OT security testing is the assessment of the systems that measure and control a physical process: SCADA masters and remote terminal units, distributed control systems, programmable logic controllers, human machine interfaces, historians, engineering workstations and the networks between them. The object under test is not data. It is a pump, a breaker, a furnace, a valve, a train.
NIST puts the priority order plainly for operational technology: “Human safety is paramount, followed by protection of the process.” The same document adds the line every rule of engagement should quote: “Any security measure that impairs safety is unacceptable.” Confidentiality, the thing an IT test usually exists to defend, is fourth of seven foundational requirements in IEC 62443 and rarely the reason anyone is worried.
The constraints are structural, not cultural. OT outages “must be planned and scheduled days or weeks in advance”. Components live “10 to 15 years and sometimes longer”. Many devices run operating systems the vendor no longer patches, and installing third-party software can void the support contract that keeps the line running. Field-level sensors and actuators “cannot be authenticated” at all, so a spoofed reading is indistinguishable from a real one.
None of that makes OT untestable. It makes the method the decision. A good OT engagement produces more evidence than an IT-style scan ever would, because it is built from passive observation, configuration and logic review, and targeted testing at the levels that can absorb it. What it does not do is find out whether a controller crashes by crashing it on a running plant.