24/7 incident response phone: 24/7 incident response · +34 902 540 891

Defence in depth

No barrier can stand alone. Defence in depth stacks layers of protection so that when one fails—and one will—the next stops the attacker. In a plant, those layers follow the Purdue model.

The idea

Buying a firewall and considering the job done is the most common mistake in industrial security. Any single control, however good, can have a bad day: a misconfigured rule, a zero-day, a USB drive or forgotten remote access. Defence in depth assumes this will happen and prepares for it: if email lets phishing through, segmentation contains the jump; if malware still gets in, allowlisting stops it; and if it slips through even then, an immutable backup enables recovery.

It is not about stacking products for the sake of it. Each layer addresses a specific failure in the previous one, and all are organised around the Purdue model: from the physical process to the corporate network. We always start with the measures that reduce the most risk at the lowest cost—knowing the assets and segmenting—and build upwards from there.

And we implement it without tying the client to a vendor. We select tools according to technical requirements and operating cost; these are the vendors we regularly work with, not a closed list.

The stack

The twelve layers

From the bottom up, each one closes a gap in the previous layer. Several are our own services and can be purchased separately; the value lies in making them fit together.

Defence-in-depth layers
#Layer · what it addsSupporting technology
01Know your assets
Know what is connected and what it communicates with. None of the layers above works without this. It is the inventory.
Rutile
02Segment the network
Zones and conduits to prevent an office incident from reaching the SCADA. The layer that removes the most risk: IT/OT segmentation. Experience with data diodes.
Fortinet · Cisco · Palo Alto Networks · Check Point · Aruba · Hirschmann · Allied Telesis
03Harden configurations
Remove default services, accounts and settings that expand the attack surface, without affecting legitimate operations.
CIS Benchmarks · DISA STIG
04Control identities and access
Named accounts, least privilege, MFA for remote access and privileged access management (PAM). Credential theft is the initial vector in most incidents.
Entra ID / AD · PAM · Yubico
05Manage vulnerabilities
A living process that prioritises real risk, not raw CVSS, and adapts treatment to what the plant allows to be patched.
Rutile (OT) · Tenable
06Protect data
Control travels with the document—drawings, recipes, intellectual property: it is encrypted, tracked and can be revoked even after being sent outside the organisation (DRM).
Sealpath
07Filter email and web traffic
Close the main entry point: more than nine out of ten attacks begin with an email.
Trellix
08Defend against malware without stopping the process
Protection designed for OT: application allowlists on engineering workstations and HMIs, USB inspection and network protection, without blocking legitimate SCADA activity.
TXOne Networks · Trellix · TrendAI
09Monitor
Centralise and correlate IT and OT logs for timely detection. This is the engine of the SOC OT.
Elastic (SIEM)
10Be able to recover
The last line of defence against ransomware: backups following the 3-2-1-1-0 rule, including an immutable or offline copy, and verified restoration.
Veeam · Acronis
11Train people
Technology is not enough: the person opening the email is the first line of defence. This is awareness and training.
In-house programme · SmartFense
12Respond when everything else fails
Contain, eradicate, recover and learn, with OT-compatible forensics. This is incident response.
DFIR
The portfolio

Vendors we work with

Each layer relies on one or more technologies. These are the vendors in our portfolio and what we use each one for. The label indicates the layer it covers.

Inventory and visibility

Rutile

Our own platform. It passively discovers OT assets, maps the real topology and keeps compliance evidence up to date. The foundation on which everything else rests.

Learn more
Networks and perimeter

Fortinet

Next-generation firewalls and Security Fabric: FortiGate for segmentation and inspection, plus centralised logs, email and web security. A strategic partner with which we cover much of the perimeter.

Malware in OT

TXOne Networks

Protection designed for industry: allowlisting on OT endpoints (StellarProtect), USB inspection before connection (Portable Inspector) and network protection (EdgeIPS/EdgeFire). It protects without slowing the process.

Data protection

Sealpath

Enterprise DRM: encryption and access control travel inside the document. Access to a drawing or recipe can be revoked even after it has been distributed externally.

Detection and logs

Elastic

The Elastic Stack (Elasticsearch, Logstash, Kibana, Beats and Elastic Security) as a SIEM: it ingests, normalises and correlates IT and OT events. The backbone of detection.

Backups

Veeam

Backup and replication of virtual and cloud environments, with verification that restoration actually works.

Backup and protection

Acronis

Cyber Protect: backup with integrated antimalware, designed for rapid recovery from ransomware.

Secure email

Trellix

Email security with sandboxing and protection against phishing and business email compromise (BEC), targeting the most widely used attack vector.

Industrial networks

Cisco

Industrial networking equipment (IE and IR series) for switching and routing in OT environments.

Rugged industrial networking

Hirschmann

Industrial switches and firewalls (EAGLE family) for demanding plant environments.

Beyond products

Tools and references

It is not all about licences. Much of the work relies on open or standard frameworks and tools:

  • Hardening baselines: CIS Benchmarks and DISA STIGs to harden Windows, Linux, virtualisation and network equipment, plus recommendations from each OT vendor.
  • IT vulnerability scanning: Tenable, Qualys and Rapid7 for the corporate environment; in OT, passive assessment with Rutile to avoid touching the process.
  • Identity: Microsoft Entra ID and Active Directory as the corporate identity foundation, with MFA and privileged access management (PAM).
  • Reference frameworks: the Purdue model and IEC 62443-3-2 to organise the layers, NIST SP 800-82 for OT networking and the 3-2-1-1-0 rule for backups.
Where to start

Layers are deployed in sequence, not all at once

Titanium · Legal information
Titanium · Legal information
Titanium · Legal information