Safe Power Grid Pentest, Practitioner's Guide to Security Without Operational Downtime

No ratings

Presented at Elbsides 2026 by

Pentesting critical infrastructure like a power grid is a high-stakes game where "move fast and break things" is a recipe for disaster. This session provides a transparent look on a regional grid, breaking down a repeatable, safety-first methodology that balances deep technical discovery with operational uptime. We start at the beginning: the Rules of Engagement (RoE) workshop. You’ll learn how to work with site operators to map the environment using digital twins and mirrored test benches before a single packet is sent. From there, we move into the data: leveraging passive traffic analysis and protocol-specific inspection to identify firmware CVEs and insecure "clear-text" command paths without touching a live PLC. The core of the talk demonstrates how to map the real-world effectiveness of the Purdue Model. We’ll walk through lateral movement scenarios—testing if guest or corporate Wi-Fi can jump the DMZ into Level 3,2,1,0 networks—and identify the "low-hanging fruit" that still plagues the grid, such as default credentials and unhardened ports. By the end of this session, you’ll have a blueprint for conducting OT assessments that satisfy both security auditors and plant engineers. We will conclude with a walkthrough of traffic analysis techniques and architectural reviews that reveal the "crown jewels" of an ICS network without risking a blackout.