Penetration Testing and Red-Team Validation
Security claims are tested by an adversarial team against the digital twin and staging OT, because a control that has never been attacked is only a hypothesis.
Attack your own plant, on purpose
Every claim in this section is a hypothesis until an adversary tries to break it. Kronos runs red-team exercises against the digital twin and a staging OT environment that mirrors the plant's segmentation, identity, and safety architecture. The red team's goal is concrete: reach an unsafe simulated plasma state, exfiltrate a protected record, or corrupt a control model without being detected. If they succeed, the architecture changes.
Scope of exercises
- Network: attempt lateral movement past microsegmentation and across the IT/OT boundary.
- Control: attempt a plasma-control attack and diagnostic spoofing.
- Supply chain: attempt to slip an unsigned or poisoned artifact past provenance and model admission.
- Insider: exercise a compromised-credential and coerced-approver scenario against separation of duties.
- Detection: measure whether anomaly detection and audit catch each attempt.
Measuring what matters
The key metric is not vulnerability count but whether the top-consequence outcomes from the threat model were reachable, and whether the independent safety path held even when control was assumed compromised. A finding that the safety path can always force a safe state, even after full control-plane compromise, is the single most important result the exercises seek to confirm.
Honest posture
Because no reactor exists, red teaming is against models and staging, which is a real limit: physical attacks, hardware implants, and real-plasma timing behaviors cannot be fully reproduced yet. Findings therefore carry a confidence caveat and are re-tested on FOAK hardware as it comes online from Q2 2027. Design status: the program is running against the twin; the physical-plant red-team phase is planned, not complete.