All case studies
Operational TechnologyRepresentative engagement

Securing a Plant Without Stopping It

A representative engagement, drawn from the environments ITBuilders works in across the Kingdom.

Delivered under the Fortinet Engage Partner Specialization — Operational Technology.

The context

Regulatory pressure on industrial operators in the Kingdom has moved from advisory to enforced. OT cybersecurity controls now carry financial penalty, and compliance has become a board-level obligation rather than an engineering preference. For operators running continuous production, that creates a problem the regulation itself does not solve: how to secure an environment that cannot be taken offline.

An industrial operator reached that point with no realistic path forward. The production environment had been built over fifteen years, ran control systems from several vendor generations, and could not be paused for assessment. The engineering team's position was that security work would stop production. The security team's position was that the regulator was not negotiable. Both were correct.

The barrier to most OT programmes is that IT security methods do not transfer. Active scanning can halt a controller. Patching assumes a maintenance window that a continuous process does not have. Agent deployment assumes an operating system that supports agents, and much of a plant floor does not. Programmes that ignore this get stopped by operations within a year, usually after the first production incident is attributed to a security change.

The approach

ITBuilders started with passive discovery — traffic analysis at aggregation points, with no active probing of control systems. Over several weeks this produced an asset inventory the operator had never held, including devices nobody could account for and two engineering laptops carrying permanent plant-floor connections alongside unrestricted internet access.

Network architecture followed, built to a zone and conduit model. Plant floor, supervisory systems, plant-level applications and corporate IT were separated, with defined and inspected conduits replacing the direct connectivity that had grown up informally. The critical design decision was that OT zones retain full function when the corporate connection is severed. A security architecture that makes production dependent on IT availability will be dismantled by operations, and it will deserve to be.

Remote access was rebuilt around the real requirement: vendors needing occasional access to specific systems for maintenance. Previously this ran through shared credentials and standing connections. It now runs through brokered, time-bound, recorded sessions scoped to individual assets — an authorisation model rather than a tunnel.

Monitoring was built to recognise normal industrial behaviour. Protocol traffic in a control environment is highly regular, and deviation is meaningful in ways corporate traffic rarely is. Detections were developed around unexpected controller communication, configuration changes outside maintenance windows, and new devices appearing on plant segments.

Everything was staged against the plant's own maintenance calendar over several months. No change was applied without an engineering owner and a documented rollback, and the engineering team held the veto throughout. That was a condition of the programme, not a concession.

ITBuilders holds the Fortinet Engage Partner Specialization in Operational Technology — a credential assessed by Fortinet against demonstrated capability in industrial environments, not a statement of intent. For a buyer who cannot evaluate OT competence from a proposal, it is an externally verifiable answer to the only question that matters before letting anyone near a plant floor.

What changed

The operator now holds a current OT asset inventory, a defensible zone architecture, controlled vendor access, and monitoring evidence sufficient for regulatory review. Production did not stop, which was the constraint that made everything else possible.

Continuity of operation

The work did not end at handover. ITBuilders continues to operate the monitoring capability, maintain the asset register as the environment changes, and produce the evidence the operator's compliance team presents at review. Deployment and operation sit with the same organisation — which, in an environment where the people who built the architecture are the people who understand its failure modes, is the difference between a system that stays current and one that degrades quietly until the next audit.

Your next step

Facing a similar challenge?

Talk to ITBuilders about the constraints, priorities and operating requirements of your environment.

Start a conversation