The idea
Buying a firewall and considering the job done is the most common mistake in industrial security. Any single control, however good, can have a bad day: a misconfigured rule, a zero-day, a USB drive or forgotten remote access. Defence in depth assumes this will happen and prepares for it: if email lets phishing through, segmentation contains the jump; if malware still gets in, allowlisting stops it; and if it slips through even then, an immutable backup enables recovery.
It is not about stacking products for the sake of it. Each layer addresses a specific failure in the previous one, and all are organised around the Purdue model: from the physical process to the corporate network. We always start with the measures that reduce the most risk at the lowest cost—knowing the assets and segmenting—and build upwards from there.
And we implement it without tying the client to a vendor. We select tools according to technical requirements and operating cost; these are the vendors we regularly work with, not a closed list.
The stack
The twelve layers
From the bottom up, each one closes a gap in the previous layer. Several are our own services and can be purchased separately; the value lies in making them fit together.
| # | Layer · what it adds | Supporting technology |
|---|---|---|
| 01 | Know your assets Know what is connected and what it communicates with. None of the layers above works without this. It is the inventory. | Rutile |
| 02 | Segment the network Zones and conduits to prevent an office incident from reaching the SCADA. The layer that removes the most risk: IT/OT segmentation. Experience with data diodes. | Fortinet · Cisco · Palo Alto Networks · Check Point · Aruba · Hirschmann · Allied Telesis |
| 03 | Harden configurations Remove default services, accounts and settings that expand the attack surface, without affecting legitimate operations. | CIS Benchmarks · DISA STIG |
| 04 | Control identities and access Named accounts, least privilege, MFA for remote access and privileged access management (PAM). Credential theft is the initial vector in most incidents. | Entra ID / AD · PAM · Yubico |
| 05 | Manage vulnerabilities A living process that prioritises real risk, not raw CVSS, and adapts treatment to what the plant allows to be patched. | Rutile (OT) · Tenable |
| 06 | Protect data Control travels with the document—drawings, recipes, intellectual property: it is encrypted, tracked and can be revoked even after being sent outside the organisation (DRM). | Sealpath |
| 07 | Filter email and web traffic Close the main entry point: more than nine out of ten attacks begin with an email. | Trellix |
| 08 | Defend against malware without stopping the process Protection designed for OT: application allowlists on engineering workstations and HMIs, USB inspection and network protection, without blocking legitimate SCADA activity. | TXOne Networks · Trellix · TrendAI |
| 09 | Monitor Centralise and correlate IT and OT logs for timely detection. This is the engine of the SOC OT. | Elastic (SIEM) |
| 10 | Be able to recover The last line of defence against ransomware: backups following the 3-2-1-1-0 rule, including an immutable or offline copy, and verified restoration. | Veeam · Acronis |
| 11 | Train people Technology is not enough: the person opening the email is the first line of defence. This is awareness and training. | In-house programme · SmartFense |
| 12 | Respond when everything else fails Contain, eradicate, recover and learn, with OT-compatible forensics. This is incident response. | DFIR |