Back to case studies

Manufacturing

A manufacturer with production systems nobody could patch

Four CNC machines were controlled by PCs running an operating system that stopped receiving security updates years ago. The machine vendors wouldn't support anything newer. Replacing the machines wasn't happening any time soon, and everything sat on one flat network with the office.

Organisation
Precision engineering firm
Size
90 staff, one site
Location
West Midlands

0 hrs

unplanned production downtime

4

legacy controllers isolated, none replaced

Passed

customer supply chain security audit

Where they started

  • Unsupported controllers couldn't be patched without voiding vendor support.
  • A single flat network meant an office infection could reach the shop floor.
  • A major customer had started asking security questions as part of its supply chain audit.
  • Any downtime on the line had a direct, measurable cost per hour.

What we did about it

01

Mapped what talks to what

Before recommending anything, we assessed every device on the shop floor and what it genuinely needed to communicate with. Most needed far less access than they had.

02

Recommended segmenting rather than upgrading

We advised moving production systems onto their own isolated network segment, with tightly controlled routes for the handful of legitimate flows, so the controllers could stay exactly as the vendor supports them. A network security partner carried out the work.

03

Matched them with a partner who could plan the cutover around production

The chosen partner ran the change across a planned shutdown weekend, with a documented rollback at each step and one of their engineers on site for the Monday restart. We stayed involved to keep the plan honest.

04

Made sure the audit evidence was produced as the work happened

Network diagrams, change records and the risk rationale for the legacy systems were produced by the partner during the work, not scrambled together afterwards - something we checked for at each milestone.

Where they are now

  • An office ransomware event can no longer reach production systems directly.
  • The firm keeps its machine vendor support intact, because nothing on the controllers changed.
  • Security questionnaires now take hours to complete rather than weeks, because the evidence exists.
"Everyone else told us to replace the machines. This was the first conversation that started with what we could actually do this year."
Operations director, Precision engineering firm

The part that didn't go to plan

One legacy label printer turned out to need a route nobody had documented. It failed on the Monday morning and took two hours to trace. Our discovery work with the partner should have caught it.

Recognise any of this?

Tell us what's getting in the way and we'll talk through what's realistic - no pressure, no jargon.