The challenge

A global manufacturer operated multiple plants on a network that had grown organically for two decades. IT systems, building management and plant-floor OT all shared the same flat space. A single compromised endpoint could, in principle, reach a programmable logic controller — and no one had the visibility to prove otherwise.

The constraint: the plant cannot stop. Any change had to be non-disruptive and reversible.

What we did

  • Passive discovery first. We deployed GreyCortex-powered NDR to map every device and flow from traffic alone — no agents, no scanning, no production impact.
  • Identity-first segmentation. Using the real traffic map, we designed enforced zones between IT, BMS and OT, and between plant sites.
  • OT-aware monitoring. Detections were tuned for industrial protocols (Modbus TCP, Siemens S7, OPC-UA) and mapped to MITRE ATT&CK for ICS.
  • Vendor oversight. Third-party integrator access was time-boxed and fully logged.

The outcome

Within the first month we surfaced several previously unknown devices and one host communicating externally over plaintext. Over the following year:

  • Zero lateral-movement incidents across segmented zones.
  • Full east-west visibility for the security team, where there had been none.
  • No unplanned production downtime caused by the rollout.

The plant kept running. The blast radius shrank to almost nothing.

Curious what this would look like in your environment? Talk to an expert.