Skip to content

AID ICS Framework

100000111000000010000010001101100000101101010110100011100001001100001110010011011111011001001001100110111100011000010100101010011010111111010111010100011110111011110110010110000000111011111010110010111001100010110110001011100011000010110010110101101110100111101111110100000011000000010011111110010011101111000111001100111010101000010100010001000101110001110010100100000110010100010011000011000110101010000000001110000011111011001110111100110000110000111010000110100000001010000110000001100110110110100101100111011100010011100111101100000111011100010000001010100010000111100000100011001010010111111010

Operational Technology (OT) and Industrial Control Systems (ICS) are components that support industrial processes found in many critical infrastructures such as energy, oil and gas, chemical, and water.

State-sponsored attackers are increasingly interested in these targets due to the lack of security by design and significant impact that they can cause if successfully breached. Critical infrastructures prioritize high availability and are very reluctant to change and patch. Moreover, the inherently vulnerable ICS devices and protocols cannot withstand even a simple attack that would otherwise be blocked or prevented in the IT environment.

Based on extensive experiences in offensive security assessment and consultation of process networks, ECQ designs its own framework AIDICS that supports and helps customers in the OT/ICS sector to achieve better security to withstand external, internal, and accidental attacks.

AIDICS Framework

AAssessIIdentifyDDesignIInspectCCoachSSimulate
Step01/06
Assess

Perform paper-based and scenario based penetration test to identify immediate gaps, vulnerabilities, and attack path.

  • Gap analysis and vulnerability assessment
  • Attack path discovery and mapping
  • Penetration testing scenarios