This case study is a composite engagement model drawn from patterns across real Armorstack OT/IT security work — not a specific named client. It illustrates our approach and typical outcomes; results are representative, not a guarantee for any individual engagement.
The Challenge
A precision manufacturer ran its production floor on the assumption that had protected industrial environments for decades: the Purdue Enterprise Reference Architecture’s air gap between the plant and the business. In that model, Levels 0 and 1 are the physical process itself — sensors, actuators, and the PLCs and RTUs that control them directly. Level 2 is supervisory control, the HMI and SCADA systems operators watch. Level 3 is operations management — the MES and historian that track production. Levels 4 and 5 are enterprise IT and the business network. Historically, Levels 0 through 3 stayed isolated from 4 and 5 almost entirely. That isolation had quietly eroded: real-time OEE dashboards for plant leadership, remote diagnostic access for equipment vendors, and a historian feeding data to corporate analytics had all opened live paths from Level 3 into the corporate network, without anyone formally re-architecting the security model around the fact that the gap was gone.
The floor itself ran a mixed protocol environment typical of a plant built up over multiple equipment generations: legacy Modbus TCP and Modbus RTU on older PLCs controlling core process lines, DNP3 on select remote monitoring points, EtherNet/IP across the newer Allen-Bradley control cells, and an OPC-UA layer bridging control-level data up to the historian and MES. Modbus in particular has no built-in authentication — any device that can reach the segment can issue a legitimate-looking write command to a register controlling a physical actuator. That was an acceptable risk when the segment was truly isolated. It was a serious one once Level 3 had direct paths to the enterprise network.
The organization’s IT security team had no ICS background, and reasonably so: they knew that a routine vulnerability scan, harmless against a modern server, can crash a PLC or interrupt a control loop it was never built to tolerate. Rather than risk an active scan taking down a production line, the OT network had simply gone unmonitored. Any production downtime carried a cost measured in the millions per incident, which made the team’s caution rational — and left the environment with effectively zero visibility into what was actually happening on it.
The Armorstack Solution
CORE
VERITY
SENTRY’s OT-aware detection was deployed passively from the start — sensors reading traffic off SPAN/mirror ports on the OT switching infrastructure, never sending a single query or scan packet to a PLC, HMI, or RTU directly. That distinction is the whole difference between IT-style and OT-style monitoring: IT tools assume they can probe an endpoint to check its state; OT monitoring has to assume any unsolicited packet to a control device is itself a risk. The sensors performed protocol-aware deep packet inspection — decoding Modbus function codes, DNP3 object headers, and EtherNet/IP CIP messages rather than seeing generic TCP traffic — and used that visibility to build a baseline of normal industrial behavior: which devices talk to which, what function codes and registers are read or written, and on what schedule. Detection worked by flagging deviations from that baseline — an engineering workstation suddenly issuing write commands to a register it had never touched, or a device polling outside its normal cycle — rather than matching signatures the way IT-focused tools do.
Network segmentation followed the Purdue model’s zone-and-conduit structure rather than a flat rebuild: a dedicated industrial DMZ was placed between Level 3 operations and Level 4 enterprise IT, and historian replication to corporate analytics was rearchitected as a one-way data flow so Level 4/5 systems could consume production data without ever having a path back into the control network. Remote vendor access — previously a direct line into the OT segment for equipment diagnostics — was routed through hardened CORE-managed jump hosts with every session recorded and time-boxed, eliminating standing remote connectivity into the plant.
VERITY’s OT/IT convergence roadmap sequenced every segmentation and monitoring change around the plant’s existing maintenance windows, so nothing required an unscheduled line stop to implement — changes to firewall rules, switch configurations, and DMZ routing were staged and validated during planned downtime, not pushed live against a running process.
The incident response procedure was built around a principle specific to OT: you cannot isolate or patch a live production asset the way you would an IT endpoint. Pulling a PLC offline mid-cycle doesn’t just interrupt a service — it can strand a batch process mid-reaction or damage tooling on a robotic cell stopped in the wrong position. So the playbook’s first move for a suspected OT compromise is never to touch the device: it’s to isolate the network conduit into the affected segment at a managed switch or firewall the SOC controls, cutting off further command traffic while letting the physical process reach a safe stopping point on its own terms. Only after that containment step, and only in coordination with plant operations and engineering, does the response escalate to a decision about physically pulling a device or applying a patch — and that decision is made jointly, during a window operations signs off on, not unilaterally by a security analyst reacting to an alert.
Outcomes
Comprehensive OT/IT security achieved without a single minute of unplanned downtime.
Threat detection improved by 94%, giving the organization visibility into previously unmonitored industrial systems.
Two ransomware attempts were detected and neutralized before reaching production systems.
Ready for results like these?
If your OT network’s security still depends on an air gap that stopped being fully true the day someone plugged in a remote diagnostics connection or a real-time dashboard, that gap is worth re-examining before an incident finds it for you. Armorstack builds OT monitoring and segmentation around the Purdue model and the protocols actually running on your floor — not a repurposed IT security stack. Let’s talk about your production environment.