SystimaNX
Back to case studies
Manufacturing & IndustrialNetworking & CloudNext-Gen Firewalls

Manufacturing Edge & OT Security

Segmenting flat plant networks into defensible zones while still delivering the predictive-maintenance telemetry the business needed — without opening a path from the corporate network into the control plane.

Production uptime preserved with clearer OT/IT boundaries
Client
Confidential — discrete manufacturing
Industry
Manufacturing & Industrial
Timeline
6 months
Technologies
6+ tools

The Challenge

!Plant floor networks had grown organically over two decades, so HMIs, PLCs, historians, and corporate laptops all shared the same flat VLAN with no meaningful access control between them. A single compromised office laptop could, in principle, reach machine controllers directly.
!Multiple equipment vendors required remote access to their skids and cells for support and firmware updates, but each vendor connected differently — some through consumer-grade VPN routers left plugged into the network indefinitely, others through ad hoc remote-desktop tools installed by line technicians.
!The operations team wanted predictive-maintenance analytics and wanted controller and sensor telemetry flowing to a cloud historian, but security had no way to guarantee that opening that pipe wouldn't also open a route back into the control plane.
!Legacy PLCs and HMIs on the floor could not run modern endpoint agents, be patched on a normal cadence, or tolerate active vulnerability scanning, since a dropped packet or scan-induced latency spike risked stopping a production line.
!Plant IT and corporate security had never shared a common view of what normal OT traffic looked like, so there was no baseline against which to detect anomalies, and any monitoring proposal risked drowning operations in false positives.
!Insurance and customer audits increasingly asked pointed questions about network segmentation, incident detection, and vendor access controls, and the client had no documented architecture or evidence to show auditors beyond informal diagrams.
!Plant leadership was justifiably risk-averse about any change to the floor network, since even a short unplanned outage on a production line carried real revenue and contractual penalty exposure, which made every proposed change a negotiation.
!There was no centralized logging or alerting for OT-adjacent events, so incidents on the floor were typically discovered by operators noticing something odd on an HMI rather than by any security telemetry.

Our Solution

Ran a passive network assessment using span-port captures and Claroty's OT-aware discovery to build an accurate asset inventory and traffic map without touching a single device, establishing ground truth before any design work began.
Designed Purdue-model-aligned zones and conduits, grouping cells and lines by criticality and function, and defined explicit allow-listed conduits between zones instead of relying on a flat, implicitly-trusted network.
Deployed Palo Alto Networks industrial firewalls at zone boundaries and between production cells for east-west inspection, replacing the informal vendor VPN routers with a single audited jump-host pattern and a dedicated vendor DMZ with time-boxed credentials.
Built a one-way-biased telemetry path from OT sensors and historians into Azure IoT Hub, using data diodes and protocol breaks where the equipment supported it, so analytics data could flow out without opening a corresponding path back in.
Stood up Grafana dashboards fed by the new telemetry pipeline so operations and security shared the same live view of plant traffic patterns, which let both teams jointly define what normal looked like before treating deviations as alerts.
Used Ansible to codify and version firewall rule sets and jump-host configurations, replacing manual, undocumented changes with a repeatable, auditable change process that plant IT could review before each deployment window.
Sequenced every change into planned maintenance windows with a tested rollback plan for each step, and used Wireshark captures during and after each cutover to confirm no unexpected latency or packet loss on control traffic.
Ran tabletop exercises with plant and IT leadership simulating a vendor-credential compromise and a ransomware-style lateral-movement attempt, which surfaced gaps in the incident-response playbook and built shared muscle memory before go-live.

Measurable Impact

Segmentation
12 zones, 100% of cross-zone paths monitored

Critical production cells are grouped into 12 Purdue-aligned zones isolated behind explicit allow-listed conduits instead of a flat network, with every cross-zone path monitored.

Vendor remote access
100% of vendor sessions brokered, zero standing VPN routers

All vendor connectivity now runs through a single jump-host and DMZ pattern with time-boxed, logged credentials, replacing the previous fleet of ad hoc VPN routers left plugged in permanently.

Telemetry pipeline
100% one-way via data diodes

Predictive-maintenance data reaches the cloud historian via diode-backed conduits with zero corresponding inbound paths into the control plane.

Shared visibility
Anomaly triage time cut by roughly 60%

Operations and security now work from the same Grafana view of normal OT traffic, cutting time-to-triage on floor anomalies from hours to under 30 minutes in most cases.

Production uptime
Zero unplanned downtime across 6 months

Every cutover was sequenced into maintenance windows with tested rollbacks, and no change caused an unplanned line stop over the full 6-month engagement.

Audit readiness
Full architecture package ready in under 2 weeks

The client can now hand auditors and insurers a defensible, diagrammed segmentation model backed by logged evidence, assembled in under 2 weeks versus the informal descriptions used previously.

Incident response
2 tabletop exercises, playbook gaps closed

Two tabletop exercises simulating vendor-credential compromise and lateral movement produced an updated OT incident playbook that plant and IT leadership have both trained on.

We needed modernization without gambling the line. The design respected OT constraints at every step and still got us to a defensible architecture we can show an auditor with a straight face. The tabletop exercises alone changed how plant and IT talk to each other during an incident.

P
Plant IT director
Director of Manufacturing IT (NDA)

Technology stack

Palo Alto NetworksClarotyAzure IoT HubGrafanaAnsibleWireshark (assessments)
Book a consultation
Manufacturing Edge & OT Security | Case Study | SystimaNX