The ICT security assessment of critical infrastructures is nowadays a prominent problem. All the existing risk assessment
methodologies require, in order to be effective, to be fed with real data regarding the behavior of the system under analysis.
In this paper we present at high level a methodology for conducting experimental ICT security tests.
Keywords Critical Infrastructures - ICT Security assessment - ICT Experimental Security