Research Library / Case Studies /

Automotive Manufacturing (EV / Industrial OT)

Protecting Industrial OT Systems: OT Security Engagement with a Leading EV Manufacturer

An EV manufacturer producing over 100,000 electric scooters a year needed to know if its plant floor could be trusted. Payatu found factory-default credentials on OT devices, no firewall between plant and IT networks, and prioritized 40+ remediations before a single production line was touched.
OT Security Gap Assessment, OT Device Configuration Review, OT Vulnerability Assessment, Network Architecture Review, MES Application Security Review

At a glance

INDUSTRY

Automotive Manufacturing (EV / Industrial OT)

CLIENT PROFILE

A leading EV manufacturer producing 100,000+ electric scooters annually

SERVICES

OT Security Gap Assessment, OT Device Configuration Review, OT Vulnerability Assessment, Network Architecture Review, MES Application Security Review

ENGAGEMENT

Non-disruptive assessment on live production systems

key Numbers

82

Critical and High- Risk Findings Across the Plant OT Environment

40+

Technical Remediations Prioritised

23

IEC 62443 Compliance Gaps Identified

Key Takeaways

  • Client – a leading EV manufacturer operating a high-volume production facility, producing over 100,000 electric scooters annually.

  • Problem – a complex network of machines, industrial control systems, and interconnected devices had no consolidated view of its OT security posture, and any compromise risked production, safety, and continuity.

  • What Payatu did – ran a non-disruptive gap assessment against IEC 62443 across plant OT devices, network architecture, network devices, and the MES application, without interrupting live production.

  • Outcome – identified factory-default credentials, unsegmented IT-OT networks, and 23 IEC 62443 compliance gaps, then delivered a prioritised roadmap of 40+ remediations.

the challenge

Why the client called us in

With a state-of-the-art facility producing over 100,000 electric scooters a year, even minor OT disruptions carry significant operational and financial impact. The client wanted to strengthen the security and resilience of its Operational Technology environment before a targeted attack or latent vulnerability could threaten production, safety, or continuity.

  • Identify deviations from IEC 62443 and industry OT security standards
  • Assess plant OT devices, network architecture, and the MES application without disrupting production
  • Build a prioritised, risk-based remediation roadmap

scope of engagement

What was in scope

  1. Gap assessment against IEC 62443 and industry standards
  2. Plant OT device configuration review
  3. Plant OT device vulnerability assessment
  4. Network architecture and network device configuration review
  5. MES application security review

Our Approach

How Payatu ran the engagement

01

Kick-off and Data Collection
Aligned with IT and OT stakeholders on critical systems, then reviewed network diagrams, asset inventories, and access policies for a high-level gap analysis.

02

OT Device and Network Configuration Review
Assessed PLCs, RTUs, HMIs, engineering stations, firewalls, routers, and switches for access control, authentication, and hardening gaps, using non-disruptive passive methods to avoid production impact.

03

Manual Vulnerability Assessment
Mapped critical OT assets against NVD and ICS-CERT databases, re-scoring each CVE using real environmental controls to prioritise remediation by actual risk.

04

Network Architecture and MES Review
Reviewed IT-OT segmentation, DMZ design, and remote access paths, then assessed the MES application and its integrations with Jira, SAP, and downstream OT systems.

05

Reporting and Continuous Compliance
Delivered a risk-categorized report and remediation roadmap, then proposed a long-term compliance framework of periodic assessments and control validation.

Key findings

What we found

Plant OT Devices
Factory-default credentials, insecure services (Telnet, FTP, SNMPv1, VNC), and unrestricted USB access were found active on engineering systems and industrial PCs, with no centralized logging or SIEM integration.
Network Architecture
No firewall existed between plant OT and IT networks, and dual-homed systems bridged OT to external networks, allowing unrestricted lateral movement.
MES Application
Active Directory was not integrated with the MES, and no role-based access control existed, so all users could make critical changes with unrestricted privileges.
IEC 62443 Compliance
23 gaps were identified against the standard, including missing OT-specific security policies, no dedicated OT cybersecurity owner, and OT segmentation that did not follow the Purdue Model.

the outcome

Results and Impact

Payatu's assessment gave the client a prioritised, risk-ranked view of its OT security posture before a real incident could halt production or compromise safety.

‍

  • 40+ technical remediations prioritized by real-world risk and business impact

  • Internal roadmap built for network segmentation and secure remote access

  • 23 IEC 62443 compliance gaps identified and mapped to specific controls

  • Client prepared for next-phase initiatives including CSMS implementation and red teaming

Dark background with a flowing, curved red wave pattern across the center.

Get the full case study

Download the complete PDF - full methodology, findings and remediation detail.

Download Case Study (PDF)
White arrow pointing downward on a dark background.White arrow pointing downward on a dark background.

More Case Studies

No items found.
OT/ICS

Building a Security Program from Ground Up for a Security-Critical Government Agency in Asia

Read Case Study
No items found.
OT/ICS
No items found.
IoT & hardware

Payatu IoT Security Assessment Success Stories

Read Case Study
No items found.
IoT & hardware
Fintech
Infrastructure Security Assessment

National Bank Infrastructure Security Assessment

Read Case Study
Fintech
Infrastructure Security Assessment
Physical Security Assessment
Social Engineering Assessment
Security Awareness Training
Regulatory Compliance Assessment