---
title: "Food plant OT segmentation without downtime | Edge SDN"
description: "A food and beverage producer protected legacy devices in several plants with IEC 62443 zones and conduits, on its existing switches and with no production stop."
url: https://www.edge-sdn.com/success-cases/food-and-beverage/
last_updated: 2026-10-04
---

Food and beverage · Edge SDN · IEC 62443

# Segment a food plant without stopping production

Food and beverage producer with several processing plants

No production stop, far fewer false alerts

In short

A food and beverage producer with several plants had to show strong security controls on its production network. Legacy devices could not protect themselves and production could not stop. The Edge SDN platform split the riskiest areas into IEC 62443 zones and conduits on the existing switches. Operators noticed nothing and false alerts dropped.

## The challenge

- Old devices with no built-in security, still essential to production
- Continuous production: a stop means large losses
- Plant staff are process experts, not security experts

## What did not work, and what did

What they tried
- Firewalls and IT tools added latency and stops
- Network-wide rules ignored the risk of each device
- New VLANs and IP addresses needed a shutdown
- IT suppliers proposed office tools that broke the lines

What worked
- Protection only where the risk is
- Zones and conduits by risk level, IEC 62443
- Old switches kept, probes add the visibility
- Nothing changes for the operators

## How we did it

1. **Start with the riskiest areas**Protect the most exposed devices first, not the whole network.
2. **Draw zones and conduits**Group devices by risk. Let only production traffic through.
3. **Match the operating state**Production, remote maintenance and SCADA traffic each get a profile.
4. **Keep the old switches**Network probes add the visibility that non-SDN switches lack.
5. **Extend plant by plant**Analyse the next areas and roll out in phases.

## The results

- **No production stop**Operators saw no change in their work.
- **Fewer false alerts**Firewalls and IDS see only the traffic production needs.
- **Faster response**The security team works on real threats.
- **More plants**Rolled out to further plants and network segments.

### Read the full story

## The situation

The producer runs several processing plants. The production lines mix new equipment with old systems. Many old devices have no security of their own, but production depends on them every day.

The IT manager had to show strong controls on the plant network. He knew the existing measures were not enough. A security failure could mean a regulatory problem, a food safety risk and damage to the brand.

## What we did

We used the Edge SDN platform on the most exposed parts of the network first. Following IEC 62443, we grouped devices into **security zones** by risk and connected them through **conduits** that carry only the traffic production needs.

Each zone has **profiles for each operating state**: normal production, remote maintenance and SCADA communication. The profile sets what may pass in that state.

Many switches in the plants were old and not SDN-capable. We kept them for the basic segmentation and placed **network probes** at key points. The probes analyse the traffic of the zones and conduits in real time. No full replacement of the network was needed.

## What changed

The protection is invisible to operators. Production runs as before.

The company’s own firewalls and intrusion detection now see less irrelevant traffic, so they raise far fewer false alerts. The security team spends its time on real threats.

After the first areas, the producer analysed the rest of its plants and extended the solution in phases to more plants and segments.

**Food production is a NIS2 sector**

NIS2 lists food businesses in industrial production, processing and wholesale distribution. Article 21 asks them for cybersecurity risk-management measures. [\[Directive (EU) 2022/2555, Annex II point 4 and Article 21\]](https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng)

Product used

### Edge SDN

[Explore Edge SDN](https://www.edge-sdn.com/products/edge-sdn/)

Related use case

### Reduce the attack surface of an old machine: protect what you cannot patch

[Read](https://www.edge-sdn.com/use-cases/protect-a-machine-you-cannot-patch/)

The customer is not named on this page. Results describe this project and depend on each network.

## See a critical CVE hit a machine

We show you the moment that matters: a new vulnerability lands. One machine is exposed and the other is not. The customer notice is ready to send.

Meet us at 35.BI-MU, fieramilano Rho, 13–16 October 2026
