OT cybersecurity services are where a lot of MSPs quietly lose good deals. Not because the work is unprofitable. Because they scope industrial environments like they scope IT, and those are two different jobs with two different failure modes.
Here is the useful part up front. A large share of what your client calls OT security is work your team already does every day: identity, segmentation, remote access, backup, and patching the Windows boxes sitting on the plant floor. The part you cannot safely touch is the controls layer. Split the scope on that line and you keep the client, the margin, and the relationship.
MSP Pentesting is channel-only. We white-label IT penetration testing for MSPs, MSSPs, vCISOs and GRC firms, and when a client's scope crosses into industrial control systems we hand that piece to our sister practice, Cascadia OT Security. Same parent company, separate operators, separate methodology. You are never cut out of your own account.
What OT cybersecurity services actually cover
Operational technology is the hardware and software that monitors or controls physical processes. Pumps, chillers, conveyors, breakers, boilers. The building management system that keeps a data hall at temperature. The SCADA system supervising a water district.
OT cybersecurity services are the assessment, hardening, monitoring and testing work wrapped around that equipment. In practice a full service line has five parts:
- Asset inventory. You cannot protect a controller nobody documented. Most plants have no accurate list.
- Network architecture and segmentation. Where does IT stop and OT begin, and is that boundary real or theoretical.
- Vendor and remote access control. The integrator's jump host is usually the softest thing in the building.
- Monitoring and detection. Passive, protocol-aware, because active scanning is a risk in itself.
- Testing and validation. Assessment against a real standard, then a penetration test where it is safe to run one.
Four of those five are recognisably your work. That is the whole opportunity.
The line that decides everything
Every scoping conversation comes down to one question. Is this the enterprise OT layer or the controls layer?
The enterprise OT layer
This is the network and identity infrastructure surrounding a control system. Building management systems, DCIM, the IT-to-OT boundary, engineering workstations, historians reachable from the corporate side, vendor remote access. It runs on Windows, Ethernet and Active Directory. It behaves like IT because it mostly is IT, just installed by an integrator and never patched.
An MSP with a competent internal pentest habit can assess most of this. The methodology maps cleanly to NIST SP 800-82 Rev. 3 and MITRE ATT&CK for ICS.
The controls layer
PLCs, RTUs, SCADA servers, HMI workstations, process historians, and Safety Instrumented Systems. Protocols like Modbus, DNP3, Profinet, EtherNet/IP and OPC-UA. This layer is mapped to IEC 62443-3-3 and IEC 62443-4-2, not to CIS or OWASP.
Do not test this with an IT playbook. A malformed Modbus packet does not return a 400 error. It can lock a controller. A loud port scan against a live PLC can stop a line. An SIS that faults during testing is a safety event, not a finding.
That is the line. Everything above it is a service you can build. Everything below it needs a specialist.
What you can keep and what you refer
| Scope item | Who owns it | Why |
|---|---|---|
| OT asset inventory and network diagram | You | Discovery and documentation, no controller interaction required |
| IT-to-OT boundary firewall review | You | Standard firewall and rule analysis |
| Vendor remote access and identity | You | MFA, jump hosts, conditional access, account lifecycle |
| Engineering workstation hardening | You | Windows endpoints with an unusual software load |
| BMS and DCIM assessment | You or a specialist | Depends on whether testing touches live control functions |
| PLC, RTU and SCADA penetration testing | Specialist | Protocol-aware tooling and lab-unit exploitation only |
| Safety Instrumented System review | Specialist | Process safety consequence, not an IT risk decision |
| IEC 62443 control mapping for an auditor | Specialist | Auditors expect industrial control references, not SOC 2 language |
How to sell it without hiring a controls engineer
You do not need to build an industrial practice to make money on OT cybersecurity services. You need to be the person who scopes it correctly.
Start with the assessment, not the pentest. An OT security assessment is the natural first engagement because it produces the asset inventory and the architecture picture that every later project depends on. It is also the least risky thing to run in a production environment, since most of it is passive.
Then sequence the remediation. Segmentation almost always comes first, because it shrinks the blast radius before you touch anything else. Our write-up on OT network segmentation covers how to separate the plant floor from the corporate network without breaking a process.
Only then does a penetration test make sense. Testing an environment nobody has mapped is how you find out what a controller does when it stops responding.
Three deals from one conversation. That is the packaging.
What is actually driving the demand
OT scope rarely shows up because a client got curious. Something forces it. Knowing which pressure you are dealing with tells you what the deliverable has to look like.
The most common trigger is an audit boundary that moved. A client running a SOC 2 program acquires a facility, or a manufacturer's customer starts sending security questionnaires down the supply chain. Suddenly the plant is in scope and nobody has ever looked at it.
The second is insurance. Underwriters have gotten specific about industrial exposure, and some now want an ICS-specific test with control mapping before they will write or renew a policy on a facility with real OT footprint.
The third is regulatory. Water and power utilities, defense suppliers under NIST SP 800-171 and CMMC, and healthcare clients with building automation tied into clinical spaces all have their own clock running.
Ask which one it is on the first call. An insurance-driven engagement needs a report an underwriter will accept. An audit-driven one needs control mapping. A regulatory one needs both plus evidence retention. Same technical work, three different documents, and the document is what the client is paying for.
Pricing and margin
OT work carries better margin than IT pentesting for a plain reason: fewer firms can deliver it, and the buyer is usually operating under an insurance or audit deadline rather than shopping on price.
A few things to hold firm on when you quote.
Bill the assessment separately from the test. Clients who bundle them end up with a rushed inventory and a test scoped against the wrong assets. Charge for travel honestly, because a real OT engagement usually needs someone on site at least once. And price the report, not the hours, since what the client is actually buying is a document their underwriter or auditor will accept.
If you resell through us, our MSP partner program gives you wholesale pricing on the IT side and a clean referral path to Cascadia for the industrial side. The white-label reporting means your logo stays on the deliverable either way.
The safety rules that make or break the engagement
Operations teams have been burned by IT before. They will judge your entire proposal on whether you sound like you understand that.
Four commitments to put in writing:
- Zero impact on production. Not "minimal." Zero, as a design constraint.
- Active exploitation against lab units only. Vendor spares, never a production controller.
- Passive observation on live segments. Listen, do not probe.
- An operations kill switch. Ops can halt all testing inside 60 seconds, no discussion.
Put those four lines in the statement of work. They convert better than any capability slide, because they are the exact fears the plant manager walked in with.
Frequently asked questions
What is OT cybersecurity?
OT cybersecurity is the protection of the systems that monitor and control physical processes: industrial controllers, SCADA, building management systems and the networks around them. It differs from IT security in its priority order. IT protects confidentiality first. OT protects availability and safety first, because the consequence of failure is physical.
What does OT mean in cybersecurity?
OT stands for operational technology. It is the counterpart to IT. Where IT moves data, OT moves valves, motors and breakers. ICS, industrial control systems, is the subset of OT that does the actual controlling.
Can you assess OT cybersecurity without a site visit?
Partly. Architecture review, firewall rule analysis, remote access configuration and policy work all happen remotely. Asset inventory and anything involving physical network taps or controller inspection needs someone on site. Plan for at least one visit on any engagement you intend to stand behind.
How do you choose an OT cybersecurity provider?
Ask three questions. Which standard do you map findings to, and can you show a sample report against IEC 62443. What is your rule for touching production controllers. Who exactly runs the engagement, and have they worked in a plant. A vendor that answers the first question with "NIST" and nothing else has not done this work.
Is a generic IT pentest enough for an OT environment?
Increasingly, no. A growing number of cyber insurance underwriters and auditors now ask specifically for an ICS penetration test with industrial control mapping, not an IT test that happened to include industrial assets in scope. Check the requirement language before you scope, because the two deliverables are not interchangeable.
Where to start
Pick one client with industrial exposure. A manufacturer, a data center tenant, a utility, a hospital with real building automation. Ask them a single question: who is responsible for security on the plant network. The answer is usually a long pause, and that pause is your opening.
Scope the assessment. Keep the IT work. Refer the controls layer. You stay the trusted provider on the account, and you stop walking away from revenue because part of the scope scared you.
If you want a second opinion on a scope you are looking at right now, send it over. We will tell you honestly which parts belong in the IT envelope and which need Cascadia, and you can get a pentest quote for the portion we handle directly.



.avif)
.png)
.png)
.png)

