Manufacturing was the most targeted industry in IBM's X-Force Threat Intelligence Index for the fifth year in 2026, accounting for 27.7% of the incidents X-Force observed in 2025, according to IBM's announcement of the report. Dragos tracked 119 ransomware groups targeting industrial organizations in 2025, up from 80 in 2024, which together hit 3,300 organizations, and manufacturing accounted for more than two-thirds of all victims, per the Dragos 2026 OT/ICS Cybersecurity Report and Year in Review.
The threat data is rarely what starts a test. A manufacturing penetration test is usually requested by someone outside the plant: an OEM customer running its supplier audit, a prime contractor flowing down CMMC, a TISAX assessment, a cyber insurer's renewal form, or an RFP that asks for an accredited firm and certified testers. Each asks for something different. This guide covers what to test, why now, how to scope it without touching production, and what it costs, for manufacturers in the United States and Canada. Every regulatory and standards statement below was checked against the primary text on 2 October 2026. It explains the requirements; it is not legal advice.
Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider at firm level, founded in Toronto in 2021 with a London office, and serves clients in the United States and Canada. Each human-led engagement is run by two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP certifications, with 18 published CVEs across the team. For a plant, that means the IT side and the boundary: the external perimeter with VPNs and vendor remote access, the internal network and Active Directory, a segmentation test of every path from the office network into the plant DMZ and OT zones under written rules of engagement, plant Wi-Fi, ERP, MES and customer portals, phishing of office and plant staff, and physical entry where scoped. Controller-level OT testing, meaning PLCs, HMIs, safety instrumented systems and industrial protocols, is a specialist discipline Stingrai does not publish as a service, so pair it with your OT vendor or an OT specialist. Engagements run as a one-time annual test or as a continuous program; findings post to the PTaaS portal as they are confirmed, retesting is included, and human-led and hybrid engagements include an attestation letter. Published prices cover one web application and its APIs (pricing); network, Active Directory and segmentation scopes are quoted.
Quick answer: what does a manufacturing penetration test cover?
A manufacturing penetration test covers the systems an attacker uses to reach production, tested from outside and inside the network: the internet-facing perimeter, including VPNs, vendor and integrator remote access and any exposed remote desktop; the internal network and Active Directory; the segmentation between the office (IT) network and the plant (OT) zones, including the plant DMZ, jump hosts, historians and engineering workstations; plant Wi-Fi; and the ERP, MES and portal applications that hold orders, drawings and supplier data. Phishing and physical entry are added when a customer, insurer or RFP asks for them. Controllers, HMIs and safety systems are not actively scanned or exploited in production: NIST SP 800-82 Rev. 3 says penetration testing "is used with care on OT networks" and points to replicated or simulated systems and planned outages. For most manufacturers the requirement arrives through a contract, a certification or an insurance application rather than a sector regulation, and the trigger sets both the scope and the report.

Why attackers target plants: the 2026 data
Independent sources describe the same pattern from different vantage points. Each figure below keeps the base its publisher used.
IBM X-Force Threat Intelligence Index 2026. IBM published the report on 25 February 2026. Its announcement states: "Manufacturing tops the target list for the fifth year. The sector accounted for 27.7% of incidents observed by X-Force, with data theft being the most common." The base is the incidents IBM's X-Force teams observed in 2025, not every attack on every manufacturer. Two findings in the same release cover all industries rather than manufacturing alone, and they show how and where attacks landed: "Vulnerability exploitation became the leading cause of attacks, accounting for 40% of incidents observed by X-Force in 2025," and North America accounted for 29% of cases, becoming "the most attacked region for the first time in 6 years."
Dragos 2026 OT/ICS Cybersecurity Report and Year in Review. Released on 17 February 2026, it reports that Dragos "tracked 119 ransomware groups targeting industrial organizations in 2025, up from 80 in 2024, collectively impacting 3,300 organizations. Manufacturing accounted for more than two-thirds of all victims. Industry-wide, the average dwell time for ransomware in OT environments was 42 days." It also "noted persistent mischaracterization of OT incidents as 'IT only' due to OT devices such as engineering workstations and HMIs misclassified as IT for running Windows operating systems." Whether the office network can reach hosts like these is what a segmentation test checks: engineering workstations at Level 3 by reachability from the IT side, and HMIs in the control zones only through a listener the OT team places there, with no traffic aimed at the HMI itself.
Verizon 2026 Data Breach Investigations Report. Published on 19 May 2026 and covering incidents from 1 November 2024 to 31 October 2025, the Verizon 2026 Data Breach Investigations Report records 3,627 incidents in Manufacturing (NAICS 31 to 33), 2,713 of them with confirmed data disclosure. Its sector summary says System Intrusion, Social Engineering and Basic Web Application Attacks "represent 91% of breaches", that "Malware was involved in 75% of the breaches in this vertical, with Ransomware accounting for 61%", and that the initial access vector breakdown for Manufacturing breaches is led by "Exploitation of vulnerabilities (38%), Phishing (13%), Credential abuse (11%)". Its sector example is the late 2025 ransomware attack on Asahi Group Holdings, which "forced a shutdown of their domestic manufacturing facilities and resulted in a suspension of shipments."
CISA and FBI advisories. The joint #StopRansomware advisory on Akira (AA24-109A, last revised 13 November 2025) says Akira actors "have a notable preference for educational institutions and organizations in the Critical Manufacturing, Information Technology, Healthcare and Public Health, Financial Services, and Food and Agriculture sectors." It describes initial access "through a virtual private network (VPN) service without multifactor authentication (MFA) configured, mostly using known Common Vulnerabilities and Exposures (CVEs)", Kerberoasting and domain trust discovery once inside, a Linux variant aimed at VMware ESXi virtual machines and, in a June 2025 incident, payloads aimed at Nutanix AHV hypervisors. The Medusa advisory (AA25-071A, last updated 18 August 2026) counts over 500 victims as of April 2026, lists manufacturing among the affected industries, and says Medusa actors "leverage newly announced exploits within 24 hours."
Canada. The Canadian Centre for Cyber Security's National Cyber Threat Assessment 2025-2026 states that "Ransomware is the top cybercrime threat facing Canada's critical infrastructure", and its Ransomware Threat Outlook 2025-2027 says Akira "has been used to impact industries in manufacturing and telecommunications globally and in Canada."
Read together, the sources describe one path. Entry comes through the IT side: exploited edge devices and VPNs, stolen or weak credentials, phishing. The spread runs through Active Directory and the hypervisors that host it. Production is at risk once ransomware reaches the Windows hosts that run or schedule a line, which Dragos says are misclassified as IT because they run Windows. A penetration test that follows that path, and proves where the boundary between office and plant holds, answers the question the data raises.
What triggers a manufacturing penetration test, and what each trigger asks
The same plant can face four or five of these at once. Read each one for what it actually says, because the wording decides the scope and the evidence.
Trigger | Who it reaches | Does it name a penetration test? | What to scope against it |
|---|---|---|---|
OEM customer audits and TISAX | Automotive suppliers | Named as an example for critical systems where availability protection needs are high (VDA ISA 6, control 5.2.6, marked "(A)") | System audits "from the internet and the internal network", segmentation of office and manufacturing networks (5.2.7) |
CMMC Levels 1 and 2, DFARS 252.204-7012 | Defense suppliers handling FCI or CUI | No | Level 2: periodic assessment of control effectiveness (NIST SP 800-171 3.12.1), with OT documented as Specialized Assets or justified as out of scope. Level 1: the 15 FAR 52.204-21 safeguards; Specialized Assets are outside its scope |
CMMC Level 3 | Defense suppliers whose program requires Level 3 | Yes, CA.L3-3.12.1e, at least annually | Cannot be designated during the 2026 suspension |
CPCSC Levels 1 and 2 | Canadian defence suppliers | No; ITSP.10.171 does not use the word | Security assessment at an organization-defined frequency (03.12.01), which is not one of the 13 Level 1 controls; PSPC says Levels 2 and 3 are under development |
IEC 62443-4-1 | Machine builders and automation vendors that develop products | Yes, SVV-4, for product developers | The product's verification and validation testing |
Cyber insurance applications | Any manufacturer buying cyber cover | Asked about, by type and frequency | Internal and external network, OT segmentation, remote access with MFA |
RFPs and vendor due diligence | Suppliers to larger manufacturers | Depends on the document | Tester accreditation, certifications, references, report format |
OEM customer audits and TISAX
Automotive suppliers meet testing requirements through their customers. TISAX is the assessment and exchange mechanism the ENX Association runs for the automotive industry, and its catalogue is the VDA Information Security Assessment (ISA), which the ENX portal distributes free of charge. Two controls in ISA 6 shape a supplier's test.
Control 5.2.6 asks: "To what extent are IT systems and services technically checked (system and service audit)?" Its "should" requirements call for regular system or service audits "carried out by qualified personnel", using suitable tools such as vulnerability scanners and "performed from the internet and the internal network". For high protection needs it adds: "For critical IT systems or services, additional system or service audit requirements have been identified and are fulfilled (e.g., service specific tests and tools and/or human penetration tests, risk-based time intervals) (A)". That line is marked "(A)" for availability: the TISAX Participant Handbook applies it under the Info high, Info very high, High availability and Very high availability objectives, but not under Confidential or Strictly confidential, which take only the lines marked "C". Info high and Info very high could be selected only until 31 March 2024, so for a new assessment the example applies when the label you need is High availability or Very high availability.
Control 5.2.7 requires that "Requirements regarding network segmentation are determined and fulfilled." Its considerations for risk-based segmentation include "Separation of networks with different operational purpose (e.g. test and development networks, office network, manufacturing networks)", and its high protection requirements name "wireless and remote access" as specific risks. ISA 6 also brought operational technology into scope: its definition of an IT system lists "industrial automation and control system, OT devices, IoT" among the examples.
The ISA's own definitions separate "must" requirements from "should" requirements and from the additional requirements that apply at high and very high protection needs, so read which column a line sits in before treating it as mandatory. The label you need sets the level of scrutiny: the TISAX Participant Handbook maps high protection objectives such as "Confidential" and "High availability" to assessment level 2, a plausibility check of your self-assessment with evidence and an interview, and very high objectives such as "Strictly confidential" and "Very high availability" to assessment level 3, a comprehensive verification that includes observing local conditions. ENX says ISA2027 "will be the basis of TISAX Assessments ordered from 2027" and that "the final date to open an initial assessment under ISA6 is March 2027"; controls 5.2.6 and 5.2.7 carry into ISA2027 with minor rewording.
Beyond TISAX, each OEM can add its own requirements through supplier contracts and portal documents. One shared reference is the Automotive Industry Action Group's "Cyber Security 3rd Party Information Security" guideline, which AIAG says came out of an initiative "to create a common set of cybersecurity expectations for OEMs and their automotive trading partners" and was drafted by information security leaders and executives from GM, Ford, FCA and Honda. It is a paid publication, so its testing language could not be checked for this guide. When a customer audit asks for a penetration test, ask for the clause, its scope and the evidence format before buying anything.
One clarification for anyone searching for an "automotive pentest": testing the vehicle itself is a different discipline. UN Regulation No. 155 requires the vehicle manufacturer to "perform, prior to type approval, appropriate and sufficient testing to verify the effectiveness of the security measures implemented" (paragraph 7.3.6) and to show how its cyber security management system manages dependencies with contracted suppliers (7.2.2.5). Testing ECUs, telematics units and in-vehicle networks is specialist product security work, separate from the enterprise and plant testing in this guide.
CMMC and DFARS for defense supply chains
For defense suppliers the contract clause comes first. DFARS 252.204-7012, in the text issued with Class Deviation 2026-O0025, requires "adequate security" on covered contractor information systems, which for a contractor's own systems (those not operated on behalf of the Government) means the security requirements in NIST SP 800-171 Revision 2, and it requires cyber incidents to be rapidly reported, defined as "within 72 hours of discovery". CMMC, codified at 32 CFR part 170 and placed in contracts by DFARS 252.204-7021, assesses contractors at three levels: Level 1 for Federal Contract Information, Level 2 for CUI against NIST SP 800-171 Revision 2, and Level 3, which adds 24 requirements selected from NIST SP 800-172.
Only Level 3 requires a penetration test. The word "penetration" appears once in the eCFR text of part 170, current to 30 September 2026, in requirement CA.L3-3.12.1e: "Conduct penetration testing at least annually or when significant security changes are made to the system, leveraging automated scanning tools and ad hoc tests using subject matter experts." Level 2 requirements "are identical to the requirements in NIST SP 800-171 R2", and neither Revision 2 nor Revision 3 of NIST SP 800-171 contains the word. Requirement 3.12.1 asks contractors to "Periodically assess the security controls in organizational systems to determine if the controls are effective in their application", and NIST SP 800-171A lists "conducting penetration testing of key system components" among the typical assessor actions under its TEST method. At Level 2, a test is the practical evidence for effectiveness, not a mandate.
OT is a Specialized Asset or out of scope. Part 170 lists Operational Technology and Industrial Internet of Things devices among Specialized Assets, which at Level 2 are assets that "can process, store, or transmit CUI but are unable to be fully secured". They must be documented in the asset inventory, the system security plan and the network diagram of the assessment scope, and they are not assessed against the other CMMC requirements. At Level 1, Specialized Assets are not part of the assessment scope at all. Plant systems that cannot process, store or transmit CUI and are physically or logically separated from CUI assets can be Out-of-Scope Assets, and the contractor must be prepared to justify that. Either way the boundary is the testable claim: a segmentation test shows whether the CUI enclave and the plant networks are separated the way the diagram says.
Status on 2 October 2026. On 13 July 2026 the Department of War Chief Information Officer suspended the move to CMMC Phase 2. The implementing memorandum from the Under Secretary of War for Acquisition and Sustainment, dated the same day, says "The upcoming November 2026 transition to Phase 2 of CMMC implementation is suspended", that requiring activities "may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during this period", and that the requirements of DFARS 252.204-7012 "remain in effect". Class Deviation 2026-O0025, Revision 3, signed on 3 September 2026, directs contracting officers to collaborate with requiring activities to remove or revise CMMC requirements accordingly and keeps the prescription that puts the CMMC clause in solicitations and contracts "On or after November 10, 2028" wherever contractor information systems will process, store or transmit FCI or CUI. Part 170 still requires a senior Affirming Official to affirm continuing compliance after every assessment "and annually thereafter" (32 CFR 170.22).
For a supplier that handles CUI, that means a Level 2 self-assessment whose score has to hold up, and a test of the enclave and its boundary is the evidence behind it. Our CMMC penetration testing requirements guide covers the level-by-level detail, and the CMMC Level 2 self-assessment guide covers the evidence an assessor will ask for.
CPCSC for Canadian defence suppliers
Canadian defence suppliers face the Canadian Program for Cyber Security Certification. Public Services and Procurement Canada's program overview, last modified 29 September 2026, sets out three levels, with Level 1 launched in April 2026: an annual self-assessment of 13 controls at Level 1; external assessments led by an accredited certification body, plus an annual affirmation, for 98 controls at Level 2; and assessments conducted by National Defence, plus an annual affirmation, for "130+" controls at Level 3. PSPC adds that "Levels 2 and 3 are currently under development." The controls come from the Cyber Centre's ITSP.10.171, which PSPC says is closely adapted from NIST SP 800-171 and SP 800-172. ITSP.10.171 does not use the word "penetration"; its requirement 03.12.01 asks organizations to assess their security and privacy requirements at an organization-defined frequency, and 03.12.01 is not one of the 13 Level 1 controls. Suppliers that sell to both governments should read our CMMC and CPCSC guide for Canadian defence suppliers.
IEC 62443 for asset owners, integrators and machine builders
IEC 62443 is a series, and who it applies to depends on your role. The ISA describes its stakeholder groups as "asset owners (end users), automation product suppliers, integrators who build and maintain control system solutions and their components, and service suppliers who support the operation of control systems." A plant that operates equipment is an asset owner, addressed by 62443-2-1, security program requirements for asset owners; 62443-3-2 covers security risk assessment for system design, and integrators and service providers are addressed by 62443-2-4.
A machine builder or automation vendor that develops products falls under 62443-4-1. The IEC describes it as specifying "the process requirements for the secure development of products used in industrial automation and control systems", and adds that "these requirements only apply to the developer and maintainer of the product, and are not applicable to the integrator or the user of the product." The published table of contents of the ANSI/ISA edition shows that Practice 5, security verification and validation testing, includes "SVV-4: Penetration testing" and "SVV-5: Independence of testers". The requirement text sits in the paid standard and was not reviewed for this guide. For a machine builder, the parts of that testing that cover a companion web application, a customer portal or a cloud service are application testing; device firmware and industrial protocol testing is specialist product work.
NIST SP 800-82 Rev. 3: the guidance OT engineers will hold you to
NIST SP 800-82 Revision 3, the Guide to Operational Technology (OT) Security published in September 2023, is guidance rather than a mandate, but it is the document a plant's OT engineers are most likely to hold a test plan against. Its OT discussion of penetration testing (control CA-8) reads: "Penetration testing is used with care on OT networks to ensure that OT functions are not adversely impacted by the testing process." It names "employing a replicated, virtualized, or simulated system" as a compensating control, says that when OT systems are taken offline for testing, "tests are scheduled to occur during planned OT outages whenever possible", and adds: "If penetration testing is performed on non-OT networks, extra care is taken to ensure that tests do not propagate into the OT network."
On discovery it is blunter: "OT network owners should exercise extreme caution when permitting active scanning on an operational network due to device sensitivity on the target network." Its incident examples explain why. A ping sweep on an active SCADA network made a robotic arm swing around 180 degrees; another ping sweep hung a system controlling integrated circuit production and destroyed $50,000 worth of wafers; and an IT consultancy testing a natural gas utility's corporate network "carelessly ventured into a part of the network that was directly connected to the SCADA system", locking up the SCADA system so that the utility could not send gas through its pipelines for four hours. The CMMC rule incorporates SP 800-82 Rev. 3 by reference for its definitions, so defense suppliers will meet it there too.
Cyber insurance applications
Insurers ask about testing and about the OT boundary on the form you sign. Three published applications show the pattern.
Form | What it asks |
|---|---|
AXIS Insurance: Cyber Technology & MPL Application, form AXIS 1012098 0623 | Section 2.4: whether the network includes "OT/ICS/SCADA" systems that store or process critical information or support critical business processes. Section 5.2, "Pen Testing": whether the applicant "conducts regular penetration testing", by type (external network, internal network, social engineering, physical, web application) and frequency (quarterly, twice a year, annually, ad hoc or never), and whether testing is internal or outsourced. Section 5.13: which network segmentation exists, with "OT" as an option, and how it is accomplished |
The Hanover Insurance Company: Ransomware Supplemental Questionnaire, form 114-10174 (1/22) | "Is your operational technology environment segmented from your information technology environment(s)?", and how (firewalls, VLANs, unidirectional security gateways, DMZs); whether OT is segmented from the internet; whether employees and third parties may access the OT environment remotely and, if so, whether MFA is enforced |
Beazley Insurance Company: Ransomware Supplemental Application, form F00765 (05/2022 edition) | "How often do you (or a third party on your behalf) conduct penetration testing on your network?", with never or not regularly, annually, two to three times a year, and quarterly or more often as the options |
A test that covers the internal network, the OT boundary and remote access gives you evidence for those answers, and the AXIS form, with its five named testing types each on its own frequency ladder, shows why a single external test does not answer the question. Our guide to what cyber insurance underwriters actually ask covers how to present it at renewal.
RFPs and vendor due diligence
RFPs and due-diligence questionnaires from larger manufacturers and their customers can specify the tester as well as the test: an accredited firm, certified testers, references in the sector, a redacted sample report and professional liability insurance. Treat those lines as scoping inputs. The buyer checklist below turns them into questions a provider has to answer in writing.
What to test in a plant environment
The test follows the attack path described above, from the internet to the edge of the plant, and stops at the controllers.
Area | What the test covers | Why it is in scope |
|---|---|---|
External perimeter | VPN concentrators and SSL VPN portals, vendor and integrator remote access gateways, remote support tools, file transfer appliances, any exposed remote desktop, mail and DNS | Akira's initial access through VPNs without MFA; Medusa's exploitation of newly announced vulnerabilities within 24 hours; Verizon's Manufacturing initial access vector breakdown: "Exploitation of vulnerabilities (38%)" |
Internal network and Active Directory | Lateral movement from an office workstation, privilege escalation to domain admin, Kerberos and delegation paths, file shares, trusts between office and plant domains, and the management planes of backup and virtualization | Akira's Kerberoasting, domain trust discovery and hypervisor targeting |
IT/OT segmentation | Every path from the office network to the plant DMZ, jump hosts, historians, engineering workstations and OT subnets, tested against a written matrix, with reachability checks only beyond the DMZ | NIST SP 800-82 Rev. 3 firewall and DMZ guidance; VDA ISA 5.2.7; the Hanover and AXIS segmentation questions |
Plant Wi-Fi | Corporate, guest and plant wireless networks at each site, where each one lands, and rogue access points | VDA ISA 5.2.7 names wireless and remote access as specific risks |
ERP, MES and portals | Authenticated testing of ERP and MES web front ends and supplier and customer portals across every user role | In Manufacturing, System Intrusion, Social Engineering and Basic Web Application Attacks "represent 91% of breaches" (Verizon 2026 Data Breach Investigations Report) |
Phishing and vishing | Office staff and plant staff, including shift supervisors and maintenance teams who may sit outside the office awareness program | Verizon's Manufacturing initial access vector breakdown: "Phishing (13%)"; the AXIS form has a social engineering row |
Physical security | Site entry, badge controls, unattended network ports in production areas, where scoped | The AXIS form asks how often physical testing is done |
Each area maps to a service line: internal and external network testing, an Active Directory assessment, a Wi-Fi security assessment run on site or with a device shipped to the plant, web application testing for ERP, MES and portals, phishing campaigns and physical security assessments. The detail of an internal scope, start positions and deliverables is in our guide to internal network penetration testing.
How to test IT/OT segmentation without touching production

NIST SP 800-82 Rev. 3 recommends grouping OT components into levels, tiers or zones and names the Purdue model as one industry-recognized way to do it. Its example architecture puts devices "typically found in the Purdue model levels 0, 1, and 2" in a field level, "the Purdue level 3 components" in an operations management level, and a DMZ between operations management and the enterprise network that supports "bridging the operations management and enterprise tiers". The same guide supplies the specification a segmentation test checks:
Firewall rulesets "should be established to only permit connections between adjacent levels, tiers, or zones."
Organizations using a Purdue model architecture "should implement firewall rules and connection paths that prevent Level 4 devices from directly communicating with Level 2, 1, or 0 devices."
"Any communications between the enterprise level and the operations management level are required to go through services within the DMZ."
Organizations "should consider making outbound rules as stringent as inbound rules."
CISA, the FBI, the EPA and the Department of Energy make two related points in their May 2025 fact sheet on primary mitigations for OT: "Segment IT and OT networks", and where remote access to OT is essential, use virtual private network functionality "with a strong password and phishing-resistant multifactor authentication (MFA) for user remote access."
A segmentation test turns those statements into a pass or a fail, path by path. Agree a matrix before testing starts, then test from the IT side.
Tester start position | Destination | Intended policy | What the test records |
|---|---|---|---|
Office user network | Plant DMZ services (remote access gateway, patch and file transfer services, historian replica) | Named services only | Reachable ports against the named set, and the authentication outcome on each |
Office user network | Site operations zone (Level 3: historians, engineering workstations, MES servers) | No direct path; through the DMZ only | Any direct route or open service, and whether a listener in the zone is reached |
Office user network | Control zones (Levels 1 and 2) | No access | Whether a listener placed by the OT team is reached; no traffic sent to controllers |
Vendor or integrator VPN | Jump host in the plant DMZ | MFA, named accounts, logged sessions | MFA enforcement, shared accounts, session logging and onward reach |
Corporate and guest Wi-Fi at the plant | Office and plant segments | Guest: internet only. Corporate: office only | Routes and services reachable from each wireless network |
Listener device in each plant zone, placed and run with the OT team | Office network and internet (outbound) | Deny except named flows | Which outbound connections from the listener succeed |
Four practices keep the test useful and safe.
Use listeners, not controllers, as targets. The OT team places a small laptop or virtual machine in each protected zone, and the tester tries to reach it from each start position. A reached listener proves the path exists without a packet ever being aimed at a PLC or HMI.
Read the rules as well as testing them. A review of the firewall rules between office, DMZ and plant zones finds the "any to any" exception that a reachability test from one start position can miss.
Look for the paths that skip the firewall. Dual-homed engineering workstations, shared file shares and historians, backup and virtualization management networks that span both sides, and Active Directory trusts between office and plant domains are the bypasses to look for.
Treat a reached control zone as a finding, not a foothold. If a listener in a control zone answers, the tester stops that path, reports it immediately and goes no further without the plant contact's agreement.
The method is the same whether the driver is a TISAX label, a CMMC enclave boundary or an insurer's segmentation question, and the result is one matrix that answers all three.
Safe testing rules for production
The rules of engagement are where a plant decides what the test may and may not do. NIST SP 800-172, the source of CMMC's Level 3 testing requirement, puts it plainly: "All parties agree to the specified rules of engagement before the commencement of penetration testing." For a manufacturer the rules should cover at least the following.
A written exclusion list. Every PLC, HMI, safety instrumented system, controller and field device network is listed as out of bounds for active scanning and exploitation. Industrial protocols are excluded from the IT-side test.
Named people with stop authority. An OT engineer or plant manager who can stop the test at any moment, a named tester on a live channel throughout, and an IT contact who can change a firewall rule or restore a service.
Business hours, staff on site, for IT-side work. Testing of the perimeter, the office network and Active Directory runs in agreed business hours with plant staff present, so any anomaly is seen and handled at once. For anything that probes past the DMZ, SP 800-82 Rev. 3 advises that active scans of an operational OT network "should be scheduled to occur during planned OT outages whenever possible", so agree in writing which reachability checks run in business hours and which wait for an outage.
A light touch on hypervisors and OT-adjacent subnets. Management interfaces are identified and checked for exposure and authentication; no power operations, no snapshot changes and no exploitation that risks availability.
Rate limits and no denial of service. Discovery is throttled, nothing is flooded, and accounts are not locked out on purpose.
Stop conditions agreed in advance. Any unexpected behavior on a production system, an alarm on the plant floor, a request from the named OT contact, or a listener answering inside a control zone stops the relevant work until the plant contact agrees to resume.
Evidence handling. How credentials, hashes and network diagrams collected during the test are stored, transmitted and destroyed, and who receives the report.
Put the exclusions, windows and stop authority in the statement of work, not only in an email thread, so they bind both sides.
What Stingrai tests, and what it leaves to OT specialists
Stingrai tests the IT side of a manufacturer and the boundary into the plant: internal and external networks, Active Directory, cloud, the ERP, MES and portal web applications, Wi-Fi, phishing and vishing, physical entry, and the segmentation between IT and OT, all under the rules of engagement above. Controller-level OT testing, meaning PLCs, HMIs, safety instrumented systems and industrial protocols, is a specialist discipline that Stingrai does not publish as a service. Pair it with your OT vendor or an OT specialist: the segmentation results from the IT-side test show that specialist where the boundary is weak, and the two reports together cover the estate. Our ranking of manufacturing penetration testing companies lists providers by the scope they publish.
Scoping inputs and cost
A manufacturing quote is built from a handful of inputs. Have them ready before the scoping call and the proposal will be precise rather than padded.
Input | Why it moves effort | What to give the tester |
|---|---|---|
Live hosts and IP ranges | Enumeration scales with responsive hosts, not allocated address space | External IPs and domains; internal ranges with a live-host estimate per site |
Plants and sites | Each site needs a start position, logistics and possibly on-site days | Site list, which sites are in scope, on-site or remote access |
Active Directory domains | Identity work scales with domains, forests, trusts and object counts | Domain and forest names, trusts, user and computer counts |
Segmentation pairs | Each IT-to-OT path tested is a unit of work | The matrix: source zones, destination zones, intended policy |
Remote access paths | Each VPN, vendor gateway and remote support tool is tested separately | The list of paths, who uses each and whether MFA is enforced |
Web applications | ERP, MES and portals are each their own scope | URLs, roles, test accounts and API documentation |
Wi-Fi | Assessed per site and per network | Wireless networks per plant and on-site availability |
People and physical | Campaign size and site visits | Target population, pretext limits, sites for physical entry |
Retest and reports | Retest window and report formats add effort | Who needs what: customer audit, insurer, CMMC or TISAX file |
Stingrai's published planning bands put a network test, external or internal, at US$5,000 to US$40,000 and a web application test at US$5,000 to US$30,000, with the annual testing budget of a mid-market organization (150 to 500 employees) at US$20,000 to US$50,000, in our 2026 penetration testing cost guide. In Canada, our Canadian cost guide puts a standard external network test at CA$15,000 to CA$35,000, a standard internal network test at CA$20,000 to CA$35,000 and a standard Active Directory assessment at CA$25,000 to CA$35,000, with complex scopes above those ranges. Where a plant lands depends on sites, live hosts, domains and segmentation pairs. Our internal network guide describes a single site with one domain, a few hundred live hosts and one or two start positions as commonly around a working week of field time plus reporting and quality assurance, while two or three sites with a segmentation matrix run materially longer and a multi-domain forest across many sites is usually phased.
Stingrai's own published prices cover web applications only. An Autonomous Pentest, in which Snipe, Stingrai's autonomous agent for web applications and their APIs, tests alone, is at US$3,000 per assessment or US$650 per month. A Hybrid Pentest, in which Stingrai's penetration testers and Snipe test together throughout, is at US$6,800 per assessment or US$1,275 per month. The monthly prices are for 12-month continuous programs. Each package covers exactly one web application and its APIs, such as a customer portal or an ERP front end. The "No High or Critical Finding = Don't Pay" guarantee applies to the Autonomous tier only. Networks, Active Directory, segmentation, more applications, Wi-Fi, social engineering, physical and red team work are quoted through get a quote. Current figures are on the pricing page.
How to scope a manufacturing penetration test
Eight steps take a plant from a customer's request to a test it can defend.
Name the trigger and the evidence it needs. Write down the TISAX label and controls, the CMMC or CPCSC level and enclave, the insurer's questions or the OEM clause, and what each expects to see in the report.
Inventory the attack paths, not just the hosts. List external IP ranges and domains, every VPN and remote access path, Active Directory domains and trusts, sites, wireless networks and the ERP, MES and portal applications.
Draw the zones and write the segmentation matrix. Group the plant into levels or zones as NIST SP 800-82 Rev. 3 describes, then list every source and destination pair with its intended policy.
Agree the OT exclusions and the rules of engagement. Exclude controllers, HMIs, safety systems and industrial protocols, name the people with stop authority, set business-hours windows with staff on site, and place listeners in protected zones.
Choose the start positions. Typically the internet, an unauthenticated device on the office network, a standard domain user and a vendor remote access account.
Add applications, Wi-Fi, people and physical where the trigger asks. Match each addition to a line in the customer, insurer or certification document.
Decide between one-time and continuous, and book the retest. An annual test fits a stable estate; portals and applications that change monthly fit a continuous program.
Set the report formats before the test starts. Agree the full report, the executive summary, the attestation letter, the scope statement with its exclusions, the segmentation matrix results and any mapping to customer or insurer questions.
Buyer checklist and RFP questions
Put these questions in the RFP and ask for written answers.
Accreditation. Is the firm CREST-accredited as a penetration testing service provider, and is it listed on the CREST Marketplace?
Named testers. Who are the named testers, what certifications does the team hold (for example OSCP, OSCE³, OSWE or CREST CRT), and are the people in the proposal the people on the engagement?
Sector experience. References from manufacturers or industrial organizations, and a redacted sample report from a comparable scope.
Rules of engagement for production. A written OT exclusion list, named stop authority, business-hours testing with staff on site, and a description of how segmentation is tested without touching controllers.
Segmentation method. Will every pair in your matrix be tested and reported as a pass or a fail?
OT pairing. If controller-level testing is needed, who does it, and how do the two reports fit together?
Retest. Is retesting included, within what window, and does it produce a dated record?
Findings workshop. A readout with IT, plant engineering and management together, so fixes are agreed between the people who own each side of the boundary.
Report formats. A full technical report, an executive summary, an attestation or completion letter, a scope statement listing exclusions, segmentation results and mapping to the customer or insurer questions.
Data handling and insurance. How evidence and credentials are stored and destroyed, and what professional liability cover the firm carries.
Delivery model. A price for a one-time annual engagement and a price for a continuous program.
Proposals that answer these questions differently are not comparable on price alone, so normalize them against your scoping inputs first.
What the report should include for a customer audit or insurer
The audience decides the format. A customer auditor, an insurer and a CMMC or TISAX file each need proof of the same test, at different depths.
An attestation or completion letter naming the firm, the testers, the dates, the scope and the retest status. It is the document to send a customer or insurer that asks for proof of testing.
A scope statement listing what was tested from the internet and from inside the network, the start positions, the segmentation pairs and the explicit exclusions, with the reason for each. An excluded controller network should read as a decision, not an omission.
Methodology naming the standards followed and both the automated tooling and the manual testing performed.
Findings with severity, evidence, affected assets and remediation guidance at configuration level.
Segmentation results, path by path, against the intended policy.
A remediation and retest record, dated after the fixes.
An executive summary a plant manager, a customer and an underwriter can read.
A mapping to the questions that triggered the test, such as VDA ISA 5.2.6 and 5.2.7, the AXIS sections 5.2 and 5.13, or NIST SP 800-171 requirement 3.12.1.
Send the letter and scope statement outside the company and keep the full technical report inside it. Our comparison of a completion letter and a full report explains which audience should get which.
How often to test
No single cadence covers every trigger. The AXIS form asks for a frequency per test type, on a ladder from quarterly to never. The VDA ISA asks for regular audits and, for critical systems where availability needs are high, "risk-based time intervals". CMMC Level 3 says at least annually or when significant security changes are made, and at Level 2 the annual affirmation is the practical clock. A workable pattern for a plant is an annual test of the perimeter, internal network, Active Directory and segmentation, a fresh test after any significant change (a new plant, a new remote access path, an ERP or MES migration, an acquisition or a network redesign), and continuous testing for customer-facing applications that change month to month. Stingrai runs both one-time annual engagements and continuous programs.
How Stingrai supports manufacturers
Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.
For a manufacturer, that translates into a test built around the boundary between office and plant. The external perimeter is tested including the VPNs, vendor gateways and remote support tools that integrators use; the internal network is tested from an office start position through lateral movement, Active Directory ACL abuse and Kerberos and delegation paths to domain admin; and the segmentation matrix is tested path by path from the IT side, with listeners in protected zones and no traffic aimed at controllers. ERP, MES and portal applications are tested authenticated across every user role for broken authorization and business logic flaws, plant Wi-Fi is assessed on site or with a device shipped to the plant, and phishing, vishing and physical entry are added where a customer or insurer asks for them.
Two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP certifications staff every human-led engagement, reviewed by the team lead and an engagement partner, and the team has 18 published CVEs. Findings post to the PTaaS portal as they are confirmed, each with a working proof of concept and prioritized remediation guidance, with live chat to the testers and Jira and Slack integration. Retesting is included, human-led and hybrid engagements include an attestation letter, and Stingrai is rated 5.0 on Clutch from 20 reviews. Engagements run as a one-time annual test or as a continuous program. The firm-level accreditation is listed on the CREST Marketplace. Stingrai's penetration testing supports your CMMC, TISAX and cyber insurance submissions by producing the testing evidence each one asks about.
Frequently Asked Questions
What does a manufacturing penetration test cover?
It covers the systems an attacker uses to reach production: the external perimeter including VPNs and vendor remote access, the internal network and Active Directory, a segmentation test of every path from the office network into the plant DMZ and OT zones, plant Wi-Fi, and the ERP, MES and portal applications. Phishing and physical entry are added when a customer, insurer or RFP asks for them. Controllers, HMIs and safety systems are not actively scanned or exploited in production; NIST SP 800-82 Rev. 3 says penetration testing "is used with care on OT networks."
Does CMMC require a penetration test?
Only at Level 3. Requirement CA.L3-3.12.1e at 32 CFR 170.14(c)(4)(xx) says to conduct penetration testing "at least annually or when significant security changes are made to the system," and Level 3 cannot be designated during the suspension that began on 13 July 2026. Levels 1 and 2 do not require a test, and NIST SP 800-171 does not contain the word "penetration", but requirement 3.12.1 asks for periodic assessment of whether controls are effective, and NIST SP 800-171A lists penetration testing of key system components among typical assessor actions. DFARS 252.204-7012 remains in effect.
Should we pentest the OT network?
Not the controllers in production. Test the IT side and the boundary into OT: whether the office network can reach the plant DMZ, jump hosts, historians, engineering workstations and control zones. NIST SP 800-82 Rev. 3 says penetration testing "is used with care on OT networks" and names replicated, virtualized or simulated systems as compensating controls, with planned outages for testing that takes OT offline. That work is specialist OT testing, so pair it with your OT vendor or an OT specialist. Stingrai tests the office side and the segmentation boundary and does not publish controller-level OT testing as a service.
How do you test IT/OT segmentation without disrupting production?
Agree a matrix of source and destination zones with the intended policy for each, then test from the IT side only. The OT team places listeners in protected zones so that reachability is proven without traffic aimed at a PLC or HMI, the firewall rules between zones are reviewed, and dual-homed hosts, shared services and domain trusts are checked for paths that skip the firewall. IT-side testing runs in business hours with plant staff on site and a named contact who can stop it, and the rules of engagement say in writing which checks past the DMZ wait for a planned outage. NIST SP 800-82 Rev. 3 adds that when penetration testing is performed on non-OT networks, "extra care is taken to ensure that tests do not propagate into the OT network."
What do automotive customers ask suppliers for?
TISAX is the shared mechanism: suppliers are assessed against the VDA ISA catalogue, and OEM supplier contracts can add their own requirements. ISA 6 control 5.2.6 asks for regular system audits performed "from the internet and the internal network" and names human penetration tests as an example for critical systems where availability protection needs are high (the availability labels and the older Info labels, not Confidential). Control 5.2.7 asks for network segmentation, including separation of office and manufacturing networks. ENX says ISA2027 will be the basis of assessments ordered from 2027. Testing the vehicle itself is a separate product discipline; UN Regulation No. 155 sets cyber security requirements for vehicle type approval in the countries that apply it.
Does cyber insurance require a pentest for manufacturers?
The published applications reviewed for this guide ask about testing and segmentation rather than make a test a condition of cover. The AXIS Cyber Technology & MPL Application, form AXIS 1012098 0623, asks whether the applicant conducts regular penetration testing, by type and frequency, and which network segmentation exists, with OT as an option. The Hanover Ransomware Supplemental Questionnaire, form 114-10174 (1/22), asks whether the operational technology environment is segmented from IT and from the internet, and whether remote access to it uses MFA. A test of the internal network, the OT boundary and remote access gives you evidence for those answers.
How much does a manufacturing penetration test cost?
It depends on live hosts, sites, Active Directory domains, segmentation pairs and applications. Stingrai's published planning bands put a network test at US$5,000 to US$40,000 and a web application test at US$5,000 to US$30,000; in Canada, a standard internal network test is CA$20,000 to CA$35,000 and a standard Active Directory assessment CA$25,000 to CA$35,000. Stingrai's published prices cover one web application and its APIs, at US$3,000 per assessment or US$650 per month for an Autonomous Pentest and US$6,800 per assessment or US$1,275 per month for a Hybrid Pentest, the monthly prices on 12-month continuous programs, and network, segmentation and multi-site scopes are quoted.
How often should a manufacturer run a penetration test?
At least annually for the perimeter, internal network, Active Directory and segmentation, and again after any significant change such as a new plant, a new remote access path, an ERP or MES migration or an acquisition. CMMC Level 3 sets at least annually or after significant change, the AXIS application asks for a frequency per test type, and the VDA ISA asks for regular audits, with risk-based intervals for critical systems where availability needs are high. Customer-facing applications that change month to month suit a continuous program.
What should the report include for a customer audit?
An attestation or completion letter naming the firm, testers, dates, scope and retest status; a scope statement listing what was tested, the start positions, the segmentation pairs and the excluded OT systems with reasons; the methodology; findings with severity, evidence and remediation; segmentation results path by path; a dated retest record; and an executive summary. Map the results to the questions that triggered the test, such as VDA ISA 5.2.6 and 5.2.7 or the insurer's form. Share the letter and scope statement, and keep the full technical report inside the company.
Related reading
References
IBM. IBM 2026 X-Force Threat Index: AI-Driven Attacks are Escalating as Basic Security Gaps Leave Enterprises Exposed. 25 February 2026. https://newsroom.ibm.com/2026-02-25-ibm-2026-x-force-threat-index-ai-driven-attacks-are-escalating-as-basic-security-gaps-leave-enterprises-exposed.
Dragos. Dragos 2026 OT/ICS Cybersecurity Report and Year in Review, press release. 17 February 2026. https://www.dragos.com/resources/press-release/dragos-2026-year-in-review-new-ot-threats-ransomware.
Verizon. Verizon 2026 Data Breach Investigations Report. 19 May 2026. https://www.verizon.com/dbir.
CISA, FBI and partners. #StopRansomware: Akira Ransomware, AA24-109A. Last revised 13 November 2025. https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-109a.
CISA, FBI and HHS. #StopRansomware: Medusa Ransomware, AA25-071A. Last updated 18 August 2026. https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a.
Canadian Centre for Cyber Security. National Cyber Threat Assessment 2025-2026. Modified 30 October 2024. https://www.cyber.gc.ca/en/guidance/national-cyber-threat-assessment-2025-2026.
Canadian Centre for Cyber Security. Ransomware Threat Outlook 2025-2027. Information as of 4 September 2025; modified 28 January 2026. https://www.cyber.gc.ca/en/guidance/ransomware-threat-outlook-2025-2027.
ENX Association and VDA. Information Security Assessment (ISA) 6 and ISA2027, TISAX downloads. https://portal.enx.com/en-us/TISAX/downloads/.
ENX Association. TISAX Participant Handbook, version 2.8. 13 March 2025. https://portal.enx.com/handbook/TISAX%20Participant%20Handbook.pdf.
Automotive Industry Action Group. AIAG's New Cybersecurity Guidelines Publication Has Arrived! 3 May 2018. https://blog.aiag.org/aiags-new-cybersecurity-guidelines-publication-has-arrived.
UNECE. UN Regulation No. 155, Cyber security and cyber security management system, E/ECE/TRANS/505/Rev.3/Add.154. 4 March 2021. https://unece.org/transport/documents/2021/03/standards/un-regulation-no-155-cyber-security-and-cyber-security.
Office of the Federal Register. 32 CFR part 170, Cybersecurity Maturity Model Certification Program, eCFR, current to 30 September 2026. https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170.
Under Secretary of War for Acquisition and Sustainment. Implementing Department of War Chief Information Officer's Suspension of the Advancement to CMMC Phase 2 Requirements. 13 July 2026. https://dowcio.war.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdf.
Defense Pricing, Contracting, and Acquisition Policy. Class Deviation 2026-O0025, Revision 3, Revolutionary FAR Overhaul Part 40, DFARS Part 240. Signed 3 September 2026. https://www.acq.osd.mil/dpap/dars/classdev/DFARS_RFO/Part-240/2026-O0025_Rev3_TAB_A_Deviation_Memo.pdf.
National Institute of Standards and Technology. SP 800-171 Revision 2 (February 2020) and Revision 3 (May 2024), Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r2.pdf and https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r3.pdf.
National Institute of Standards and Technology. SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information. June 2018. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171A.pdf.
National Institute of Standards and Technology. SP 800-172, Enhanced Security Requirements for Protecting Controlled Unclassified Information. February 2021. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-172.pdf.
National Institute of Standards and Technology. SP 800-82 Revision 3, Guide to Operational Technology (OT) Security. September 2023. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r3.pdf.
Public Services and Procurement Canada. Canadian Program for Cyber Security Certification: program overview. Modified 29 September 2026. https://www.canada.ca/en/public-services-procurement/services/industrial-security/security-requirements-contracting/cyber-security-certification-defence-suppliers-canada/program-overview.html.
Canadian Centre for Cyber Security. Protecting specified information in non-Government of Canada systems and organizations (ITSP.10.171). Modified 28 October 2025. https://www.cyber.gc.ca/en/guidance/protecting-specified-information-non-government-canada-systems-and-organizations-itsp10171.
International Society of Automation. ISA/IEC 62443 Series of Standards and ANSI/ISA-62443-4-1-2018 table of contents. https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards and https://www.isa.org/getmedia/99afef02-46b1-4d75-9b46-4c4531fd1c34/isa-62443-4-1-toc.pdf.
International Electrotechnical Commission. IEC 62443-4-1:2018, Secure product development lifecycle requirements. https://webstore.iec.ch/en/publication/33615.
AXIS Insurance. AXIS Cyber Technology & MPL Application, form AXIS 1012098 0623. https://www.axiscapital.com/docs/default-source/resources/axis-1012098-0623-axis-cyber-technology-mpl-application-7-20-23.pdf.
The Hanover Insurance Company. Ransomware Supplemental Questionnaire, form 114-10174 (1/22). https://sites.hanover.com/linec/docs/114-10174.pdf.
Beazley Insurance Company. Ransomware Supplemental Application, form F00765, 05/2022 edition. https://www.beazley.com/globalassets/product-documents/application/beazley_ransomware_supplemental_052022_ed.pdf.
CISA, FBI, EPA and DOE. Primary Mitigations to Reduce Cyber Threats to Operational Technology. 6 May 2025. https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology.
Stingrai. Pricing. https://www.stingrai.io/pricing. Published one-time and continuous package prices for one web application and its APIs.
Ready to scope a manufacturing penetration test?
The incident that stops a line usually starts in the office: an unpatched VPN, a vendor account without MFA, a domain admin path a few hops long, and a firewall rule that lets the office reach the plant. Stingrai's penetration testing supports your customer audits, CMMC and TISAX evidence and insurance renewals with two named penetration testers on every human-led engagement, a segmentation test run from the IT side under written rules of engagement, retesting, and an attestation letter on human-led and hybrid engagements, as a one-time annual engagement or a continuous program. Book a free scoping call, get a quote for a multi-site network and segmentation scope, or read the published package prices on the pricing page.



