The company
An 800-person Canadian manufacturing group, three production sites, conventional business IT and an industrial estate that has grown in layers over twenty years. The security team is two people, supported by an eight-person IT team.
The profile is common in the sector: an organisation whose business is to produce, not to do cybersecurity, but whose customers and insurers now demand evidence. Nobody there is hostile to security; it is simply that every hour spent on a compliance spreadsheet is an hour not spent on production.
The problem: the data existed, the picture did not
The trigger is commercial. A major customer asks for proof of posture before renewing the contract, with a three-week deadline. In parallel, an ISO 27001 effort has been under way for eighteen months with no clear milestone: everyone knows it is progressing, nobody can say how far.
Everything needed to answer already exists, spread across five places: the vulnerability scanner, a compliance spreadsheet maintained by one person, vendor questionnaires traded over email, the EDR, and the ticketing system. No single risk register, and therefore no quick answer to the only question that matters: where do we stand?
Producing a status report for the executive team takes three to four days of manual stitching, and the result is stale before it is presented. The real cost is not the time spent: it is that nobody can say, on an ordinary Tuesday, what the company's risk is.
On the industrial side the blind spot is sharper still. No visibility into what is actually reachable from the Internet. The controllers are assumed to be isolated — that belief rests on a 2019 network diagram and on the word of an integrator who no longer works there.
What gets put in place
One assessment, two frameworks
The baseline runs against NIST CSF 2.0 and ISO 27001 at once, carried by the 1,534-control SCF backbone: one entry feeds both, and every validated control advances everything attached to it. That is what turns eighteen months of scattered preparation into a measurable trajectory. Maturity is scored on a CMMI 0 to 5 scale, so the team stops arguing in “compliant / not compliant” and starts arguing in levels.
A register that fills itself
Findings from each module feed the 9 domains and 52 sub-domains of the risk register, inherent and residual. The status stops being a quarterly deliverable and becomes a permanent state the executive team can consult without asking for it.
The outside-in view, OT included
The external attack surface is mapped read-only, industrial protocols fingerprinted included, without ever touching production. The first scan surfaces fourteen critical exposures, five of them on assets nobody knew were exposed: a vendor portal from an abandoned project, two admin interfaces left open after a migration, an expired certificate on a production service, and an industrial supervision interface reachable from the Internet — precisely what the 2019 diagram said was impossible.
Third parties, continuously rather than once a year
The forty critical suppliers move under continuous monitoring. Their posture as observed by external scan is set against the posture they declared in the questionnaire, and the gap between the two is flagged. The scan covers a scope the supplier validated themselves, which makes the finding debatable in a review rather than accusatory.
What it yields
A defensible first measurement in four days: not a full audit, but a quantified starting point that can be presented without justifying it line by line. ISO 27001 compliance moves from 41% to 84% in eight months, not because the platform fixes anything, but because the order of work stops being arbitrary.
The executive report is produced in under an hour instead of three days, with every figure sourced in the platform. The auditor pack is exportable at any time. The GRC team gets back the weeks it spent stitching spreadsheets together — most of its time goes back to substance.
Commercially, the proof of posture the customer asked for is delivered in three days instead of the month originally estimated. It is often that kind of turnaround, more than the score itself, that decides a renewal.
What it does not fix
The platform does not reduce remediation effort. The fourteen critical exposures take real teamwork over six weeks, including two interventions in maintenance windows on the industrial side. What changes is knowing which ones to handle first and why — not that the work disappears. An organisation with nobody to fix things will get nothing but a better-sorted list.
Figures representative of real deployments. Organisations composite and anonymised.