About Services Sectors Contact Engage Us
Oscar Tango
OT/ICS Cybersecurity  ·  UAE

Offensive Security
for Operational
Technology

We think like the adversary. Oscar Tango delivers real-world attack simulation, penetration testing, and security assessments for critical infrastructure and industrial control systems.

OT/ICS
Specialist Focus
SCADA
Protocol Expertise
Red Team
Offensive Capability
UAE HQ
Regional Coverage

Built for the
Industrial Attack
Surface

Oscar Tango is an offensive security firm purpose-built for operational technology environments. We operate at the intersection of OT security and adversarial tradecraft — bridging the gap between traditional IT security and the unique constraints of industrial systems.

Our name carries dual meaning: OT as in Operational Technology, the systems we protect - and Offensive Tradecraft, the tactics, techniques and procedures we practice.

OT-Native, Not OT-Adjacent
Deep knowledge of SCADA, DCS, PLCs, and ICS protocols — Modbus, DNP3, IEC 61850, OPC-UA. We understand how industrial systems fail before attackers do.
Adversarial Mindset
Our engagements simulate realistic threat actors, from opportunistic ransomware to nation-state APTs with OT-specific capabilities and TTPs.
Safety-First Methodology
Every engagement is scoped with operational continuity at the forefront. We test at the edge of your resilience — without crossing it.

Services

Offensive security engagements designed around the realities of operational environments — where availability is paramount and the stakes extend beyond data.

01 / Penetration Testing

OT/ICS Penetration Testing

Structured, scoped testing of industrial control systems, SCADA environments, historian servers, and OT network architecture. We identify exploitable paths from IT/OT boundaries to the engineering layer — without disrupting production.

SCADA DCS PLC HMI Historian IT/OT Boundary
02 / Red Teaming

Red Team & Attack Simulation

Full-scope adversary emulation against your people, process, and technology. We simulate APT groups with documented OT capabilities — testing your detection, response, and operational resilience under realistic threat conditions.

Adversary Emulation APT TTPs MITRE ATT&CK ICS Purple Team
03 / Assessment

Security Assessments & Audits

Comprehensive evaluation of your OT security posture against recognised frameworks — IEC 62443, NERC CIP, NIST SP 800-82, and NCA OTCC. Gap analysis, architecture review, and a prioritised remediation roadmap.

IEC 62443 NERC CIP NCA OTCC Architecture Review
04 / Training

Training & Advisory

Hands-on OT security training for engineers, security teams, and leadership — tabletop exercises, incident response simulations, and bespoke awareness programmes tailored to your industry and threat landscape.

Tabletop Exercises IR Simulation Engineer Training Executive Briefing
05 / Physical Security

Physical & Electronic Security

Assessment of the physical and electronic controls that guard your OT estate — perimeter protection, surveillance and CCTV, intrusion detection, and access control systems. Delivered as a standalone engagement or as the physical dimension of a full-scope red team, we test how an adversary defeats these controls to reach the environments where cyber compromise begins.

Physical Red Team Surveillance & CCTV Access Control Badge & RFID Intrusion Detection Perimeter Security
06 / Wireless & Cellular

Wireless, Cellular & Private 5G Security

Security assessment across your full wireless and cellular footprint — Wi-Fi, Bluetooth, and proprietary RF, through to the private 4G / 5G networks now underpinning industrial connectivity. We test private 5G implementations end to end: the RAN, core, and SIM / device trust boundaries that segmentation depends on. The same survey surfaces the rogue side — vendor-installed cellular modems, unauthorised access points, and out-of-band paths that quietly bridge the air gap past your controls.

Wi-Fi / 802.11 Bluetooth & BLE Private 5G / 4G RAN & Core Rogue Modems RF Survey Out-of-Band Paths

Why Oscar Tango

01

OT-Native, Not OT-Adjacent

We are not an IT security firm that added an OT practice. Industrial systems are our primary domain — we understand engineering constraints, safety instrumented systems, and the operational cost of downtime.

02

Regional Intelligence

Based in the UAE with regional coverage across the Gulf. We understand the local regulatory landscape — UAE Cyber Security Council frameworks, TDRA requirements, and Saudi Arabia's NCA/OTCC controls — as well as international OT standards including IEC/ISA 62443 and NIST SP 800-82. We understand the threat actors that target regional critical infrastructure.

03

Controlled Aggression

Offensive testing in live OT environments requires rigour that goes beyond standard penetration testing. Our methodology is designed to maximise finding quality while preserving operational continuity.

Sectors
We Serve

Mining Oil & Gas Power & Utilities Water Treatment Aviation Rail Defence Petrochemicals Manufacturing Ports & Logistics Building Automation Smart Cities

Start an
Engagement

Tell us about your environment and what you're trying to achieve. We'll scope an engagement that fits your operational constraints.

Email
contact@oscartango.ae
Location
Abu Dhabi, United Arab Emirates
All enquiries are handled under strict confidentiality. Engagement scope and findings are never disclosed without client consent.
Your email client should now be open with your enquiry ready to send. If it didn't open, email us directly at contact@oscartango.ae.