A 28-story corporate headquarters case study — an internet-exposed BAS discovered during a cyber-insurance scan, a worked risk-prioritization matrix, VLAN segmentation and default-deny firewalling, credential and patch remediation, and the verification testing that proved it actually worked.
The project brief: Alderwood Financial Group's headquarters BAS — a nine-year-old, single-vendor Niagara installation with a shared admin account, a flat network, and a forgotten internet-facing port-forward — surfaces on an external attack-surface scan run for a cyber-insurance renewal. An outside controls/OT security engineer is brought in to assess, prioritize, remediate, and verify before the audit.
This module walks the whole engagement the way a real OT security assessment actually proceeds: a four-pass vulnerability assessment and its five findings, a worked likelihood-times-impact risk matrix that drove remediation sequencing, network segmentation and default-deny firewalling paired with credential rotation and a staged patch program, and the external re-scan, internal lateral-movement test, and credential audit that verified the fix — plus a before-and-after composite risk score. The full worked numbers, complete remediation action list, and finished reasoning are part of the unlocked module below.