Support
CASE STUDY
Chemical Processing

Chemical Processing

A global chemical processor achieved centralized OT asset visibility and security monitoring across nine plants and multiple ICS vendors with Industrial Defender.

DOWNLOAD CASE STUDY

Industrial Defender was the perfect tool to monitor security events across a number of different ICS systems and vendors.

Overview

Overview

A large chemical processor needed centralized OT asset visibility and security monitoring across nine plants running heterogeneous ICS systems from vendors including Honeywell, Schneider, Siemens, Woodward, Hima, Rockwell, and Yokogawa.

Key Outcomes
A centralized management console for assets, vulnerabilities, and overall risk
Security event monitoring in place to detect potential threats on endpoints
Network-level threat detection across the ICS environment
API-enabled integrations to share OT security data with IT teams
Background

Background

This customer is a large producer of chemicals including low-density polyethylene (LDPE), producing a wide range of chemical grades suitable for many plastic processing techniques and used across various applications.

Their environment consists of wide industrial networks comprised of heterogeneous ICS systems, including Honeywell, Schneider, Siemens, Woodward, Hima, Rockwell, and Yokogawa. Complete asset visibility and management was a challenge, with several teams running nine different plants with different groups and operators. The goal was to monitor and manage these systems from one location.

Strategic Priorities
  • Centralized asset visibility & management
  • Security monitoring
  • Risk reporting
  • Easy enterprise integration
Three Primary Objectives

Centralize Visibility & Management

Centralize asset visibility and management across nine plants running heterogeneous ICS systems.

Stay Ahead of Vulnerabilities

Effectively keep up with vulnerabilities in their devices across multiple ICS vendors.

Detect and Escalate Threats

Detect anomalies in the OT network and endpoints, and forward OT security events to the IT security team.

The Decision

Decision

The company deployed Industrial Defender to monitor and manage all of its OT assets across nine plants.

Immediate Issue Discovery

The moment the solution was implemented, they found problems they weren't previously aware existed — including a service account causing continuous failed logons from an unused service still running, which they were able to correct right away. They also found serious disk space issues on some of their OT devices.

Vulnerability-Driven Risk Prioritization

The vulnerability monitoring tool helped the company understand which devices in their system were at the greatest risk, letting them run a policy to confirm vendor-required patches had been applied successfully.

Automated Compliance Monitoring

They created an automated report to regularly monitor for any assets falling out of compliance with the new patch policy.

The Solution

A Unified OT Cybersecurity Platform

The Industrial Defender platform enables organizations to strengthen cybersecurity across multiple domains.

Asset Inventory Management

  • Automated asset discovery
  • Continuous inventory updates
  • Lifecycle tracking

Patch & Software Management

  • Authorized software lists
  • OS version tracking
  • Patch monitoring

File Integrity Monitoring

  • Detection of unauthorized file changes
  • Continuous verification

Configuration Monitoring

  • Unauthorized configuration detection
  • Port and service monitoring
  • Baseline comparison

User Account Monitoring

  • Admin account tracking
  • Unauthorized access alerts
  • Account expiration enforcement

Security Event Monitoring

  • Login anomaly detection
  • Log aggregation and correlation
  • Malware monitoring

Network Intrusion Detection

  • IDS deployment across networks
  • Detection of unusual activity
  • Threat filtering

Firewall Rule Monitoring

  • Configuration tracking
  • Baseline enforcement
  • Change detection

Together, these capabilities created a unified OT cybersecurity platform — delivering continuous visibility, automated monitoring, and audit-ready compliance across the utility's entire operational environment.

Results

Results

Centralized Event Visibility

All security events are now visible in one centralized location, with OT security events automatically forwarded to the IT security team.

Network Visibility Without Firewall Changes

Connecting to Level 2 switches let the team gather asset information without changing hard-coded firewall rules — a requirement that was very important to them.

Deep, Centralized ICS Visibility

The end result was deep, centralized visibility into their ICS network and endpoints across all nine plants.

Combined Active and Network-Level Monitoring

Through a combination of active OT data collection and network-level monitoring of devices and networks, the company was able to effectively manage risk, detect threats, and automate manual tasks.

Relevance

Relevance

Complex, multi-vendor OT environments with distributed plant operations need a single, vendor-agnostic platform to centralize visibility, streamline vulnerability management, and connect OT security data to IT teams.

Key Challenges
  • Heterogeneous ICS environments spanning multiple vendors (Honeywell, Schneider, Siemens, Woodward, Hima, Rockwell, Yokogawa)
  • Distributed plants managed by different teams and operators
  • Limited visibility into device-level vulnerabilities and risk
Industrial Defender Solutions
  • Centralized console for OT asset visibility, vulnerability, and risk management
  • Automated policy-based patch compliance monitoring
  • API-enabled integration connecting OT security data to IT security teams