The situation

The provider serves a port and an airport. Its network covers many zones, linked by optical fibre and wireless bridges, and was built for convenience rather than security.

The network carries safety and operational systems: surveillance cameras, environmental sensors, actuators, access gates, bulkhead controls, energy monitoring, fire suppression and emergency networks. Different third-party vendors supply and maintain many of them.

What made it hard

The IT manager had little control over large parts of the network. Many devices were black boxes with no access for security tools. Vendors worked on their own systems without supervision.

Protection came only from basic VLANs and border firewalls. Vendors of systems such as access gates and fire safety did not allow VLAN changes or extra firewalls. Any disruption could affect safety at two busy transport hubs.

The team needed more security without changing IP addresses, the network design or the vendors’ systems.

What we did

We used the Edge SDN platform, starting with the most sensitive VLANs. Inside them we analysed the traffic and built perimeters around devices. Operational traffic still passes, but devices can no longer see each other directly, which blocks lateral movement during an attack.

Each VLAN got security zones in several layers. New or changed devices fit in without complex reconfiguration.

Enforcement runs on the existing access switches, managed from the Edge SDN platform. Upper-level switches separate logical zones inside the existing VLANs. In parts of the network with predictable traffic and non-SDN switches, the gains came without extra probes.

What changed

Traffic between zones dropped sharply and the border IDS raises fewer alerts. The network works as before, so vendors reach their systems exactly as they did.

The IT team can now block traffic in a single zone, at the access switch, when something goes wrong. That was impossible before.

A fault or misconfiguration in one zone no longer spreads to others, which makes vendors’ work easier and safer. Unauthorised devices can no longer be added. Vendors also became more disciplined in how they work.