
Åben
Slået op
•
Slutter om 2 dage
Betales ved levering
Penetration Test of the IT/OT System of a Photovoltaic Power Plant and Battery Energy Storage System 1. Subject of the Contract The subject of this contract is the execution of a comprehensive penetration test of the IT/OT infrastructure of a photovoltaic power plant and battery energy storage system to assess its resilience against cyberattacks and unauthorized remote control. The test must simulate real-world cyberattack scenarios, focusing on the possibility of: Unauthorized remote access Takeover of device control Manipulation of energy production or storage Disruption of system availability Exploitation of communication interfaces Leakage of sensitive data 2. Scope of Testing The test shall include: 2.1 External Testing Simulation of attacks from the public internet Analysis of open ports and exposed services Testing of remote access mechanisms (VPN, web interfaces, cloud services) 2.2 Internal Testing Testing within the local network Network segmentation assessment and lateral movement attempts Verification of access rights management 2.3 OT / Industrial Layer Testing of communication protocols used between devices Verification of controller and control unit security Assessment of the possibility to interfere with operational parameters Review of firmware updates and configuration settings 2.4 Network Infrastructure Firewall Routers Switches SCADA / EMS systems 3. Minimum Test Duration Active testing must be conducted for a minimum of 24 hours. The test must not be limited to automated scanning only; manual testing simulating a real attacker is required. The supplier may propose an extended testing scope (e.g., multi-phase testing). 4. Required Deliverables The outcome of the contract must include: A structured list of identified vulnerabilities Severity assessment (e.g., according to CVSS or equivalent methodology) Brief description of potential exploitation scenarios Clearly defined and prioritized list of security improvement measures Technical report for IT/OT administrators Executive summary for management Optional: Proposal for a re-test after implementation of remediation measures. 5. Supplier Requirements The supplier must meet the following criteria: Proven experience with penetration testing of both IT and OT systems Experience with industrial or energy technologies is an advantage Security certifications (e.g., OSCP, CREST, CISSP, or equivalent) Professional liability insurance NDA signature prior to commencement of testing 6. Proposal Requirements The proposal must include: Description of the testing methodology Proposed timeline Price offer (fixed price) Composition of the implementation team References from similar projects 7. Expected Implementation Date Expected implementation date: June 2026 8. Evaluation Criteria Professional qualifications and experience Testing methodology Quality of deliverables Price
Projekt-ID: 40271428
14 forslag
Åben for bud
Projekt på afstand
Aktiv 3 dage siden
Fastsæt dit budget og din tidsramme
Bliv betalt for dit arbejde
Oprids dit forslag
Det er gratis at skrive sig op og byde på jobs
14 freelancere byder i gennemsnit €1.313 EUR på dette job

Hi there, I will perform a focused IT/OT penetration test of your photovoltaic plant and BESS, combining real-world red-team techniques and OT-safe procedures, my background in critical infrastructure and SCADA/EMS assessments makes me a strong fit. - Deliver a structured list of identified vulnerabilities with CVSS scores and concrete exploitation scenarios for PV inverters, BMS, SCADA and cloud remote access. - Provide prioritized remediation guidance, a technical report for IT/OT teams and an executive summary for management. - Risk & quality control: staged manual testing, minimal-disruption rules, rollback plan, firmware/patch review and full NDA before work. Skills: ✅ Penetration Testing ✅ SCADA / ICS protocols testing (Modbus, DNP3, IEC 60870) ✅ Network segmentation & lateral movement testing ✅ Firewall / Router / VPN assessment and hardening ✅ Incident hardening, CVSS-based risk triage Certificates: ✅ Microsoft® Certified: MCSA | MCSE | MCT ✅ cPanel® & WHM Certified CWSA-2 I’m available for June 2026 start; Can you confirm the permitted attack windows, full asset inventory (IP ranges, SCADA/EMS vendor and firmware versions), and whether a failover/test environment is available for safe live testing? Best regards,
€1.450 EUR på 7 dage
6,4
6,4

With a proven track record of over five years in both software engineering and cybersecurity, I am confident in my ability to perform an exceptional penetration test on your IT/OT infrastructure. Importantly, I hold several security certifications including OSCP, CISSP, and CREST which validates my expertise in executing comprehensive penetration tests. Furthermore, I have hands-on experience with industrial systems like those found in power plants and energy storage facilities. This gives me a unique edge as your potential supplier. In addition to my experience and skills, I bring a collaborative and proactive approach to every project I undertake. As your cybersecurity specialist, I understand the importance of thorough testing that simulates real-world attack scenarios. My methodology is not limited to automated scanning but also includes manual testing that replicates the actions of an actual attacker. This meticulous approach creates more realistic and robust results for vulnerability detection and assessment. Keeping lines of communication is also vital during any project; therefore, I assure you that my excellent written and verbal communication skills will provide you seamless collaborate ensuring you are fully informed throughout the process.
€1.233,33 EUR på 4 dage
4,5
4,5

Hi there,Good morning I am Talha. I can work with your project skills Network Administration, Cloud Security, Computer Security, Risk Assessment, Penetration Testing, Internet Security, Network Security and Web Security I am excited to present my proposal, which centers around a personalized approach designed to elevate your project. We will start with an in-depth consultation to gain a deep understanding of your project's unique requirements, goals, and constraints. Our commitment to customization means that we will tailor our services to align perfectly with your project, and we will explain how this approach will meet your expectations. Please note that the initial bid is an estimate, and the final quote will be provided after a thorough discussion of the project requirements or upon reviewing any detailed documentation you can share. Could you please share any available detailed documentation? I'm also open to further discussions to explore specific aspects of the project. Thanks Regards. Talha Ramzan
€750 EUR på 12 dage
3,7
3,7

With over a decade of experience in web and mobile development, particularly in cybersecurity and penetration testing, I understand the critical importance of assessing the resilience of your photovoltaic power plant and battery energy storage system against cyberattacks. Your project requires a comprehensive penetration test to simulate real-world scenarios and uncover vulnerabilities that could lead to unauthorized access, manipulation of energy production, or data leakage. I have a proven track record in conducting penetration tests for both IT and OT systems, ensuring thorough assessments and delivering actionable security improvement measures. My expertise in industrial technologies, combined with certifications like OSCP and CISSP, equips me to safeguard your infrastructure effectively. I am prepared to propose a detailed testing methodology, a timeline that meets your expectations, and a competitive fixed-price offer within your budget constraints. My team is composed of skilled professionals who have successfully completed similar projects, as evidenced by our references. I encourage you to take the next step in securing your IT/OT system by reaching out to discuss how I can support your project.
€1.200 EUR på 20 dage
2,6
2,6

I am well-equipped to conduct a thorough penetration test of your IT/OT systems for the photovoltaic power plant and battery storage, bringing a wealth of experience in both fields and recognized credentials like OSCP and CISSP. My commitment to a realistic testing approach involving manual testing techniques ensures that the vulnerabilities are accurately identified and prioritized, providing you with actionable insights and a comprehensive report tailored for both technical staff and management. You can trust my proven track record in delivering high-quality assessments and my dedication to enhancing your system's cybersecurity posture.
€1.125 EUR på 7 dage
0,0
0,0

Prague, Czech Republic
Betalingsmetode verificeret
Medlem siden maj 22, 2025
€30-250 EUR
€30-250 EUR
€30-250 EUR
€5000-10000 EUR
€30-250 EUR
£10-20 GBP
£18-36 GBP / time
min ₹2500 INR / time
min £36 GBP / time
$10-30 USD
£20-250 GBP
£18-36 GBP / time
$30-250 USD
$750-1500 AUD
$2-8 USD / time
$30-250 CAD
₹12500-37500 INR
₹100-400 INR / time
min $50 USD / time
$250-750 USD
$2-8 USD / time
$25-50 USD / time
$10-30 USD
$60 USD
$15-25 USD / time