Industry
Plant-floor and office IT kept separate but connected, with the uptime discipline a production line demands.
The context
Manufacturing has two networks with genuinely different rules. The office network can tolerate a reboot in working hours. The plant floor cannot — a stopped line has a per-minute cost the plant manager can quote from memory.
We keep them separate and connected: production systems on isolated segments with change control, office IT run conventionally, and a controlled boundary between them. That boundary is also the single most important security control in a plant, because factory-floor equipment is frequently unpatchable and must instead be protected by what surrounds it.
The constraints
Generic IT advice fails here for specific reasons. These are the ones that change the design.
Line stoppage cost per minute is known and large. Maintenance windows are narrow and scheduled far ahead.
Machine controllers running unsupported operating systems cannot be patched or replaced economically — they must be isolated.
Production data is wanted in ERP, which means a connection between networks that must not become an attack path.
Heat, dust, vibration and electrical noise on the shop floor destroy commercial-grade equipment.
Surveillance serves safety investigation and compliance evidence, not only security.
Our approach
Specific design decisions, not principles. This is what actually changes in a deployment for this sector.
Production isolated from office traffic, with a firewalled, logged and monitored crossing point rather than an open route.
No unscheduled changes on plant networks. Every change planned, windowed, and reversible.
Unpatchable controllers protected by isolation, strict allow-listing and monitoring, because patching is not available.
DIN-rail switches, IP66 enclosures, fibre where electrical noise is a factor, and UPS sized to the actual load.
Coverage that supports incident investigation and safety compliance as well as security, with retention set accordingly.
A typical engagement
A phishing email reached an office PC on a completely flat network that also carried machine controllers running an unsupported Windows version. The infection was contained by chance rather than by design. We segmented the plant, established a monitored boundary and isolated every legacy controller.
Client details are withheld deliberately. We do not publish client names or site specifics without written permission — particularly for security work, where publishing what we installed and where would be indefensible.
Full capability
Most clients in this sector start with the pillars above and add others as the estate consolidates.
Other sectors
Tell us the constraint you are up against — a site, a deadline, a compliance requirement, an audit finding — and we will tell you what is realistic.