CENSUS
Lateral Movement and OT Estate Hardening
- Embedded security Systems
- IT to OT Security Assessment
- Industrial
- Industrial Protocols
- OT Resillience
- OT Security Solutions
Most OT breaches start in IT, not the plant floor. Here's how to map lateral movement paths and harden your OT estate without disrupting production.
Lateral Movement and OT Estate Hardening
Many successful OT intrusions begin outside the control environment. Attackers enter through corporate IT, remote access, vendor connections, or exposed services, then move laterally toward critical operations using legitimate trust relationships and network paths.
The challenge is not only identifying those paths. In OT, remediation must work around availability, safety, vendor support, legacy equipment, and limited maintenance windows. A vulnerability that would be patched the same week in an enterprise environment may wait months for a maintenance window, or may have no vendor patch at all.
CENSUS approaches this as an engineering problem: identify how critical systems can be reached, design the controls that remove or constrain those paths, implement them, and validate the result.
ASSESS. DESIGN. BUILD.

CENSUS structures OT security engagements across three connected phases. Each phase produces artefacts that the next phase consumes, and the sequence is designed to end in implemented change.
Why OT Discovery Is Passive
OT-facing discovery in production environments is passive by design. CENSUS does not run active scans against control equipment, does not probe controllers, and does not require a planned production interruption.
Passive analysis yields more than is commonly assumed. From mirrored traffic alone it is possible to establish the set of active assets and the services running on them, identify industrial protocols by their content rather than by port assumption, compare actual communication flows between zones against the flows the architecture intended, identify tunnelling and remote access behaviour, and observe which trust relationships are genuinely in use.
Where active validation adds value, it is performed against enterprise and boundary systems, where testing is operationally safe and where the significant paths run in any case. The controller itself is rarely where the assessment question focuses.
CENSUS OT Security Solutions

Four solution pillars define what we deliver. Each pillar can be scoped as an assessment alone, or extended through design and implementation.
Prioritising What Can Actually Be Fixed
OT remediation cannot be prioritised by vulnerability severity alone. A critical-rated issue on an asset that cannot be touched for eight months is less actionable than a boundary change that can be made next week and removes the path to it.
CENSUS considers three factors together:
- Reachability: Does the issue sit on a viable path to an operationally significant asset?
- Feasibility: Can the change be implemented within safety, availability, vendor, and maintenance constraints?
- Exposure reduction: How much of the mapped attack surface will the change remove or constrain?
This may result in segmentation, access restrictions, protocol controls, or other compensating measures being prioritised ahead of patching, where those controls provide a faster and more durable reduction in risk. In an environment where patching is constrained by factors outside the operator's control, a well-specified compensating control is often the more durable answer.
From Finding to Implemented Controls
CENSUS combines offensive security expertise with production-grade engineering across network, system, protocol, and device layers.
Our teams have conducted OT security testing across operational industrial environments, including oil refinery infrastructure and industrial manufacturing facilities. Our researchers hold doctorate-level expertise in ICS and embedded systems security, with hands-on experience across industrial protocols, firmware analysis, and passive OT network instrumentation, including tooling developed internally for industrial protocol identification.
Understanding how an environment can be compromised is only the first part of the problem. The objective is to translate that understanding into controls that can be implemented within operational constraints and validated against the paths they were designed to close.
Where to Start
Most engagements begin with an IT-to-OT Security Assessment. It provides a documented view of how critical systems can be reached, which paths matter most, and which changes can reduce that exposure, without requiring active interaction with control equipment or a planned production interruption.
A summary of this approach is available for download
Lateral Movement And OT Estate Hardening
To discuss a scoped engagement for your environment, contact [email protected].