Short answer: Traditional IT pentesting techniques cannot be applied to SCADA and operational technology (OT) systems; aggressive packets sent by standard security scanners can crash low-compute PLCs, causing production line downtime or mechanical damage.
Audits in industrial networks are conducted in accordance with IEC 62443 principles, relying on passive network sniffing and architecture analysis rather than active packet injection. In the initial phase, firewalls and DMZ configurations between the corporate IT network and the production layer (OT) are tested to verify whether unauthorized lateral movement exists from office workstations to the industrial control layer. Because this step sends zero packets into the production workflow, it poses no downtime risk.
Testing controllers and SCADA in the second phase must never occur during live production hours; it should strictly be scheduled during planned plant maintenance shutdowns or conducted in a test lab using spare hardware. Configuration backups from the live line are loaded onto digital twins or lab hardware to simulate vulnerability assessments there. If testing on a live line is unavoidable, the following rules must be observed: 1) An automation engineer must be on standby at the console throughout testing, 2) Aggressive scanning and exploit modules in standard tools must be completely disabled, 3) Rate-limited, specialized tools sensitive to industrial communications protocols must be used.
An emergency stop protocol to instantly kill the test in the event of unexpected hardware behavior, alongside a clear legal liability framework regarding potential downtime losses, must be defined upfront in your contract.