The situation

The manufacturer runs several plants. New digital lines sit next to old equipment. SCADA and MES run on a mix of new and outdated computers. The network grew over the years for convenience, not for security.

Internal maintenance staff and outside vendors need access, on site and remote, to keep production going. Any solution had to work with that.

IT and OT pulled in different directions

The IT manager, responsible for the SCADA servers, worried about a growing attack surface and weak segmentation. The OT manager knew the risk too, but feared that more security would slow down maintenance and remove flexibility.

The usual answers had already failed: firewalls with endless rules, VLAN redesigns, new IP addresses and network access control.

What we did

The Edge SDN platform started with a discovery phase. It analysed the traffic between all devices and built a map of who talks to whom. From that map it found the communication patterns and generated the segmentation rules.

The rules went to the existing switches. They let each machine reach only the hosts it needs in normal operation. The platform keeps watching the traffic, so the rules can change without stopping production.

The method for mapping and writing rules is built into the software. IT and OT teams can both use it without being security specialists.

What changed

The company passed its cybersecurity assessments with top ratings. It can now take part in tenders that ask for high security standards.

IT and OT now work together better, because each side got what it needed. Maintenance staff handle network changes for local and remote work on their own. IT keeps the overview and stops being the bottleneck.