IT/OT System Cybersecurity Penetration Test
Budget: €750 – €1,500 EUR
Penetration Test of the IT/OT System of a Photovoltaic Power Plant and Battery Energy Storage System
1. Subject of the Contract
The subject of this contract is the execution of a comprehensive penetration test of the IT/OT infrastructure of a photovoltaic power plant and battery energy storage system to assess its resilience against cyberattacks and unauthorized remote control.
The test must simulate real-world cyberattack scenarios, focusing on the possibility of:
Unauthorized remote access
Takeover of device control
Manipulation of energy production or storage
Disruption of system availability
Exploitation of communication interfaces
Leakage of sensitive data
2. Scope of Testing
The test shall include:
2.1 External Testing
Simulation of attacks from the public internet
Analysis of open ports and exposed services
Testing of remote access mechanisms (VPN, web interfaces, cloud services)
2.2 Internal Testing
Testing within the local network
Network segmentation assessment and lateral movement attempts
Verification of access rights management
2.3 OT / Industrial Layer
Testing of communication protocols used between devices
Verification of controller and control unit security
Assessment of the possibility to interfere with operational parameters
Review of firmware updates and configuration settings
2.4 Network Infrastructure
Firewall
Routers
Switches
SCADA / EMS systems
3. Minimum Test Duration
Active testing must be conducted for a minimum of 24 hours.
The test must not be limited to automated scanning only; manual testing simulating a real attacker is required.
The supplier may propose an extended testing scope (e.g., multi-phase testing).
4. Required Deliverables
The outcome of the contract must include:
A structured list of identified vulnerabilities
Severity assessment (e.g., according to CVSS or equivalent methodology)
Brief description of potential exploitation scenarios
Clearly defined and prioritized list of security improvement measures
Technical report for IT/OT administrators
Executive summary for management
Optional: Proposal for a re-test after implementation of remediation measures.
5. Supplier Requirements
The supplier must meet the following criteria:
Proven experience with penetration testing of both IT and OT systems
Experience with industrial or energy technologies is an advantage
Security certifications (e.g., OSCP, CREST, CISSP, or equivalent)
Professional liability insurance
NDA signature prior to commencement of testing
6. Proposal Requirements
The proposal must include:
Description of the testing methodology
Proposed timeline
Price offer (fixed price)
Composition of the implementation team
References from similar projects
7. Expected Implementation Date
Expected implementation date: June 2026
8. Evaluation Criteria
Professional qualifications and experience
Testing methodology
Quality of deliverables
Price
1. Subject of the Contract
The subject of this contract is the execution of a comprehensive penetration test of the IT/OT infrastructure of a photovoltaic power plant and battery energy storage system to assess its resilience against cyberattacks and unauthorized remote control.
The test must simulate real-world cyberattack scenarios, focusing on the possibility of:
Unauthorized remote access
Takeover of device control
Manipulation of energy production or storage
Disruption of system availability
Exploitation of communication interfaces
Leakage of sensitive data
2. Scope of Testing
The test shall include:
2.1 External Testing
Simulation of attacks from the public internet
Analysis of open ports and exposed services
Testing of remote access mechanisms (VPN, web interfaces, cloud services)
2.2 Internal Testing
Testing within the local network
Network segmentation assessment and lateral movement attempts
Verification of access rights management
2.3 OT / Industrial Layer
Testing of communication protocols used between devices
Verification of controller and control unit security
Assessment of the possibility to interfere with operational parameters
Review of firmware updates and configuration settings
2.4 Network Infrastructure
Firewall
Routers
Switches
SCADA / EMS systems
3. Minimum Test Duration
Active testing must be conducted for a minimum of 24 hours.
The test must not be limited to automated scanning only; manual testing simulating a real attacker is required.
The supplier may propose an extended testing scope (e.g., multi-phase testing).
4. Required Deliverables
The outcome of the contract must include:
A structured list of identified vulnerabilities
Severity assessment (e.g., according to CVSS or equivalent methodology)
Brief description of potential exploitation scenarios
Clearly defined and prioritized list of security improvement measures
Technical report for IT/OT administrators
Executive summary for management
Optional: Proposal for a re-test after implementation of remediation measures.
5. Supplier Requirements
The supplier must meet the following criteria:
Proven experience with penetration testing of both IT and OT systems
Experience with industrial or energy technologies is an advantage
Security certifications (e.g., OSCP, CREST, CISSP, or equivalent)
Professional liability insurance
NDA signature prior to commencement of testing
6. Proposal Requirements
The proposal must include:
Description of the testing methodology
Proposed timeline
Price offer (fixed price)
Composition of the implementation team
References from similar projects
7. Expected Implementation Date
Expected implementation date: June 2026
8. Evaluation Criteria
Professional qualifications and experience
Testing methodology
Quality of deliverables
Price