IT/OT System Cybersecurity Penetration Test

Job ID: 40271428

Budget: €750 – €1,500 EUR

Penetration Test of the IT/OT System of a Photovoltaic Power Plant and Battery Energy Storage System
1. Subject of the Contract

The subject of this contract is the execution of a comprehensive penetration test of the IT/OT infrastructure of a photovoltaic power plant and battery energy storage system to assess its resilience against cyberattacks and unauthorized remote control.

The test must simulate real-world cyberattack scenarios, focusing on the possibility of:

Unauthorized remote access

Takeover of device control

Manipulation of energy production or storage

Disruption of system availability

Exploitation of communication interfaces

Leakage of sensitive data

2. Scope of Testing

The test shall include:

2.1 External Testing

Simulation of attacks from the public internet

Analysis of open ports and exposed services

Testing of remote access mechanisms (VPN, web interfaces, cloud services)

2.2 Internal Testing

Testing within the local network

Network segmentation assessment and lateral movement attempts

Verification of access rights management

2.3 OT / Industrial Layer

Testing of communication protocols used between devices

Verification of controller and control unit security

Assessment of the possibility to interfere with operational parameters

Review of firmware updates and configuration settings

2.4 Network Infrastructure

Firewall

Routers

Switches

SCADA / EMS systems

3. Minimum Test Duration

Active testing must be conducted for a minimum of 24 hours.

The test must not be limited to automated scanning only; manual testing simulating a real attacker is required.

The supplier may propose an extended testing scope (e.g., multi-phase testing).

4. Required Deliverables

The outcome of the contract must include:

A structured list of identified vulnerabilities

Severity assessment (e.g., according to CVSS or equivalent methodology)

Brief description of potential exploitation scenarios

Clearly defined and prioritized list of security improvement measures

Technical report for IT/OT administrators

Executive summary for management

Optional: Proposal for a re-test after implementation of remediation measures.

5. Supplier Requirements

The supplier must meet the following criteria:

Proven experience with penetration testing of both IT and OT systems

Experience with industrial or energy technologies is an advantage

Security certifications (e.g., OSCP, CREST, CISSP, or equivalent)

Professional liability insurance

NDA signature prior to commencement of testing

6. Proposal Requirements

The proposal must include:

Description of the testing methodology

Proposed timeline

Price offer (fixed price)

Composition of the implementation team

References from similar projects

7. Expected Implementation Date

Expected implementation date: June 2026

8. Evaluation Criteria

Professional qualifications and experience

Testing methodology

Quality of deliverables

Price