The situation
The producer runs several processing plants. The production lines mix new equipment with old systems. Many old devices have no security of their own, but production depends on them every day.
The IT manager had to show strong controls on the plant network. He knew the existing measures were not enough. A security failure could mean a regulatory problem, a food safety risk and damage to the brand.
What we did
We used the Edge SDN platform on the most exposed parts of the network first. Following IEC 62443, we grouped devices into security zones by risk and connected them through conduits that carry only the traffic production needs.
Each zone has profiles for each operating state: normal production, remote maintenance and SCADA communication. The profile sets what may pass in that state.
Many switches in the plants were old and not SDN-capable. We kept them for the basic segmentation and placed network probes at key points. The probes analyse the traffic of the zones and conduits in real time. No full replacement of the network was needed.
What changed
The protection is invisible to operators. Production runs as before.
The company’s own firewalls and intrusion detection now see less irrelevant traffic, so they raise far fewer false alerts. The security team spends its time on real threats.
After the first areas, the producer analysed the rest of its plants and extended the solution in phases to more plants and segments.