DOC-901 · About
About scadapentest.com
scadapentest.com covers security testing of operational technology: SCADA, distributed control systems, PLC and RTU estates, and building-control environments where availability and safety come before confidentiality. People who run plants are right to check the provenance of advice about their plant, so it is set out here.
Publisher
The site is published by SEQ SIA (reg. No. 40203410806), Lastādijas iela 12 k-3, Riga, LV-1050, Latvia, trading as OffSeq, a provider of security testing and advisory services. Contact: support@offseq.com.
scadapentest.com is not affiliated with NIST, CISA, ENISA, the IEC, ISA or any equipment manufacturer, and nothing here is an official interpretation of a standard or a directive.
Authorship
SEQ SIA (OffSeq) is responsible for publishing, maintaining and updating this site. Articles use team attribution rather than a named byline. Every guide lists the primary documents behind it so a reader can check the basis for the guidance instead of taking it on trust.
How the guidance is sourced
- Technical statements about OT testing risk cite NIST SP 800-82r3, the CISA and joint-agency advisories named in each guide, or the standard itself. Where a claim could not be traced to a primary text it was left out.
- Regulatory statements quote the instrument: Directive (EU) 2022/2555 (NIS2) and Regulation (EU) 2024/2847 (Cyber Resilience Act) as published in the Official Journal, and the IEC and ISA catalogue entries for the 62443 parts.
- Incidents are only included where a government agency, a national CERT or a vendor advisory published the detail. Stuxnet figures, the 2016 Kyiv outage and the Oldsmar water incident are deliberately absent for that reason.
- Engagement descriptions are generalised from real work and never identify a client, a site or an unremediated finding.
- The “Updated” date only moves when the text changes; an automated content-hash ledger reverts unearned bumps.
The interactive tool
The approach selector on the home page is a planning aid built from the published guidance cited beside it. It runs entirely in the browser, stores nothing, and returns method suitability and required safety controls rather than a price, a schedule or an assessment of your site. It is not a permit and it does not replace the judgement of the people who own the process and the safety case.
Commercial interest
We sell the kind of testing this site describes. That is a direct interest in you concluding that you need it, and it should colour how you read every recommendation here.
- Links to OffSeq are our own service links, not a market comparison. We do not rank or score competing providers.
- No vendor, platform, scanner or monitoring product pays for a mention, and there is no advertising or affiliate revenue.
- Where the honest answer is that a method should not be run, the site says so, including when that means a smaller engagement or none at all.
Not advice
This site is not legal advice on whether NIS2 or the Cyber Resilience Act applies to your entity, and it is not a safety assessment. Decisions about testing a live process belong to the operator, its process safety function and, where relevant, its regulator.
Corrections
Send corrections to support@offseq.com, ideally with the primary source. Substantive changes are made and re-dated in the open.