Reference · Cyber Security

Penetration test of a process control system at Wassergewinnung Essen

Security is decided in operation, not in a document.

Water treatment plant of Wassergewinnung Essen under a digital protective dome, symbolising OT cyber security. Water treatment plant of Wassergewinnung Essen under a digital protective dome, symbolising OT cyber security.

The requirement

Wassergewinnung Essen GmbH supplies drinking water and is therefore part of the critical infrastructure. The German IT Security Act 2.0 and NIS-2 define what has to be demonstrated. Concepts, audits and certificates were all in place.

What remained open was the question no document answers: do the measures hold when someone attacks them in earnest? An attacker does not follow the security concept. They use whatever works.

WGE therefore did not want another theoretical analysis, but a practical validation of its process control technology. And it wanted day-to-day operations to stay as simple as possible.

Why operational technology has to be tested differently

IT penetration tests are standard. There are established methods, tools and plenty of providers. In operational technology the situation is different.

  • Plants run for 10 to 30 years, and updates are difficult or risky.

  • Protocols are often unencrypted, which makes them readable and open to manipulation.

  • Security was frequently not considered at design time.

  • An attack here does not only affect data, it affects the supply itself.

The solution

Codewerk examined the SIMATIC PCS 7 system from an attacker’s perspective, not from a checklist.

  1. Validate existing assumptions

    Does what the security concept describes actually hold in the running plant? Every measure was tested in practice instead of being confirmed on paper.

  2. Uncover blind spots

    Find the entry points nobody had thought of. That is the harder and the more valuable part of a penetration test.

  3. Test the system, not just the component

    Internal communication paths, access routes, lateral movement inside the network. That is where the critical weaknesses in OT environments arise, not in the individual device.

  4. Turn findings into measures

    Every finding became a concrete starting point, prioritised and matched against the reality of the plant.

The result was not a certificate but a list of concrete starting points. The most visible one: the alerting of the existing SIEM was sharpened so that security incidents surface earlier.

The Codewerk advantage

WGE contributed the knowledge of its plant and its processes, Codewerk the understanding of operational technology and the experience from penetration tests in industry and rail. The combination produced no expert opinion, but a solid basis for the next steps.

  • We know the plants, not just the attack techniques. From industrial and rail projects we know how such systems are built, what has grown historically and where the typical weaknesses sit.

  • We have worked with WGE for years, among other things on observability. We know the plant, the processes and the people behind them.

  • We are not yes-men. Anyone ordering a report that says everything is fine will not get one from us. We challenge existing assumptions and name what is uncomfortable. That costs some nerves in the conversation. But it is the only way to make a system genuinely safer.

  • Results, not paperwork
  • OT understanding, not IT templates
  • A view of the whole system
  • Clear next steps

Voices from the project

„The penetration test of the SIEMENS PCS7 system further improved the effectiveness and precision of our existing SIEM. Targeted adjustments to the alerting mechanisms optimised the early detection of security incidents and sustainably strengthened the overall security of the plant.“

Detlef Stein
Head of IT Security and Process Control Technology
Wassergewinnung Essen GmbH
Translated from the German original.

Next step

How secure is your plant really?

Tell us briefly what you have in mind: which plant, which protection goals, which timeframe. We will come back with a proposal for what a test at your site would look like.