Manufacturer: Passing a Customer Security Audit Without Replacing the Machines
A major customer sent a 140-question security audit. Three critical machines ran operating systems a decade past support and could not be replaced. Segmentation solved what a budget could not.
How do you pass a customer security audit with unsupported machinery?
By isolating rather than upgrading. The legacy controllers were moved onto a dedicated network segment with no internet route and tightly restricted access, then documented as an accepted risk with those compensating controls — which is what the auditor was looking for.
The challenge
A long-standing customer, itself under supply chain pressure, issued a detailed
security questionnaire with a deadline and an implied consequence. The manufacturer could not answer
a significant portion of it truthfully, and three questions were outright blockers.
The core problem was three CNC machines whose controllers ran an operating system that stopped
receiving security updates a decade ago. The machine vendor would not support an upgrade. Replacement
was a six-figure conversation the business was not going to have.
- Three production controllers on unsupported operating systems, all reachable from the office network
- One flat network — a compromised office laptop could reach the production floor
- Permanent, shared remote access accounts held by two machinery vendors
- No asset inventory, so several questionnaire answers were guesses
- No documented patching cadence for office systems
What we did
The question was never "how do we patch these machines" — it was "how do we bound
the risk they carry, and evidence it".
Discovery
A full network discovery produced the asset inventory the business had never had. It found 40 percent
more connected devices than expected, including a test workstation with default credentials and a
supplier's remote access appliance nobody could account for.
Segmentation
We designed and implemented separation between IT and operational technology:
- A dedicated VLAN for the production controllers, with no internet route at all
- A controlled boundary permitting only the specific traffic the engineering workstations require
- Removable media control on the controllers themselves
- Monitoring at the segment boundary so unusual traffic is visible
- Separate VLANs for office staff, servers, guests and building systems
Vendor access
Permanent shared vendor logins were replaced with individually named, time-limited access, requested
per session, multi-factor authenticated and logged.
Documentation
The legacy controllers were recorded as an accepted risk with the compensating controls listed
explicitly — which is precisely the treatment an auditor expects, rather than a claim that the
problem does not exist.
The outcome
The customer audit was passed at first submission, and the relationship continued.
- Customer security audit satisfied, contract retained
- Production controllers isolated with no internet route, machines still in service
- Asset inventory produced for the first time, now maintained
- Two permanent vendor accounts replaced with logged, time-limited access
- Cyber Essentials certification achieved four months later, which the customer accepted in place of
the questionnaire at the following renewal
No production time was lost during implementation. Segmentation changes were staged over three
weekends with a rollback agreed before each one.
This case study is published anonymously and the client is not identified.
The transferable lesson
Auditors are not asking you to have no risk. They are asking whether you know what your risks are and
what you have done about them. "We cannot patch this machine, so here is how we have contained it,
and here is who accepted that decision" is a strong answer. "We are fine" is not.
The Cyber Essentials certificate that followed has since replaced the questionnaire process with two
other customers, which the finance director reckoned had paid for the entire project.
Published anonymously. Identifying details have been removed or generalised, and no client is named without written consent. Outcomes described relate to this engagement and are not a guarantee of results elsewhere.