One compromised controller. A factory stopped — or worse.
Modbus with no authentication, 15,000 Schneider systems reachable online, 150,000 ICS systems exposed on the internet. Industrial control systems were designed for availability — not for security. IT/OT convergence creates attack paths that neither IT nor OT teams can see.
THE OT PARADOX—MAXIMUM AVAILABILITY, MINIMUM SECURITY
Critical operators (OIV): ANSSI can prescribe audits of ICS systems
OUR SERVICES
QREDTEAM
ADVERSARY SIMULATION
- Full OT Red Team — simulation of the IT→OT pivot from the corporate network to the controllers
- Exploitation of industrial protocols (Modbus, BACnet, OPC-UA, PROFINET, DNP3)
- Ransomware simulation in an OT environment — impact on production availability
- Red Team on SCADA, DCS and process-control HMI systems
- Pentest of segmented OT networks — robustness testing of IEC 62443 zones and conduits.
QLAB
DEEP SECURITY RESEARCH
- Reverse engineering of PLC firmware (Modicon, SIMATIC, FactoryTalk) without sources
- 0-day research on critical industrial equipment (Schneider, Siemens, Rockwell, ABB)
- JTAG/UART hardware analysis on controllers — configurations and application logic
- Supply-chain audit of OT components — backdoors in manufacturer firmware
- SBOM evaluation of ICS systems for NIS2 and LPM compliance.
QSHIELD
SOFTWARE PROTECTION
- Protection of embedded OT code against competitor reverse engineering
- Anti-cloning for controller makers exporting outside the EU
- IP protection of proprietary industrial process-control algorithms
- Obfuscation of SIS (safety instrumented systems) code against adversary analysis
- Protection of equipment firmware exported to geopolitically risky markets.
QUARKSLAB DIFFRENTIATOR
Most firms audit the OT security policy — not the protocols that run the controllers. Quarkslab reverse-engineers the firmware of Modicon, SIMATIC and FactoryTalk PLCs, actually exploits Modbus and OPC-UA, and maps the IT→OT paths your teams can’t see. We are ANSSI-referenced for critical-operator (OIV) assessments — with the technical depth a PASSI qualification demands.
WHAT WOULD WE SAY TO EACH OTHER, FACE TO FACE
Do you know whether an attacker on your IT network can send commands to your Modbus controllers in under 30 minutes?
Most industrial critical operators have separated IT and OT on paper. In practice, there is almost always a jump server, a maintenance PC or a provider VPN that creates an undocumented path. Quarkslab maps and tests these real paths — not the theoretical topology of your ISMS.