Blueprint · Manufacturing and industry

    Securing the plant, then making the data earn its keep

    Blueprint, not a client engagement

    This is a blueprint, not a client engagement. It sets out how we would approach this programme and what each stage produces. Our case studies are separate, and every one of them is a real engagement.

    A smart-factory blueprint: segment and monitor the plant network first, then predictive maintenance, visual quality control and anomaly detection

    Most manufacturers already generate the data a smart factory needs. What stands between them and using it is a plant network that was never designed to be connected safely, and a data path that nobody has designed at all. This is the order we would work in, and what each stage produces.

    The data is already there. The network it would cross is the problem.

    A modern plant is instrumented. Drives, PLCs, sensors, vision systems, energy meters and the MES produce more data in a shift than most head offices produce in a month. Almost none of it is used beyond the immediate control loop, because it sits in systems that were never designed to share it, on a network that was never designed to be reached.

    So the first move is not analytics. It is the network. Production estates are typically flat and unpatched by design — a line control PC running an operating system nobody may update because the vendor validated it that way — and reachable from the office network by anyone who gets a foothold there. Connecting that estate to anything, including your own data platform, before segmenting it is how a quality initiative becomes an outage.

    IEC 62443 is the right reference for this work, because it thinks in zones and conduits rather than perimeters, which is how plants are actually built. The work itself is unglamorous: asset inventory, zoning, conduit control, monitoring that understands industrial protocols, and a patching strategy that respects vendor validation instead of pretending it does not exist.

    There is now a product dimension as well. The EU Cyber Resilience Act's reporting obligations took effect on 11 September 2026: manufacturers placing products with digital elements on the EU market must report actively exploited vulnerabilities and severe incidents, with the full set of requirements following on 11 December 2027. If there is software in what you sell, that is a live obligation rather than a planning item.

    Once the estate is segmented and monitored, the connectivity that was a liability becomes the asset: a data path off the line that is deliberate, one-way where it should be, and trustworthy enough to make decisions on.

    How we would run it

    1. 01

      OT discovery and zoning

      Passive asset discovery across the plant: what is actually on the network, including the devices nobody has a record of. Zones and conduits defined against IEC 62443, with the highest-value segmentation identified first rather than a five-year target architecture.

    2. 02

      Segmentation and monitoring

      Separation between office and plant networks, conduit controls at the boundary, and monitoring that speaks industrial protocols rather than treating a PLC like a laptop. Detection tuned to what abnormal looks like on a production line, which is not what it looks like on a corporate network.

    3. 03

      A governed data path

      A deliberate route from machine data to a platform where it can be used, with direction of flow and permitted payloads designed rather than inherited. Historian, MES and quality data reconciled so that a batch, a line and a product mean one thing across all three.

    4. 04

      Predictive maintenance

      Models trained on your own failure history rather than a vendor's demonstration dataset. The honest constraint is that prediction needs failures to learn from: where the history is thin or unlabelled, the first stage is instrumenting and labelling properly, and the early value comes from anomaly detection rather than remaining-useful-life estimates.

    5. 05

      Agentic operations support

      An agent layer that watches the signals and assembles the context a planner would otherwise gather by hand — asset history, spares availability, production schedule, warranty position — then drafts the intervention for a person to approve. It prepares decisions; the planner still makes them.

    6. 06

      Visual quality control

      Inspection models on the lines where defect classes are visually detectable and the cost of a miss is high. Scoped with a labelled dataset and an explicitly agreed false-negative tolerance, because a model optimised for accuracy alone will quietly trade away the errors that matter most.

    7. 07

      Anomaly and loss control

      The same detection thinking applied to consumption, yield, weighing, scrap and returns. Losses in manufacturing are rarely dramatic and usually persistent, and the useful output is a deviation from an established pattern, surfaced to a named owner with the evidence attached.

    8. 08

      Governance and handover

      Model documentation, human oversight designed to be operable, drift monitoring, and the ISO/IEC 42001 artefacts where certification is in view. Plus the operating routine that keeps all of it working after the programme closes.

    What the programme produces

    • OT asset inventory, including the devices nobody had recorded
    • Zone and conduit design against IEC 62443, sequenced by value
    • Segmentation between office and plant networks, implemented and tested
    • Monitoring that understands industrial protocols, with tuned detection
    • A governed data path off the line, with flow direction and payloads defined
    • Reconciled definitions across historian, MES and quality systems
    • Predictive maintenance or anomaly models trained on your own history, with an evaluation harness
    • An agent layer that drafts interventions for human approval
    • Visual inspection models with an agreed false-negative tolerance
    • Model documentation, oversight design and drift monitoring
    • Cyber Resilience Act reporting readiness, where you place products with digital elements on the EU market

    What it would need from you

    • An OT owner who can approve change windows. Nothing in the plant happens without one.
    • Maintenance and quality history, however messy. Discovering it is thinner than expected is a finding, not a failure.
    • Tolerance for sequence. The segmentation work produces no visible AI and makes everything after it possible.
    • A named person on the line who will use the output. Predictions nobody acts on are a cost.

    Questions

    Can we start with predictive maintenance and do the security afterwards?

    You can, and we would advise against it. The connectivity predictive maintenance needs is exactly the connectivity that makes an unsegmented plant dangerous. The sequence is not a sales preference — it is the order in which the risk and the value actually arrive.

    How much data do we need?

    Less than vendors imply for anomaly detection, considerably more than most plants have for failure prediction. Anomaly detection learns what normal looks like, which you have in abundance. Predicting a specific failure mode needs examples of that failure, labelled, and if you have three you have a research project rather than a deployment.

    Does IEC 62443 replace ISO 27001?

    No — they answer different questions and work well together. ISO 27001 governs the management system; IEC 62443 governs how an industrial automation environment is designed and operated. Manufacturers with both usually run one management system with the industrial control set inside it.

    Does the Cyber Resilience Act apply to us?

    If you place a product with digital elements on the EU market, yes — including where the digital element is a small part of a mostly mechanical product. Reporting obligations for actively exploited vulnerabilities and severe incidents have applied since 11 September 2026, with the wider requirements from 11 December 2027.

    Is this a real project you have delivered?

    Not as written. It is a blueprint: the sequence, the reasoning and the deliverables we would bring to a smart-factory programme, drawn from the parts of it we do deliver — OT-adjacent security, data work, and AI built to run in production. Our case studies are real engagements and are labelled as such.

    Leave with your top three risks documented

    Thirty minutes with a senior practitioner. No slideware, no sales engineer.