- Primary risk
- Production stoppage, IP theft
- Driver
- OEM supply chain audits
- Approach
- OT-aware, conservative scoping
- Region
- Onsite West Mids free
Two risks, not one
Stoppage. A line that stops costs money by the hour, and ransomware operators price accordingly. Recovery is slower than in an office environment because reinstating control systems is not the same as restoring a file server.
Intellectual property. Designs, tooling, process parameters, tender pricing. Theft here is quiet — there is no encryption event, no ransom note, just a competitor who is suddenly better informed. Most manufacturers have no way of detecting it and no idea whether it has already happened.
Operational technology needs a different approach
This is where most generic providers get manufacturing wrong. Conventional active scanning can and does knock over legacy PLCs and HMIs — devices that were never designed to receive unexpected traffic and that fail closed, or fail loudly, when they do.
We scope OT-adjacent work conservatively. The usual approach is assessing the IT/OT boundary, reviewing network segmentation, examining remote access paths used by equipment vendors, and testing the corporate network properly — because that is where a realistic attack actually starts. Where genuine active OT testing is warranted, we will tell you that specialist OT expertise is the right answer rather than take the work.
What we consistently find
- Flat networks where an office laptop can reach the plant floor.
- Vendor remote access — permanent, unmonitored connections for equipment suppliers, often the single largest hole in the estate.
- Unsupported operating systems running machine controllers, unpatched because the vendor will not certify updates.
- Engineering workstations holding CAD and process data with no access control and no backup.
- Shared accounts on the shop floor, unavoidable in practice and rarely compensated for elsewhere.
Supply chain pressure
Large manufacturers have pushed security requirements down their supply chains substantially, and tier two and tier three suppliers who were never previously asked anything now receive detailed requirements with contractual deadlines. Cyber Essentials is normally the entry requirement; evidence of independent testing follows for larger contracts.
Where to start
Cyber Essentials, external infrastructure testing, and a segmentation review at the IT/OT boundary. Then vendor remote access — inventory every permanent connection into your network and justify each one. That exercise costs nothing and routinely finds connections nobody could account for.
Common questions
Will you scan our production network?
Not conventionally, no. Legacy control systems fail when scanned, and stopping your line to prove a point is not a useful outcome. We assess the boundary, segmentation and remote access paths, and test the corporate network properly.
Our machine controllers run unsupported Windows. What can we do?
Segment them so they cannot be reached from the corporate network or the internet, restrict what they can reach outbound, and treat vendor access as a controlled exception rather than a standing connection. Replacement is often impossible; isolation is achievable.
An OEM is auditing our security. Where do we start?
Send us the actual requirement document. These vary enormously and are frequently ambiguous about whether they want certification, testing, or both. Working out what is genuinely being asked is the first useful step and we don't charge for that conversation.
Do you charge travel to come to our site?
Not across the West Midlands, Shropshire or Staffordshire. Elsewhere we quote travel as a separate transparent line.
Related
Solusec
Typically replies within one business day
Hi 👋 Need a hand with pen testing, Cyber Essentials, or something urgent? Pick whichever suits you:
💬 WhatsApp usQuick questions, quick answers 📞 Call us
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day