OMAR MORANDOOFFENSIVE OT SECURITY

OT / ICS SECURITY · INDUSTRIAL ROOTS

Offensive security.
Industrial by nature.

I’m Omar Morando. I research how industrial systems fail, build the tools to test them, and turn that knowledge into stronger defenses.

Co-Founder & CTO · BlackFox

Creator & Lead Developer · SCADAsploit

20+ yearsIndustrial automation & OT/ICS
Black Hat EuropeArsenal · London, 2023
SANS ICS SummitSpeaker · 2024

01 / BACKGROUND

Built on the factory floor.

My path into security started with the systems that run industry.

SCADA software, PLCs, industrial networks and embedded systems came first. Offensive security followed. That engineering background shapes how I investigate vulnerabilities: from the code and the protocol to what happens in the physical process.

Across more than 20 years in industrial automation and OT/ICS, I’ve combined software development, security research and technology leadership. Today, I bring those disciplines together in offensive assessments, SCADAsploit and practical training.

Industrial automation → Software & embedded → Offensive OT security → Research & technology leadership

02 / EXPERTISE

Know the process.
Test the assumptions.

Offensive OT security at the core. IT expertise where industrial systems and enterprise networks meet.

01 /

Offensive OT security

Penetration Testing, Adversary Simulation and Red Teaming grounded in the behavior of industrial systems.

02 /

OT / ICS security

PLC, SCADA, remote I/O, IIoT and industrial protocols. From device internals to network architecture.

03 /

Security research

Vulnerability research, protocol analysis, network and binary exploitation, and exploit/tool development.

04 /

Security architecture

Segmentation, monitoring and detection, secure industrial architectures and IEC 62443.

05 /

Software & embedded

Industrial software, real-time systems and robotics. Engineering the tools that support security research.

06 /

Automotive security

Cybersecurity for connected vehicles and embedded ECUs, informed by ISO/SAE 21434 and UNECE requirements.

TECHNICAL STACK

C / C++ Python Go C# Qt / QML PyQt ROS

Embedded & real-time: FreeRTOS · ChibiOS/RT · Linux/RT. Security: reverse engineering · malware analysis · tool development.

03 / FEATURED RESEARCH

SCADAsploit.

Offensive Security Framework for IT/OT Adversary Simulation

CREATOR & LEAD DEVELOPER

I created SCADAsploit to bring an industrial perspective to offensive security. The framework supports OT/ICS penetration testing, Red Teaming and security validation across converging IT and OT environments.

A remote C2 architecture and graphical commander connect asset discovery, pre- and post-exploitation, OT-oriented modules and IT/OT pivoting. Its industrial focus includes Schneider Electric, Siemens, Rockwell Automation and ABB systems.

  • Asset discovery
  • OT modules
  • Remote C2
  • IT/OT pivoting
Explore SCADAsploit
Public SCADAsploit graphical commander showing the framework interface.
SCADAsploit C2.OT / Graphical commander
Presented at Black Hat Europe ArsenalLondon · December 2023

04 / WORKSHOPS & ADVANCED TRAINING

Learn the attack.
Engineer the defense.

Practical OT cybersecurity training. Understand the systems, investigate attack techniques and build the skills to protect them.

012 days

Advanced OT

Advanced · OT foundations required

Develop a practical approach to protecting industrial devices and networks, from security fundamentals to incident response.

FORSystem designers, PLC/SCADA programmers, industrial network specialists and OT security teams.

  • Segmentation & IDS/IPS
  • Secure architecture & monitoring
  • IEC 62443 & incident response
  • Introduction to Secure PLC Programming
View workshop details
022 days

Secure PLC Programming

Advanced · PLC programming required

Apply security by design to PLC software. Build more resilient PLC/HMI/SCADA applications and diagnose cyber impacts on program execution.

FORPLC programmers, maintenance technicians, system integrators, machine builders and automation engineers.

  • OT cyber risks
  • Resilient application design
  • Secure PLC coding
  • Diagnostics & execution integrity
View workshop details

05 / EXPERIENCE

Engineering. Research. Leadership.

A selected career timeline, from SCADA development to offensive security and technology strategy.

Current

BlackFox

Co-Founder & CTO

Technology strategy, OT/IT security, offensive research and proprietary tool development.

Appointment: February 2025

EY Advisory

Director of OT Cybersecurity

OT security across governance, infrastructure, monitoring and training; SCADAsploit development leadership.

2021 — 2025

HWG / Sababa

OT & offensive security leadership

Head of OT Cybersecurity (2023–Jan 2025); CTO (Apr–Dec 2022); Adversary Cybersecurity Director (Dec 2021–Apr 2022).

2020 — 2022

CNH Industrial / Iveco Group

Automotive Cybersecurity Specialist · External consultant

Hardware and software cybersecurity for connected-vehicle ECUs and telematics, with ISO/SAE 21434 and UNECE R155.

2010 — 2021

Independent practice

OT Cybersecurity Expert

Offensive OT research, penetration testing and real-time embedded software. UAV R&D with DigiSky on CPSwarm (2017–2019).

Earlier industrial experience

2008 — 2010

Progea International

International Business Development · SCADA

2005 — 2008

Caterpillar Group

Business Development

1990 — 2005

Schneider Electric

Software Engineer → Product Manager → Group Product Manager

1987 — 1990

Comau

Software Engineer · SCADA development

06 / SELECTED CONFERENCES

Research, shared.

Technical talks and live demonstrations at international security events.

Talk titles are shown in their original English.

2025

BSides Prague

SCADAsploit: a C2 for OT. How to break an ICS system

2024

BSides Sofia · HackInBo · CSET

SCADAsploit: a C2 for OT. How to break an ICS system

2023

BSides Budapest · Athens · Milano

How to break the Modbus protocol and cause a PLC DoS

2023

E-TechEurope · CSET

Cybersecurity of EV systems

2022

HackInBo · BSides Roma

How to break the Modbus protocol and cause a PLC DoS

07 / CONTACT

Let’s talk
industrial security.

Offensive assessments, OT Adversary Simulation, research collaborations, speaking and hands-on workshops.