US penetration testing firm founded in 2011, running 600+ engagements a year with a fully remote, US-based team. Manual, expert-led testing across web, network, cloud, mobile, wireless, OT/ICS, and AI/LLM. Gartner Sample Vendor for PTaaS.
Penetration Testing for Energy & Utilities
Energy and utility companies operate critical infrastructure that underpins society, including power generation, electricity distribution, gas networks, water treatment, and renewable energy systems. These organisations face threats from nation-state actors, cybercriminals, and hacktivists targeting operational technology (OT) systems that control physical processes.
The convergence of IT and OT networks has created new attack vectors, with compromises of IT systems potentially providing pathways to industrial control systems. Penetration testing for energy and utilities must address both IT infrastructure and OT/SCADA systems, requiring testers with specialised expertise in industrial protocols and safety-critical environments.
Testing must be carefully planned to avoid disrupting essential services and must comply with sector-specific regulations including NIS 2 in Europe and NERC CIP in North America. The increasing deployment of smart meters, distributed energy resources, and IoT sensors across energy networks further expands the attack surface and testing requirements.
Raxis
Featured partner for Energy & Utilities.
US penetration testing firm founded in 2011, running 600+ engagements a year with a fully remote, US-based team. Manual, expert-led testing across web, network, cloud, mobile, wireless, OT/ICS, and AI/LLM. Gartner Sample Vendor for PTaaS.
- Holds OSCP Employer accreditation.
- Founded in Atlanta in 2011 by Mark Puckett, formerly head of the global Red Team at Home Depot.
- Runs over 600 penetration tests a year with a fully remote, US-based team.
- Every engineer is a senior-level practitioner based in the United States; testing is never offshored.

UK offensive security consultancy delivering CREST-accredited penetration testing, adversary simulation and CBEST, TIBER-EU and TBEST threat-led testing, mainly for financial services and other large organisations.

Global enterprise cybersecurity consultancy founded in 1999 in Oxford, holding rare CREST STAR-FS accreditation and delivering penetration testing, red and purple teaming, and PCI QSA services across five international offices.

Global Big Four professional services firm delivering CREST, CHECK, and CBEST-accredited penetration testing and red teaming services from London, serving the UK's largest enterprises and regulated organisations.

CHECK and CREST-accredited Birmingham-based cyber security consultancy with over 15 years of experience delivering penetration testing, red teaming, and OT security assessments for government and private sector clients.

Fast-growing CREST and CHECK-accredited UK cybersecurity consultancy with deep expertise in critical national infrastructure sectors.

World-renowned cybersecurity firm now part of Google Cloud, delivering threat intelligence-led penetration testing and red teaming informed by front-line incident response experience.

Award-winning Cheltenham-based cybersecurity consultancy with NCSC CHECK Green Light status and CREST approval, specialising in defence, government, and critical national infrastructure security.

Cybersecurity division of the Thales Group, with ANSSI, CREST, FedRAMP 3PAO, and NATO-cleared personnel. Defence, government, and critical infrastructure penetration testing worldwide.

US-headquartered cybersecurity consultancy with 800+ employees, serving ~40% of the Fortune 500. FedRAMP 3PAO, PCI QSA, and HITRUST accreditations.

Ethical hacking team within Orange Cyberdefense with a 20+ year track record. Known for building industry-standard security tools and groundbreaking research.

Cardiff-based CREST and CHECK-accredited cyber security company delivering penetration testing, red teaming, and OT security assessments as part of the Chess Group.
Energy & Utilities Pen Testing FAQs
Can live OT/SCADA systems be safely pen tested?+
Yes, but with extreme care. Experienced ICS pen testers use passive techniques on live systems and may use offline replicas for active testing. Safety protocols and rollback plans are essential.
What regulations govern energy sector pen testing?+
NIS 2 (EU), NERC CIP (North America), and national energy regulators set cybersecurity requirements. Many require regular security testing of both IT and OT systems.
How do we test IT/OT convergence points?+
Testing should examine network segmentation between IT and OT, data diodes, historian servers, jump servers, and any systems that bridge the IT/OT boundary. These convergence points are critical attack paths.