01
Mapped what talks to what
Before recommending anything, we assessed every device on the shop floor and what it genuinely needed to communicate with. Most needed far less access than they had.
Manufacturing
Four CNC machines were controlled by PCs running an operating system that stopped receiving security updates years ago. The machine vendors wouldn't support anything newer. Replacing the machines wasn't happening any time soon, and everything sat on one flat network with the office.
0 hrs
unplanned production downtime
4
legacy controllers isolated, none replaced
Passed
customer supply chain security audit
01
Before recommending anything, we assessed every device on the shop floor and what it genuinely needed to communicate with. Most needed far less access than they had.
02
We advised moving production systems onto their own isolated network segment, with tightly controlled routes for the handful of legitimate flows, so the controllers could stay exactly as the vendor supports them. A network security partner carried out the work.
03
The chosen partner ran the change across a planned shutdown weekend, with a documented rollback at each step and one of their engineers on site for the Monday restart. We stayed involved to keep the plan honest.
04
Network diagrams, change records and the risk rationale for the legacy systems were produced by the partner during the work, not scrambled together afterwards - something we checked for at each milestone.
"Everyone else told us to replace the machines. This was the first conversation that started with what we could actually do this year."
The part that didn't go to plan
One legacy label printer turned out to need a route nobody had documented. It failed on the Monday morning and took two hours to trace. Our discovery work with the partner should have caught it.
Tell us what's getting in the way and we'll talk through what's realistic - no pressure, no jargon.