Skip to content
StrikeCyberStrikeCyber
Mining, Energy & OT

OT Security Assessment for a Mining and Energy Operator

A mining and energy operator needed to understand whether a compromise of its corporate IT could reach operational technology and endanger safety.

Mining, Energy & OT sector
Industry
Mining, Energy & OT
Services
Penetration Testing, Vulnerability Assessment
Engagement
IT and OT security assessment
Region
National

The Challenge

The client is a mining and energy operator running physical processes across remote sites in Australia, controlled by operational technology such as industrial control systems, programmable controllers and SCADA. Much of this OT was designed for reliability and long life rather than security, and some of it predates modern network practice. Over time the corporate IT network and the OT environment had grown closer together, connected for reporting, remote support and efficiency.

That convergence created a serious question. If an attacker compromised the corporate IT network, could they cross into OT, and could an OT compromise disrupt production or endanger worker safety? As critical infrastructure, the operator also has obligations under the Security of Critical Infrastructure Act. Testing OT is not like testing a web application, because an outage or an unexpected command can have physical, safety-critical consequences. The operator needed an assessment that took safety as the first principle.

Our Approach

StrikeCyber scoped a safety-first IT and OT security assessment, combining a vulnerability assessment with carefully controlled penetration testing. The rules of engagement were agreed in detail with the operator's engineering and safety teams, and any active testing near OT was passive first, coordinated live, and paused instantly on request.

  • Assessment of the corporate IT environment and, critically, the boundary between IT and OT, to understand how the two networks were connected and separated.
  • Passive discovery within the OT environment to map devices, protocols and exposure without sending traffic that could disrupt a live process.
  • Targeted, tightly controlled testing of the IT and OT crossover points and remote access paths, carried out by expert operators who understand industrial environments.

Safety governed every decision, so the depth of active testing was greatest in IT and most cautious inside OT. This blend of penetration testing and vulnerability assessment gives a realistic view of risk without endangering operations.

What We Found

  • Flat segmentation between IT and OT. The networks were far less separated than assumed, and from a foothold in corporate IT an attacker could reach systems that communicated directly with OT, removing the barrier meant to protect production.
  • An exposed OT interface. A management interface for an industrial system was reachable from the wider network and protected by weak, default-style authentication, offering a direct route to a control system.
  • Shared and static credentials. Engineering and remote-support accounts shared credentials across multiple sites and devices, and some had not changed in years, so one compromise would unlock many systems.
  • Insecure remote access. A remote-support path into the OT environment lacked strong authentication and monitoring, giving an attacker a quiet way in and back out.

The Outcome

StrikeCyber delivered a prioritised remediation plan mapped to the operator's SOCI obligations and written for both IT and engineering audiences, so fixes could be planned around maintenance windows without risking production. The operator strengthened segmentation between IT and OT with tighter controls at the boundary, removed the exposed OT interface from general network reach and replaced its weak authentication, and eliminated shared credentials in favour of individual, managed accounts. Remote access into OT was rebuilt with strong authentication and full monitoring.

Because the engagement was designed around safety, none of this came at the cost of an outage or a disrupted process. The operator gained a clear, evidence-based understanding of how a corporate compromise could have reached its control systems, closed the paths that mattered most, and secured documented assurance to support its critical infrastructure obligations.

Why It Matters

In mining and energy the consequence of a cyber incident is not just data loss but disrupted production and physical safety. As IT and OT converge, the corporate network becomes a route to the plant, and the flaws that matter are the crossover points, exposed interfaces and shared access that connect them. A safety-first OT security assessment finds those paths without endangering operations, turning a critical infrastructure obligation into real resilience. To scope an assessment of your own environment, get in touch.

Ready to take the offensive?

StrikeCyber specialises in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

1300 654 898Free Consultation