Penetration testers, often referred to as pen testers, have shared insights into how organizations can enhance the resilience of their systems, particularly those involved in critical national infrastructure (CNI). These security professionals, whose job it is to identify vulnerabilities before malicious actors can exploit them, suggest that building systems with security as a core requirement from the initial design phase is crucial. This "secure by design" approach creates a stronger foundation for implementing technical controls that can thwart attacks.
A key recommendation from pen testers is the implementation of network segmentation. This involves dividing a network into smaller, isolated segments. Segmentation can be achieved through various methods, including high-level network architecture, the use of VLANs or firewalls, and granular management of user access. For operational technology (OT) systems, it is particularly important to maintain a clear separation between OT control systems and the broader IT infrastructure of a business.
Effective network segmentation helps prevent attackers from moving laterally across a network once they gain an initial foothold. In OT environments, this can be vital for preventing disruptions to industrial processes and maintaining system availability. Beyond simply separating IT from OT, segmentation should focus on controlling the flow of data and communications across these boundaries, establishing zones of trust and managing inter-zone data transfers. This includes minimizing exposed connections, standardizing access routes, hardening boundaries, and utilizing privileged access workstations (PAWs) for administrative tasks.
The effectiveness of logging and monitoring systems is significantly enhanced when built upon a securely designed and well-segmented network. While robust logging and monitoring alone may not completely stop pen testers, they can make their job considerably more difficult by enabling organizations to detect and respond to their activities. This requires not only the implementation of these systems but also the collection of the correct data and the establishment of appropriate responses to identified alerts and events.
Organizations should ensure that alerts are properly investigated and that incident response plans are developed, communicated, and regularly practiced. A "purple team" approach, which combines the efforts of offensive (red team) and defensive (blue team) security operations, can be beneficial in ensuring that vulnerabilities discovered during testing are fully understood and addressed.
When engaging penetration testing services, particularly for systems that include operational technology, it is recommended that organizations select providers with relevant experience in this specialized area. Without this expertise, testers might overlook specific vulnerabilities present in OT environments or, inadvertently, cause unintended consequences that could impact system operations.
The advice provided by pen testers is not exhaustive but aims to make the process of identifying and exploiting system weaknesses more challenging for security professionals, thereby contributing to overall system resilience. The National Cyber Security Centre (NCSC) offers extensive guidance on secure design principles, logging and monitoring, and maintains a list of assured providers through its CHECK scheme for penetration testing services.






