Services
Partners
Use cases
Clients
Company
Contact
FRENDE
Industry & OT

Securing an industrial infrastructure (OT/ICS)

IT/OT convergence, remote maintenance, ageing controllers: industrial environments concentrate specific risks, where a single segmentation mistake can expose production. Here is how we address them end to end.

The challenge

An environment where availability comes first

Industrial systems (ICS/SCADA) were designed for safety and availability, rarely for cybersecurity. IT/OT convergence, remote maintenance and growing interconnection have opened attack paths between the office network and the shop floor, while controllers (PLCs) often remain unauthenticated and hard to patch.

An OT incident is not measured in data alone: it means production downtime, risk to people and to the environment, and long recovery times. Any intervention must therefore use suitable methods, non-intrusive by default, validated with the operations teams.

Our role: assess the real exposure, structure segmentation according to the Purdue model and secure remote access — combining OT offensive expertise, network architecture and monitoring.

What is at stake
  • Pivot from the office IT network to the production floor
  • Production downtime and impact on personal safety
  • Controllers (PLC/RTU) exposed, unauthenticated and unpatched
  • Poorly controlled remote maintenance and contractor access
  • No visibility or detection on OT networks
Diagram

Purdue model & IT/OT segmentation

Purdue model and IT/OT segmentation ITOTL5EnterpriseERP, office IT, InternetDMZIT/OT demilitarised zoneFirewall · relay · SRA / bastion hostL3Site operationsMES, HistorianL2SupervisionSCADA / HMIL1ControlPLC / RTU controllersL0ProcessSensors / actuatorsRemote accesssecured (SRA)MFA · bastion hostcontrolled flows
Segmentation into levels (Purdue), an IT/OT boundary filtered by an industrial DMZ and secure remote access (SRA) through a bastion host — flows controlled from the top down.
Our approach

How we proceed

A gradual, non-intrusive approach, validated at every step with your operations teams.

01

Scoping & Purdue model

Scoping the perimeter and reading your architecture through the Purdue model (levels 0 to 5), to place the trust zones and the IT/OT boundary.

02

OT offensive assessment

Penetration testing adapted to industrial settings: exposed surface, IT-to-OT pivot paths and industrial protocols, with a non-destructive approach agreed with operations.

03

IT/OT segmentation & DMZ

Design and hardening of the segmentation: industrial firewalls, a dedicated DMZ, application-level flow filtering and, where relevant, data diodes for one-way reporting.

04

Secure remote access (SRA)

Controlled remote maintenance: bastion host, strong authentication (MFA), session recording and flows limited to the strict minimum, for staff and contractors alike.

05

OT monitoring & detection

Visibility on OT networks and integration with the SOC to detect abnormal behaviour without disturbing the controllers.

Services involved

Several disciplines, a single point of contact

One need — a trustworthy industrial environment — served by several of our disciplines, coordinated through a single point of contact.

Deliverables
  • Offensive assessment report prioritised by risk
  • IT/OT segmentation architecture (diagrams and filtering rules)
  • Working secure remote access solution
  • Monitoring recommendations and remediation plan
Frequently asked questions

Frequently asked questions

No. In OT environments we favour passive, non-intrusive methods by default. Any action that could have an impact is scoped, scheduled and agreed in advance with your operations teams, ideally on a test environment or during a maintenance window.

It is a reference model that organises an industrial system into levels, from the physical process (level 0) up to enterprise office IT (level 5). It provides the basis for defining trust zones and separating IT from OT, with a demilitarised zone (DMZ) filtering the exchanges between the two worlds.

Through secure remote access (SRA): a single entry point (bastion host) with strong authentication, rights limited to the strict minimum, session recording and filtered flows. Contractors reach only the equipment concerned, for as long as needed.

Rarely. The aim is to reduce risk with what you have: segmentation, filtering, access control and detection. Hardware changes are prioritised by real risk and operational feasibility.

An industrial environment to secure?

Let's talk about your OT context: we adapt the approach to your production constraints.