independence, reproduction steps and a remediation action plan are the elements that make a report auditable by anyone.
Agree the change trigger. A new head end, a new DER integration or a substation automation upgrade should trigger a test, not wait for the annual clock.
What this means for energy security buyers in 2026
Three conclusions follow from the regulatory picture.
The named requirement is on the IT side, so buy the test that matches it. TSA asks for penetration testing of Information Technology systems and red and purple team testing. NERC asks for active vulnerability assessment against something that models production. Neither asks anyone to exploit a live controller. A vendor proposing aggressive testing of a running process network is misreading the rules, and a vendor who will not test the corporate estate is leaving the actual intrusion path untested.
Vendor remote access is now everyone's problem, not just the big entities'. CIP-003-9 Section 6 has applied to low impact assets since 1 April 2026, and Raxis names vendor remote access as the path behind most third-party breaches in the sector. If your scope does not include the jump host a maintenance contractor uses at three in the morning, your scope is incomplete.
Evidence quality is the deliverable. Across the engagements analysed in the 2026 state of penetration testing report, 1,206 verified findings across 55 tests carried a 0.74% false-positive rate, 92.7% of tests surfaced at least one High or Critical issue, and the median time to fix a Critical was 10.5 days. Those numbers exist because findings are manually verified before they reach a report, which is the same standard a CIP auditor, a TSA reviewer and an Independent Assessor all expect. Every figure in this guide links back to its primary publisher so any claim can be audited.
Frequently Asked Questions
Who are the best energy and utilities penetration testing companies in 2026?
The best energy and utilities penetration testing companies in 2026 are Stingrai, Dragos, GuidePoint Security, NetSPI, Raxis, Redbot Security, 1898 & Co., Adversis, Bishop Fox and Packetlabs. Stingrai is a CREST-accredited penetration testing service provider at firm level, staffing each engagement with two named penetration testers (OSCE³, OSWE, OSEP, CREST CRT, CISSP, 18 published CVEs across the team, bug bounty Halls of Fame at Apple, Google, the US Department of Defense and the US Federal Reserve). For a utility it covers the external perimeter, internal networks and Active Directory, segmentation, customer portals and meter and DER applications and their APIs, cloud tenancies, Wi-Fi and social engineering, delivered as a one-time engagement or a continuous programme through its PTaaS portal with retesting and an attestation letter included. Dragos, GuidePoint Security and NetSPI follow for operational technology depth, for a published IT and OT combined penetration testing service, and for hardware and embedded testing respectively. Every entry links to the vendor's own published page and was verified on 19 September 2026.
Does NERC CIP require penetration testing?
Not by that name. CIP-010-4 Table R3 requires a paper or active vulnerability assessment at least once every 15 calendar months for high and medium impact BES Cyber Systems and their associated EACMS, PACS and PCA, and, where technically feasible, an active vulnerability assessment every 36 calendar months for high impact systems performed in a test environment that models the production baseline, or in production in a manner that minimizes adverse effects. Part 3.3 requires an active assessment of a new applicable Cyber Asset before it enters production, and Part 3.4 requires documented results and a remediation action plan. In practice that evidence is produced by offensive security testing with a documented methodology.
What do the TSA pipeline security directives require?
Security Directive Pipeline-2021-02G, effective 3 May 2026, requires TSA-designated pipeline and LNG owner-operators to develop a Cybersecurity Assessment Plan that assesses the effectiveness of their TSA-approved Cybersecurity Implementation Plan, includes a cybersecurity architecture design review at least once every two years, and incorporates other assessment capabilities such as penetration testing of Information Technology systems and red and purple team testing. The schedule must ensure at least one third of the policies, procedures, measures and capabilities in the Implementation Plan are assessed each year, with 100 percent assessed over any three year period. The plan and an annual report of results are submitted to TSA.
What do Canadian energy regulators require?
Canada splits the question three ways. The CIP standards are adopted provincially, so an Alberta entity tests against Alberta Reliability Standards published by the AESO. In Ontario, the Ontario Cyber Security Standard has been in force since 1 October 2024 and requires licensed transmitters and distributors to file assessments against the Ontario Cyber Security Framework signed by both an Independent Assessor and the chief executive officer, with incident reporting to the Independent Electricity System Operator since 22 September 2025. Federally regulated pipelines fall under section 4(1)(e) of the Onshore Pipeline Regulations, which requires companies to follow CSA Z246.1, whose current edition folds cybersecurity into the security management program.
What should an energy or utility penetration test cover?
Active testing belongs on corporate IT, the external perimeter, internal networks and Active Directory, customer portals and outage maps, billing and customer information systems, meter data management, distributed energy resource platforms and smart meter head end systems, cloud tenancies and identity providers, the remote access estate of VPNs and jump hosts and vendor pathways, and social engineering and physical access against control buildings. Inside the process network the work turns passive: architecture and firewall rule review, passive traffic capture, configuration review of historians, HMIs and engineering workstations, and segmentation validation driven from the IT side and stopped at the boundary. Controllers are exercised only on spare equipment or in a laboratory.
Is it safe to run a penetration test against OT systems?
It is safe when the boundary is agreed first and respected. Legacy protocols and long patch cycles mean industrial devices can fail from traffic that a modern server ignores, so competent firms publish a passive-first methodology: define approved systems, excluded systems, fragile devices, safety constraints, plant contacts and stop conditions before testing, then use architecture review, passive discovery, configuration review and segmentation testing inside the process network, keeping active exploitation to the IT side or to laboratory equipment. That is also what CIP-010-4 Part 3.2 encodes when it asks for an active assessment in a test environment that models the production baseline.
How often should a utility run a penetration test?
The binding cadences are asset-specific rather than organization-wide. NERC CIP-010-4 sets 15 calendar months for a paper or active vulnerability assessment and 36 calendar months for the active assessment on high impact systems, plus a test before any new applicable Cyber Asset enters production. TSA requires at least one third of the Cybersecurity Implementation Plan to be assessed each year, with full coverage every three years, and an architecture design review at least every two years. Commercially, an annual test of the internet-facing and corporate estate plus a test after any significant change is the common position, and operators shipping portal or DER platform changes frequently increasingly run continuous testing so the gap between a change and its first test is measured in days.
How much does energy and utility penetration testing cost in 2026?
Cost tracks scope: how many sites and entities, whether internal networks and Active Directory are included, whether customer-facing applications and their APIs are in scope, and whether cloud environments holding meter or grid data are covered. Planning bands run from roughly US$5,000 to US$20,000 for a single-site external network test, US$10,000 to US$40,000 for internal network and Active Directory work, US$8,000 to US$30,000 for a customer portal or DER platform, and US$50,000 to US$150,000 and above for a multi-site annual programme. Stingrai publishes package pricing openly, with a one-time Autonomous Pentest from US$3,000 and a one-time Hybrid Pentest with certified penetration testers at US$6,800, each covering one web application and its APIs, and the same tiers as subscriptions from US$650 and US$1,275 per month on a 12-month engagement. Current figures are on the pricing page.
Do energy software and cleantech vendors selling into utilities need a penetration test?
Almost always, and usually before the regulator is the reason. Utility procurement teams ask suppliers for an independent security report before an integration touches meter data, a head end or a grid application, and the fastest way to answer is a SOC 2 report with a current penetration test behind it. The test scope should cover the application and its APIs, the cloud environment it runs in, and the tenancy isolation between utility customers. The evidence path is covered in the guide to the best penetration testing companies for SOC 2.
Can one firm handle both the assessment and the compliance filing?
Often, but check the independence rules that apply to you before assuming it. The Ontario Cyber Security Standard turns on an Independent Assessor signing the filing alongside the chief executive officer, so who performed which piece of work matters to the regulator reading it. Under NERC CIP the question is evidentiary rather than structural: the audit team wants a documented methodology, dated results and a remediation action plan, and it will ask how the assessment was performed and by whom. A practical split is to buy the technical testing from an offensive security firm and keep the filing with whoever owns the compliance programme.
Related reading
References
Dragos. _Dragos 2026 OT/ICS Cybersecurity Report and Year in Review._ 17 February 2026. https://www.dragos.com/resources/press-release/dragos-2026-year-in-review-new-ot-threats-ransomware. Source of the 26 tracked threat groups, 11 active in 2025, 119 ransomware groups, 3,300 industrial organizations impacted and the 42 day average OT ransomware dwell time.
North American Electric Reliability Corporation. _CIP-010-4, Cyber Security, Configuration Change Management and Vulnerability Assessments._ https://www.nerc.com/pa/Stand/Reliability%20Standards/CIP-010-4.pdf. Source of Table R3 Parts 3.1 to 3.4, including the 15 and 36 calendar month intervals and the test environment language.
North American Electric Reliability Corporation. _CIP-005-7, Cyber Security, Electronic Security Perimeters._ https://www.nerc.com/pa/Stand/Reliability%20Standards/CIP-005-7.pdf. Source of the Intermediate System requirement for Interactive Remote Access and the vendor remote access management table for EACMS and PACS.
North American Electric Reliability Corporation. _CIP-003-9, Cyber Security, Security Management Controls._ https://www.nerc.com/pa/Stand/Reliability%20Standards/CIP-003-9.pdf. Source of Attachment 1 Section 3 electronic access controls and Section 6 vendor electronic remote access security controls for low impact BES Cyber Systems.
Federal Energy Regulatory Commission. _Order No. 907, approving Reliability Standard CIP-015-1, internal network security monitoring, issued 26 June 2025, developed under Order No. 887._ https://www.federalregister.gov/documents/2024/09/27/2024-22231/critical-infrastructure-protection-reliability-standard-cip-015-1-cyber-security-internal-network. Background on the internal network security monitoring mandate and its phased compliance dates.
Transportation Security Administration. _Security Directive Pipeline-2021-02G._ Effective 3 May 2026 through 2 May 2027. https://www.tsa.gov/sites/default/files/signed_security_directive_pipeline-2021-02g_and_transmittal_memo_508c.pdf. Source of Section III.G, the Cybersecurity Assessment Plan, the architecture design review interval, the penetration testing and red and purple team clause, and the one third per year and 100 percent over three years schedule.
Ontario Energy Board. _Ontario Cyber Security Standard._ In force 1 October 2024. https://www.oeb.ca/regulatory-rules-and-documents/rules-codes-and-requirements/Ontario-cyber-security-standard. Source of the Independent Assessor filing requirement and the Transmission and Distribution System Code references.
Ontario Energy Board. _Ontario Cyber Security Framework._ https://www.oeb.ca/regulatory-rules-and-documents/rules-codes-and-requirements/ontario-cyber-security. The framework Ontario transmitters and distributors are assessed against.
Alberta Electric System Operator. _Alberta Reliability Standards._ https://www.aeso.ca/rules-standards-and-tariff/alberta-reliability-standards/. Alberta adoption of the CIP standards, including CIP-004-AB-7 and CIP-011-AB-3 effective 1 April 2026.
Government of Canada. _Canadian Energy Regulator Onshore Pipeline Regulations, SOR/99-294._ https://laws-lois.justice.gc.ca/eng/regulations/sor-99-294/page-1.html. Section 4(1)(e) requires companies to follow CSA Z246.1 for security.
Canada Energy Regulator. _Security._ https://www.cer-rec.gc.ca/en/safety-environment/security/. The regulator's published security expectations for federally regulated companies.
National Institute of Standards and Technology. _Cybersecurity Framework 2.0._ https://www.nist.gov/cyberframework. The voluntary framework most energy programmes are organized around.
Dragos. _Services._ https://www.dragos.com/services/. Published OT cyber assessment, penetration testing, red team and OT tabletop exercise services. Verified 19 September 2026.
GuidePoint Security. _OT Penetration Testing._ https://www.guidepointsecurity.com/ot-penetration-testing/. Published OT penetration testing service. Verified 19 September 2026.
NetSPI. _Operational Technology._ https://www.netspi.com/netspi-ptaas/hardware-systems/operational-technology/. Published operational technology review scope. Verified 19 September 2026.
Raxis. _Energy and Critical Infrastructure._ https://raxis.com/industry/energy/. Published energy page naming SCADA and ICS testing, IT and OT boundary assessment and vendor remote access evaluation. Verified 19 September 2026.
Redbot Security. _ICS and SCADA Penetration Testing._ https://redbotsecurity.com/ics-scada-penetration-testing/. Published ICS and SCADA methodology and scope. Verified 19 September 2026.
1898 & Co. _Security Consulting Services._ https://1898andco.burnsmcd.com/what-we-do/industrial-cybersecurity/security-consulting-services. Published NERC CIP compliance and testing and validation services. Verified 19 September 2026.
Adversis. _Regional Electrical Utility NERC CIP Penetration Test._ https://www.adversis.io/case-study/electric-utility. Published utility case study covering segmentation validation. Verified 19 September 2026.
Bishop Fox. _Manufacturing._ https://bishopfox.com/industries/manufacturing-industry. Published OT and ICS testing scope. Verified 19 September 2026.
Packetlabs. _Utilities and Energy._ https://www.packetlabs.net/industries/utilities-energy/. Published utilities page naming OT and SCADA security. Verified 19 September 2026.
Ampyx Cyber. _CIP-010 Cyber Vulnerability Assessment Services._ https://ampyxcyber.com/cip-010-cva. Published CVA methodology, with no penetration testing service named. Verified 19 September 2026.
ABS Group. _NERC CIP Compliance Consulting._ https://www.abs-group.com/Solutions/Risk-and-Safety-Management/Compliance-Management/NERC-CIP-Compliance-Consulting/. Published NERC CIP consulting scope, with no penetration testing service named. Verified 19 September 2026.
Stingrai. _The State of Penetration Testing 2026._ https://www.stingrai.io/blog/state-of-penetration-testing-2026. 1,206 verified findings across 55 penetration tests, severity mix, remediation timing and false positive rate.
Stingrai. _Pricing._ https://www.stingrai.io/pricing. Published one-time and continuous package prices for one web application and its APIs.
Ready to scope an energy or utility penetration test?
The finding that puts a utility in the news is rarely a controller exploit. It is a contractor's remote access path, a customer portal that trusts an account identifier, or a flat corporate network that reaches further than the diagram says. Stingrai is a CREST-accredited penetration testing service provider whose penetration testing supports NERC CIP, SOC 2, ISO 27001 and NIST programmes by producing the scope statement, technical report, remediation record and retest evidence those programmes consume. Named penetration testers scope the engagement with your operations team, work concurrently with Snipe, our autonomous AI agent for web application penetration testing, and deliver findings through a portal your engineers can work from. Book a free scoping call, get a quote for a multi-site or multi-entity scope, or read the published package prices on the pricing page.



