Build

    Infrastructure and network

    Segmentation, hardened baselines and the evidence that both are actually enforced. Designed to be implemented in phases against a running estate, including where IT and OT have grown into each other.

    Duration

    Design 3–5 weeks; implementation phased

    Built on

    ISO/IEC 27001 Annex A · CIS Benchmarks · IEC 62443 where OT is in scope

    Indicative price

    €25,000–65,000 per engagement

    Who this is for

    • Infrastructure or network lead

      Knows the network is flat and has never had the mandate to fix it.

    • CISO

      Needs lateral movement constrained and cannot evidence that it is.

    • Manufacturing or operations lead

      Has production systems that cannot be taken down and cannot stay unprotected.

    • Auditor

      Wants baselines evidenced rather than described.

    Flat networks are a design decision nobody made

    No one designs a flat network. It arrives by accretion — a temporary route that stayed, a VLAN that was easier to skip, an acquisition plugged in over a weekend, a vendor connection nobody revoked. Each step is reasonable on its own and the cumulative result is an estate where one compromised laptop can reach the finance system, the backup server and the production line.

    Segmentation is the single highest-value control against that, and it is the one most often deferred, because it touches everything and the failure mode is visible. It is easier to buy another detection product than to change how the network is laid out, so that is what usually happens.

    But it does not require a big-bang cutover. Done properly it is phased: understand the real traffic first, design the zones, enforce in monitor mode long enough to find what you missed, then enforce for real, one zone at a time, with a rollback at every step. Nothing has to come down.

    The same logic applies to hardening. Baselines are usually written once, applied inconsistently and then drift, because nothing measures them. A baseline that is not enforced and evidenced is a document, and an auditor will treat it as one.

    Where IT and OT have converged the stakes change rather than the method. Production networks were built for availability and long asset lifetimes, then connected for remote support and analytics. You cannot patch a twelve-year-old controller and you should not try — but you can put it behind a boundary, monitor what crosses that boundary, and know within minutes when something unexpected does.

    How we do it

    1. 01

      Discovery and traffic analysis

      2 weeks

      What is on the network and what actually talks to what. Passive first, because the documented flows and the real flows are never the same and the difference is the risk.

    2. 02

      Segmentation design

      2 weeks

      Zones and conduits, with the rules that govern each boundary. Designed around how the business actually works, because a segmentation model that blocks a real workflow will be disabled by someone within a month.

    3. 03

      Hardening baselines

      1–2 weeks

      Per platform, derived from CIS and vendor guidance and adjusted to what your estate can actually run. A baseline nobody can apply is worse than none, because it creates a documented gap.

    4. 04

      Monitor mode

      2–4 weeks

      Rules enforced in observation only. This is where you find the flows nobody knew about, and it is the step that makes the cutover uneventful.

    5. 05

      Phased enforcement

      ongoing

      Zone by zone, each with a change window, a success check and a tested rollback. No phase depends on the next one succeeding.

    6. 06

      Evidence and handover

      1 week

      Configuration evidence, drift monitoring, and the operational handover — so the baseline stays true rather than decaying from the day we leave.

    Named artefacts

    What you receive

    • Asset and network inventory, including what discovery found that documentation did not
    • Traffic flow analysis — actual, not assumed
    • Segmentation design with zones, conduits and boundary rules
    • Hardening baselines per platform, validated against your estate
    • Phased implementation plan with a rollback per phase
    • Change and rollback runbooks
    • Enforcement evidence pack for audit
    • Drift monitoring configuration and the alerting behind it

    What we need from you

    • Network access for passive discovery, and someone who can explain intent where the design looks odd.
    • Change windows, and a realistic view of how many you get per month.
    • For OT scope, the engineers who own the production process. Nothing goes near a production network without them.
    • Acceptance that discovery will find things. It always does, and the first weeks are more uncomfortable than the rest.

    What changes

    1. 01Lateral movement is constrained by design rather than by hope.
    2. 02You know what is on your network, including the assets that were not on any list.
    3. 03Baselines are enforced and evidenced, so drift is visible rather than discovered at audit.
    4. 04OT assets that cannot be patched sit behind a boundary that is monitored.
    5. 05Each phase stands alone, so the programme can pause without leaving you half-segmented.

    What it costs

    €25,000–65,000 per engagement

    All prices exclude VAT.

    Questions

    Will this take systems down?

    It should not, and that is what monitor mode is for — it surfaces the flows nobody documented before anything is blocked. Every phase has a change window and a tested rollback. We would rather move slowly through eight phases than quickly through two.

    Can you segment an OT network?

    Yes, and it is usually where the value is highest. The approach differs — passive discovery only, no active scanning, the process engineers involved throughout, and IEC 62443 as the frame rather than IT baselines. We will say plainly where an asset simply cannot be touched and has to be handled by boundary and monitoring instead.

    We have a next-generation firewall already. Isn't that segmentation?

    It is the enforcement point, not the design. Most estates with capable firewalls still run flat internally, because the rules were written for north-south traffic and never revisited for east-west. The device is usually already there; the policy is what is missing.

    How do we stop it drifting again?

    Drift monitoring and a change process that treats a rule exception as a decision with an owner and an expiry date. Most drift comes from temporary exceptions that were never temporary.

    Leave with your top three risks documented

    Thirty minutes with a senior practitioner. No slideware, no sales engineer.