Manufacturing
A stopped line costs more per hour than the security program costs per year. We segment the plant floor without interrupting it.
Where the plant floor and the network meet
Manufacturing networks were built to two different standards by two different groups. The business side was designed by IT, on a refresh cycle, with patching and change control. The plant floor was designed by controls engineers, for determinism and uptime, on equipment expected to run for twenty years. Both did their jobs well. The problem is that at some point the two were connected — for scheduling, for quality data, for remote support — and nobody redesigned either one to account for it.
What that leaves is an operational network full of devices that cannot be patched and were never designed to be reachable. Controllers, HMIs, historians and drives often speak protocols with no authentication at all, because when they were specified the network was a closed loop and authentication was the locked door to the plant. Reaching one of those devices from a compromised office workstation is frequently no harder than knowing its address.
The constraint that shapes everything else is that production cannot stop. A maintenance window may be a planned shutdown two quarters out. Any security design that assumes you can reboot a switch mid-shift, or push firmware to a controller between jobs, has not met the environment. The engineering here is not particularly exotic — the sequencing is where the difficulty lives.
Where we focus
OT/IT segmentation
A real, enforced boundary between the business network and the production environment, with a controlled zone between them for the systems that legitimately need to speak to both — historians, MES, scheduling. Structured along the lines of the Purdue model where that fits, though we scope it to how the plant actually runs rather than to a reference diagram. The objective is that ransomware on an office laptop reaches the office, and stops.
Cell and line-level zoning
Dividing the production network further so a problem in one cell, line or building does not become a problem across the whole operation. This is also what makes controlled recovery possible: when a zone can be isolated, an incident becomes a contained event rather than a full plant shutdown.
Protecting equipment that cannot be patched
Control systems that must keep their validated configuration get protected by controlling what can reach them and what they can reach, rather than by changing them. That is the only approach available for a controller whose vendor support ended years ago and whose replacement is a capital project — and it works, provided the boundaries are real.
Vendor and remote support access
Integrators, OEMs and machine builders all need a path to their equipment, and in many plants that path is a cellular modem or a remote-access tool that IT does not know about. We replace undocumented access with brokered, identity-bound, scoped access that is inventoried, time-bound and revocable — so remote support remains possible and stops being an unmanaged door.
Industrial wireless and the plant environment
Coverage designed for what a plant physically is: steel structure, racking, moving equipment, RF-hostile surfaces and interference from the machinery itself. Scan guns, AGVs, tablets and telemetry each need coverage that holds while moving, and authentication that separates them from staff and guest devices.
Resilience and recovery
Redundancy where a single failure stops a line, and recovery paths that have been tested — including the ability to bring production back when the business network is compromised or unavailable. Manufacturers are among the most heavily targeted ransomware victims precisely because downtime pressure makes payment attractive; tested isolation and recovery is what removes that leverage.
How we engage
The same three phases as the rest of our work. Start at any of them; many manufacturers come to us after an incident, an insurance requirement, or a customer flowing security obligations down the supply chain.
Consult
What is actually on the production network and what it can actually reach — discovered passively, without touching a running process. Current topology, where OT and IT are joined, undocumented remote access, and equipment past support. You get a prioritized roadmap and a budget that matches it, whether or not we do the work.
Integrate
Design and deployment sequenced against the production schedule: staged and pre-configured off-line, cut over inside planned downtime, rehearsed, with a rollback path at every step. The engineer who scoped the work is the engineer who performs it — and works with your controls engineers, not around them.
Manage
Monitoring of both the business and production networks, firmware and patch lifecycle for the infrastructure, configuration change control, and regular review of whether the zoning still matches the equipment that has arrived since the last capital project.
On compliance
Manufacturers increasingly inherit security obligations from their customers rather than from a regulator. Defense-supply-chain work brings CMMC and the NIST SP 800-171 controls behind it; large OEM customers flow down their own requirements; insurers now ask specific questions about segmentation and recovery before they will write a cyber policy.
We build and operate the technical controls those obligations call for, and produce the evidence an assessment asks for. We are not a C3PAO and do not perform certification assessments or issue attestations — where an independent assessor is required, we work alongside them. See Compliance & Risk for how readiness work is structured, and Smart Building & IoT for the operational-technology engineering in more depth.
Who this is for
- Discrete and process manufacturers whose plant network and business network have grown into one another without a designed boundary.
- Defense and aerospace suppliers facing CMMC or NIST SP 800-171 obligations flowed down through their contracts.
- Multi-plant operations trying to apply one security standard across sites that were each built to their own.
- Manufacturers with aging control systems that cannot be patched or replaced on any near-term schedule.
- Operations that have been through a ransomware event, or whose insurer or customer has started asking questions they cannot currently answer.
Ready to hand off the tech?
Book a free technology & security assessment. We'll map your gaps and give you a prioritized roadmap — no obligation, no jargon.