
Many industrial organizations treat penetration testing as an annual checkbox. The test takes place, the report is generated, findings get fixed, and everyone quietly moves on for another year.
But ICS (Industrial Control Systems) and OT (operational technology) environments don’t stay stagnant for a year. They adapt consistently, and a pen test that was valid in January can be completely useless by April.
This article will look at why that gap matters in ICS and OT environments, and what continuous validation does differently.
In a typical IT environment, change management is relatively controlled. But on the plant floor, things move differently. A maintenance window might require temporarily bridging two network segments. A new PLC gets added to a production line. An integrator connects remotely to update firmware on a batch controller. Each of these events can alter the network topology and introduce new vulnerabilities.
Take the example of a food processing plant that cleared its annual pen test in February with no unusual findings. By June, the operations team had installed a new packaging line with its own HMI and integrated it into the existing SCADA network. That connection created a lateral movement path that wasn’t actually present when the testers were on site.
The pen test report was accurate on the day it was written. Four months later, it described a network that no longer existed.
This kind of drift is normal in manufacturing and process industries. Production demands won’t wait for security reviews. And the numbers back this up.
CISA published 508 ICS advisories covering more than 2,100 vulnerabilities in 2025, the first year the agency has crossed 500 advisories in a single year. Field controllers, PLCs, and SCADA systems were the most affected asset classes.
New vulnerabilities appear constantly, and any one of them could impact a device that was added to the network after the most recent test.

A penetration test gives you a snapshot. It tells you what an attacker could exploit on the day the testers were there, using the techniques they chose, against the network as it existed at that moment. That’s useful. But it’s a photograph, not a video.
The problem is that many organisations treat that snapshot as if it represents their security posture for the entire year. It won’t. Continuous validation works differently. A Continuous Adversary Emulation platform will run realistic attack simulations on an ongoing basis, mapped to frameworks like MITRE ATT&CK for ICS, so new gaps get picked up as they appear rather than months later.
For industrial environments, this matters more than it does in IT. You can’t simply patch a PLC the way you’d configure a Windows server. Downtime costs money, and some devices can’t be taken offline without stopping production.
So when a new vulnerability appears in a controller, there might be several weeks or months before a patch window opens. During that time, you’ll need to know whether your compensating controls actually function.
Annual pen tests in OT environments come with practical limitations that go beyond the timing gap:
Hacktivist groups are increasingly targeting ICS environments, and the fine line between hacktivism and state activity is a lot thinner than it used to be. Cyble tracked Z-Pentest as the most active ICS-focused group of 2025, with Sector 16 and Dark Engine close behind, and US indictments have since linked Z-Pentest to the Russian GRU-linked Cyber Army of Russia Reborn ecosystem.
Their preferred targets are exposed HMIs and web-based SCADA interfaces. These attackers don’t follow an annual schedule, and the defences against them shouldn’t either.
Annual penetration testing still has a place. It satisfies compliance requirements and provides a baseline. The UK’s NCSC has said much the same in its OT guidance, treating continuous assurance as a baseline rather than an upgrade. But relying on the annual test as your primary measure of security in an ICS or OT environment is a gamble.
Industrial networks change too often, threats evolve quickly too, and the consequences of a breach are far too severe. If a vulnerable PLC can halt an entire production line or, worse, create a major safety incident, you’ ’ll definitely need to know your defences function today. Not just on the day the testers showed up nine months ago.
Continuous validation will turn security testing from a periodic event into a permanent part of how the plant operates. And for environments where uptime and safety aren’t optional, that’s the standard to aim for.
Ans: Annual pen tests come with practical limitations that go beyond the timing gap:
Ans: A pen test identifies vulnerabilities in the system, monitors previous logs, and suggests ways to fix the existing issue at hand.
Ans: New vulnerabilities appear constantly, and any one of them could impact a device that was added to the network after the most recent test. This is why annual pen tests don’t suffice.
Ans: Continuous validation turns security testing from a periodic event into a permanent part of how the plant operates, thus enabling safety at all times.