
An operator whose operational technology had been assessed with methods designed for corporate IT, producing findings its engineers could not act on.
Operational environments do not tolerate the assumptions that IT assessments make. Systems cannot always be patched on an IT cadence, active scanning can be genuinely unsafe, and availability is frequently the dominant concern rather than confidentiality.
Applying an IT playbook produced a report full of findings the engineering team could not implement without unacceptable operational risk — so nothing changed.
The findings were framed in terms the engineering team could act on, so remediation actually happened instead of stalling on impossible recommendations.
Security and operations ended up working from a shared view of risk rather than competing priorities.
This is an anonymised, representative engagement. We do not publish client names, or figures we cannot substantiate, without explicit permission — in government and critical infrastructure, naming a client can itself be a security concern.