WhitepaperRansomware Readiness: A Field Playbook for East African Enterprises
The decisions that determine whether a ransomware event is a bad week or an existential one — and which of them have to be made before the encryption starts.
Operational technology secured without stopping the line — passive assessment first, zone-and-conduit design to IEC 62443, and segmentation staged so nothing goes down unexpectedly.

When a breach stops the line.
Industrial environments carry the hardest version of the segmentation problem: the networks that most need isolating cannot be taken offline to do it, the equipment may run software that cannot be patched or restarted casually, and the cost of an unplanned stop is measured in lost production and sometimes in safety.
Standard enterprise guidance assumes you can change a rule, observe what breaks, and roll back. On a production line that assumption does not hold, which is why so many plants are nominally segmented — a firewall between business and plant networks — while carrying a long exception list, a flat plant network behind it, and vendor remote access that bypasses it entirely.
Our approach is staged and passive by default. Observe first, design zones and conduits on paper, then enforce in increments with a tested rollback at each step. It is slower than a single cut-over, and it is the reason the work actually finishes.
The most common serious industrial incident is not a targeted control-system attack but ordinary ransomware reaching the plant because nothing stopped it — shared credentials, a flat network, or a dual-homed engineering workstation.
Equipment suppliers legitimately need to reach their machines, and the arrangements predate the current security programme: a cellular modem installed by the vendor, a persistent tunnel, shared credentials, no logging. This is the conduit we find most often.
Behind the perimeter firewall, controllers, human-machine interfaces, historians and engineering workstations frequently share one broadcast domain. One compromised asset reaches the whole process.
Equipment with a twenty-year service life runs software whose vendor support ended a decade ago. Compensating controls carry these assets; a patching policy does not reach them.
A laptop connected to both the plant and business networks is a routed path regardless of the firewall, and removable media carried between zones is the same thing more slowly. Neither is solved by network architecture.
Business-to-plant data exchange is a genuine requirement and the usual justification for the exception list. It belongs in a demilitarised zone with no direct flows, which is almost never how it was first built.
The sequence below is what a manufacturing engagement looks like in practice — shaped by what your environment can and cannot tolerate.
Talk to our Manufacturing teamPassive monitoring on span or tap ports changes no configuration and risks nothing on the control network. Four to six weeks across a full production cycle produces the real communication matrix — which reliably contradicts the documentation.
IEC 62443’s model gives plant engineering and IT security a shared vocabulary. Every observed flow is then either assigned to an explicit conduit with a named owner, or marked for removal.
Enforcement points go in monitor mode first, reporting what they would have blocked. Review with plant engineering, resolve the surprises, then move to alert, then block one conduit at a time in a planned window with a tested rollback.
Every supplier path consolidates into one brokered route — authenticated per engineer, time-bound, approved per session and recorded — replacing the modems and tunnels nobody has an inventory of.
Each of these is a published instrument you can read. We map findings to them directly, so an assessment feeds your audit and supervisory cycle instead of sitting beside it.
WhitepaperThe decisions that determine whether a ransomware event is a bad week or an existential one — and which of them have to be made before the encryption starts.
Threat AdvisoryThe mailbox-rule and supplier-impersonation patterns we keep finding in finance departments, with the detection logic and the four controls that stop them.
Industry BriefA staged approach to industrial network segmentation for plants that cannot take downtime, mapped to the IEC 62443 zone-and-conduit model.