Back to Manufacturing IT
    Case Study

    How a Precision Manufacturer Eliminated Unplanned Downtime

    A 150-employee precision machining company in southeastern Wisconsin was facing increasing OT/IT convergence risks. Flat networks, unpatched HMIs, and zero segmentation between CNC controllers and corporate systems put production and compliance at risk.

    Precision Manufacturing150 EmployeesSoutheastern WisconsinCMMC Compliance
    0
    Unplanned downtime incidents since go-live
    40+
    Connected OT devices segmented and secured
    100%
    CMMC Level 2 audit readiness achieved
    <15 min
    Average incident response time

    The Challenge

    The company operated 40+ networked devices on the production floor — CNC machines, PLCs, HMIs, SCADA monitoring stations, and environmental sensors — all sharing a single flat network with corporate workstations, email, and ERP systems.

    A ransomware incident at a peer manufacturer in the region was the wake-up call. Leadership realized that a single compromised email attachment could propagate laterally into production systems, potentially bricking CNC controllers and halting output for days or weeks.

    Adding urgency: the company was pursuing defense contracts requiring CMMC Level 2 certification. Their existing network architecture would not pass an audit.

    Our Approach

    1
    Weeks 1–2

    Discovery & Risk Assessment

    • Full inventory of OT assets: CNC controllers, PLCs, HMIs, SCADA systems, and networked sensors
    • Network topology mapping — identified 40+ devices on a flat, unsegmented network
    • Vulnerability scan of production and administrative systems
    • Compliance gap analysis against CMMC Level 2 and NIST 800-171 controls
    2
    Weeks 3–6

    Network Segmentation & Hardening

    • Designed and implemented Purdue Model-based network architecture
    • Created isolated VLANs for OT systems, corporate IT, guest access, and management
    • Deployed next-generation firewalls with OT-aware protocol inspection (Modbus, EtherNet/IP, OPC-UA)
    • Configured micro-segmentation between CNC controller groups to limit lateral movement
    • Hardened HMI and SCADA workstations — removed unnecessary services, enforced application whitelisting
    3
    Weeks 7–10

    Monitoring, Backup & Compliance

    • Deployed 24/7 network monitoring with OT-specific anomaly detection
    • Implemented air-gapped backup strategy for critical production configurations
    • Built CMMC Level 2 documentation package: SSP, POA&M, and incident response plan
    • Conducted tabletop disaster recovery exercise with plant leadership
    • Security awareness training tailored to manufacturing floor staff

    The Results

    Within 10 weeks of engagement, the manufacturer achieved full OT/IT network segmentation following the Purdue Model. Production systems were isolated from corporate infrastructure, and micro-segmentation prevented lateral movement between CNC controller groups.

    Since project completion, the company has experienced zero unplanned downtime from IT-related incidents. Their CMMC Level 2 documentation package was accepted by the assessment organization, and they successfully won two new defense contracts within six months.

    "Collett Systems didn't just put in a firewall and call it done. They understood our production environment — they walked the floor, identified every connected device, and built a network architecture that protects our CNC controllers without slowing down production. We passed our CMMC audit on the first attempt."

    — VP of Operations, Precision Manufacturer, Southeastern Wisconsin

    Technologies & Protocols

    Purdue Model Architecture
    VLAN Segmentation
    Next-Gen Firewalls
    Modbus TCP/IP
    EtherNet/IP
    OPC-UA
    SCADA Monitoring
    Application Whitelisting
    Air-Gapped Backups
    CMMC Level 2 Controls
    NIST 800-171
    24/7 OT Monitoring

    Is Your Production Floor at Risk?

    Book a free plant floor IT assessment. We'll map your OT environment, identify vulnerabilities, and deliver a prioritized action plan — no obligation.

    (262) 384-4400