Privileged access overhaul for a manufacturer
Cut standing privileged access 90% across a manufacturer's IT and OT estate.
90%
Problem, approach, and the outcome
The client is a German manufacturer whose admin rights had accumulated for years across both IT and shop-floor OT systems. On the OT side, a compromised privileged account can halt production, not just leak data.
Standing privilege had spread far beyond who actually needed it, and any fix had to avoid breaking the access engineers genuinely relied on to keep lines running.
Admin rights had accumulated for years across both IT and shop-floor OT systems, far beyond who actually needed them. Privilege sprawl had become the norm.
Every standing privileged account was a target, and on the OT side a compromise could halt production, not just leak data. The consequences reached into physical operations.
The manufacturer had to shrink that exposure without breaking the access engineers genuinely relied on to keep lines running. Security could not come at the cost of production.
We moved privileged access to just-in-time, approval-gated elevation, so rights exist only when needed and expire automatically. Removing standing privilege is the single biggest reduction in attack surface here.
The model spanned IT and OT together, with session recording on every elevated session for accountability. Covering OT as well as IT is what closed the most dangerous gap.
We mapped real access needs first, so the cutover removed standing rights without stranding the people who needed them, and rollout was staged by system criticality, proving the workflow on lower-risk estate before touching production OT. Exposure fell sharply without disrupting the line.
- 90% cut in standing privileged access
- Just-in-time elevation across IT and OT
- Every privileged session recorded
- Cutover made without disrupting production access
More Cybersecurity case studies

Zero-trust rollout for a government agency
Rolled zero-trust access to 25,000 civil servants without a productivity dip.
Read the full case study
Customer identity rebuild for a wealth platform
Passwordless identity cut account-takeover 22% and sign-in friction at a wealth platform.
Read the full case study
Red-team engagement against a fintech app
Found and helped close three account-takeover paths before a fintech's launch.
Read the full case studyGet a senior architect on the call, first time, every time.
No SDR gauntlet. 30 minutes with an engineer who can scope the problem, name the risks, and give you an honest feasibility call.
