- Objective
- Assess whether the corporate-to-OT segmentation holds under a determined insider-style path
- Path
- Corporate phishing gave us a foothold in IT. The segmented OT network itself was solid. The gap: a maintenance vendor’s dual-homed laptop that legitimately bridged zones during scheduled visits, with stored RDP credentials for the historian server. Our objective was reached during a simulated maintenance window — with written authorization from site management at every step.
- Detected
- Nothing fired: vendor traffic was implicitly trusted at the boundary
After: Vendor laptops moved to a dedicated brokered jump host, and every zone crossing now requires a just-in-time access grant.