The Challenge

A mid-sized manufacturer of precision industrial components had been running its operations on a mix of legacy and modern systems. With over 200 employees across two facilities, the company relied heavily on its OT (operational technology) environment to run CNC machines and assembly lines, while its IT network handled ERP, email, and file sharing. The two networks had been loosely connected over the years without formal segmentation.

After a near-miss ransomware incident that locked a handful of workstations, the company’s General Manager realised how exposed they truly were. Employees were using personal USB drives on shop-floor terminals, antivirus software was outdated, and there was no visibility into lateral movement within the network. A third-party audit revealed critical gaps: unpatched endpoints, no multi-factor authentication, and a flat network topology that would allow an attacker to pivot from a compromised email client directly to a production server. The company needed a complete overhaul of its endpoint and network security posture — but they lacked internal expertise and feared disrupting production schedules.

Our Approach

MS&VG began with a two-week discovery phase, conducting network scans, endpoint inventory, and risk assessments. We identified over 300 endpoints — including desktops, laptops, industrial controllers, and IP cameras — that were either unmanaged or running unsupported operating systems. The General Manager gave us a clear mandate: improve security without stopping the production line.

Our engineers deployed a layered strategy. First, we implemented a next-generation endpoint protection platform (EPP) with integrated endpoint detection and response (EDR). Every managed device received real-time threat intelligence and automated remediation for common malware. For legacy machines that couldn’t be upgraded, we created air-gapped network segments and installed lightweight sensors to monitor for anomalous behaviour. Second, we redesigned the network architecture using VLANs and firewall rules to enforce strict segmentation between IT and OT, between departments, and between guest Wi-Fi and internal systems. We also rolled out multi-factor authentication for all remote access and critical admin accounts, and deployed a centralised patch management tool to keep firmware and OS updates current — scheduling updates during planned maintenance windows to avoid downtime. The entire rollout took eight weeks, with weekly check-ins and on-site support during go-live weekends.

The Results

  • 99.6% reduction in endpoint-based security incidents within three months — from an average of 12 per week to fewer than 1.
  • Zero unplanned production downtime during the deployment; all patches and network changes were applied during scheduled maintenance windows.
  • 100% visibility into all managed endpoints and network traffic, with real-time alerts and a centralised dashboard that the General Manager can review.
  • $45,000 annual savings by consolidating five disparate security tools into one unified platform and reducing IT overtime spent on manual cleanup.
  • Passed a compliance audit (NIST SP 800-171) on the first attempt, enabling the company to bid on larger government contracts.

The transformation did more than just lock down the network — it changed the company’s culture around cybersecurity. Employees now understand why they can’t plug in random USB drives, and the IT team has a proactive playbook for responding to threats. The General Manager noted that the peace of mind alone was worth the investment, but the measurable savings and compliance win made the decision a no-brainer. Within six months, the manufacturer also saw a 15% improvement in overall IT efficiency because fewer hours were spent fighting infections and recovering from incidents.

Key Takeaway

For manufacturers with mixed IT/OT environments, endpoint and network security is not a one-size-fits-all project — it requires careful segmentation, minimal operational disruption, and a partner who understands both industrial constraints and modern cyber threats.