Offensive security for operations
Can someone shut down your charging network?
OCPP security for charging networks, backends and roaming connections.
The problem
Your last pentest tested a scope. An attacker tests a goal.
A clean report can still leave the route to a critical objective open. Office IT, supplier connections, cloud portals and operational systems rarely change together — attackers use that gap.
Send my free exposure reportDowntime calculator
What does an operational stop cost?
Revenue ÷ 365 × downtime days × operational impact.
Finding out takes an indicative 30-day plan and about four hours of your team’s time.
Request the breakdown and our team will email it to you.
Assumptions and limitations
This is a simple revenue-based downtime estimate, not a forecast of breach cost, fines, legal exposure or recovery costs. It uses the operational impact percentage you choose and does not claim regulatory outcomes.
The offer
The OCPP Kill Chain Assessment
A specialist assessment of charging backends, charge points and roaming paths, with written authorisation and stop conditions agreed before testing.
Our guarantees
Five commitments. In writing.
We don't promise you won't be attacked. Nobody can, and anyone who does is selling something. Here is what we control — in writing, in every engagement.
We don't sign off until it's shut.
Every critical finding gets retested after your remediation — included, within 90 days. If it isn't closed, we come back again. You never pay twice to find out whether a fix worked.
Your operation keeps running.
No destructive technique without your written approval. A test window you set, a named contact reachable throughout, and a stop word. One call and we stand down — no questions, and no invoice for work not yet done.
The price we quote is the price you pay.
Fixed scope, fixed fee. No change orders, no scope-creep invoices. If it takes us longer than we estimated, that is our problem, not your budget's.
The engineer you meet is the engineer who does the work.
Named in the contract. Scoping, execution and debrief by the same person. You will never be handed over to someone you haven't met.
Your report within 30 working days.
From the end of the test window to the report in your inbox.
What the work covers
Experience and approach.
What does an attacker already see?
Send your domain. Within 48 hours, receive a manually delivered exposure report based on passive public information. No active scanning happens automatically. No call or sales follow-up unless you request it.
Our approach
Our week-by-week approach.
- Week 1Map the full infrastructure
- Week 2Identify the first major vulnerabilities
- Week 3Chain vulnerabilities into attack paths
- Week 4Ransomware and encryption simulation
XPOSE Continuous Validation
Human red team once. Machine-assisted review every day.
Between engagements, automated checks highlight changes in your authorised external surface. Our engineers verify signals and connect them to operational impact. New endpoints, changed firmware and supplier connections do not wait for your next annual test.
Continuous Adversary Testing
Your attack surface changes weekly. Testing should not be annual.
A proportionate programme of ongoing exposure reviews and scheduled test days, with human-verified findings and actionable notifications. We agree the cadence, response expectations, safety boundaries and contract terms with your team before starting.
Questions, answered
Before we test.
Will this break production?
No production-impacting action is taken without an agreed rule of engagement. We coordinate sensitive tests with your team.
We already have a pentest vendor.
That is useful context. We test a critical objective across the agreed environment, rather than repeating a checklist.
Is this legal?
Every engagement begins with written authorisation, scope and escalation contacts.
How long does it take?
The indicative plan takes 30 days after scope is agreed. Expect roughly four hours from your team across scoping and readout.
What does it cost?
Scope determines the work. We discuss it after understanding the operation; no public price menu.
What happens to findings?
They are handled confidentially, documented for your team and discussed in remediation. Nothing is disclosed without written consent.
Does this satisfy NIS2 / IEC 62443?
Findings can be mapped to NIS2 and IEC 62443 requirements; your own legal and compliance advisers determine applicability.
We're not big enough for a red team.
If a compromise can interrupt a physical operation, the question is impact, not headcount. We can discuss a proportionate scope.
A clear fit
This is not for you if:
- You need a compliance checkbox and nothing more.
- You have no one who can act on findings.
- You want a report to put in a drawer.
Make the first move
Find out what is exposed before someone uses it.
Two engineers. Full-scope work. We only begin when the scope and safety conditions are clear.