Highlight-image

A Day in the Life of an OT Pentester

Author: Dominika Rusek Jonkers is Senior Security Specialist at Bureau Veritas Cybersecurity. She brings over 10 years of expertise in industrial cybersecurity. Her extensive experience spans technical assessments of Industrial Control Systems (ICS), penetration testing, Tactical Network Exploitation (TNE) and executing remediation programs. Read more about Dominika.

"The day begins early, coffee in hand, as I set off toward a manufacturing site. The drive is my planning moment - mapping the day ahead and catching up on the latest news via a podcast. Today’s mission - an operational technology (OT) security assessment for a client looking to modernize and secure their production network."

Highlight-image

Arrival and First Impressions

"I pull into the parking lot, complete the mandatory safety test, collect my visitor badge, and spot my colleague. Together, we meet the plant manager. The opening conversation sets the tone, they are concerned about their network segmentation and they lack of oversight of who is responsible for which part of OT security, along with the growing pressure from corporate headquarters to strengthen security."

Highlight-image

Connecting to the OT Network

"We configure the monitoring probe to passively capture network traffic and we walk to the control room to plug it into the OT switch. Soon, data begins to flow, revealing the first hints of this complex ecosystem.

While the initial capture runs, we engage with the on-site engineer - the heroes who keep this place going. They walk us through the criticality of various systems on the OT network, remote connection practices, backup routines, and known quirks of the network. Their insights help us prioritize our penetration testing toward the most impactful targets and, later, tie vulnerabilities to real operational risk.

With the scope agreed upon and initial insights from the monitoring probe, we unpack our gear. With the plant team’s approval, we connect our laptops to a designated switch port, set a static IP address and land on the OT network. Our goal - uncover what’s really happening here and identify where security can be improved. 

We start with selective probing and testing, doing network connectivity scans, configuration review of selected hosts, analysis of the OT Active Directory."

Highlight-image

A Call from the Field

"Mid-morning, my phone buzzes. A colleague on another project has a client suspecting malicious implants in their OT systems, possibly introduced by a third party. They’re hesitant to investigate for fear of production downtime. We exchange approaches - start with non-intrusive traffic analysis, baseline firmware versions, and prioritize critical controllers. We schedule a visit for next week - cross-project collaboration like this is what keeps our team sharp."

Lunch with the Team

"By noon, we join the cafeteria crowd, a lively mix of overalls, suits and hard hats. These informal chats reveal more than any diagram, a machine that reboots mysteriously, a rogue wireless scanner that no one remembers installing, and subtle dynamics around who really owns security on the shop floor. Over a plate of pasta, I gather context that would never surface in a formal meeting."

Highlight-image

Site Tour and On-the-Go Analysis

"After lunch, we suit up with PPE and accompany a plant engineer on a site tour. Past control rooms, conveyor belts, and robotic arms, I scan for rogue Wi-Fi signals - unapproved access points remain a persistent OT weak spot. We note areas where physical access could undermine digital controls, a reminder that in OT, cybersecurity often starts at the door."

Turning Data into Strategy

"Back at the control room, the monitoring probe has surfaced several high-severity findings: weak segmentation, OT systems with uncontrolled internet connections, multi-homed devices bridging network zones, and unnecessary protocols on sensitive endpoints. We sit down with both IT and OT teams to draft remediation steps. The challenge: fortify security without halting production. Governance becomes the recurring theme, defining ownership, processes, and how to embed security into daily operations instead of treating it as a one time fix." 

Highlight-image

Wrapping Up

"As the day draws to a close, we collect the probe, untangle the cables, and head out. The plant glows under the setting sun as I reflect on the next steps: producing a report that is actionable, realistic, and aligned with the plant’s operational constraints.

On the drive home, my phone rings again - another colleague, this time about an upcoming industry conference. We’re preparing a talk on emerging OT threats: supply chain compromises, cloud-connected industrial assets, and strategies to bridge the gap between IT and OT teams. By the time I reach my driveway, the day feels full - technical puzzles solved, meaningful conversations had, and another step taken in keeping critical infrastructure secure."

 

Note: The images in this blog were generated by AI with approval from the author. It is a creative interpretation for illustrative purposes and is not intended to be an exact representation of real events, people, or places.

About Dominika

Dominika Rusek Jonkers is Senior Security Specialist at Bureau Veritas Cybersecurity. She brings over 10 years of expertise in industrial cybersecurity. 


Her extensive experience spans technical assessments of Industrial Control Systems (ICS), penetration testing, Tactical Network Exploitation (TNE) and executing remediation programs to improve the industrial security posture. These include implementing ICS monitoring solutions, as well as designing robust network segmentation strategies. Dominika’s skill set also includes hardware hacking on IoT/IIoT devices and advanced threat hunting in ICS networks.

Her passion for knowledge sharing is evident in her role as a trainer, where she facilitates dynamic courses on topics like OT security fundamentals, ICS technical assessment methodologies, and ICS monitoring crash courses.

Quote by

Sparked your interest?

Check out our vacancies below or contact our recruitment team. We are happy to answer any questions you may have. 

Why choose Bureau Veritas Cybersecurity

Bureau Veritas Cybersecurity is your expert partner in cybersecurity. We help organizations identify risks, strengthen defenses and comply with cybersecurity standards and regulations. Our services cover people, processes and technology, ranging from awareness training and social engineering to security advice, compliance and penetration testing.

We operate across IT, OT and IoT environments, supporting both digital systems and connected products. With over 300 cybersecurity professionals worldwide, we combine deep technical expertise with a global presence. Bureau Veritas Cybersecurity is part of the Bureau Veritas Group, a global leader in testing, inspection and certification.