IndustrialClient not identifiedIEC 62443-3-3ENS · mp.comA flat industrial network sharing a broadcast domain with office IT
The line controller and an external supplier's laptop reached the administrative machines directly. Any email opened in the office had a path down to the plant floor.
Zoning and conduits per IEC 62443-3-3. National framework communication-protection measures applied to the corporate segment. Asset inventory as a verifiable baseline.
Local governmentEntity not identifiedRD 311/2022EN 301 549An e-government portal that worked but could not be evidenced
The online procedure had been running for two years and nobody complained. There was no risk analysis, no system categorisation, no statement of applicability and no accessibility statement. In the first file that required medium category, there was nothing to submit.
Risk analysis, system categorisation and statement of applicability under the National Security Framework. Portal reviewed against EN 301 549, with the accessibility statement published complete with method and date.
Private care homeEntity not identifiedArt. 9 GDPRContinuityA care centre whose backups had never once been restored
Backups ran every night and the report had come back green for three years. Nobody had ever attempted a restore, and the only accessible copy lived on the same network as the clinical records server.
Health data classified as a special category under Article 9 GDPR, a backup scheme with one replica disconnected from the network, and a full restore test measuring the real time back to service.
Tourist accommodationEntity not identifiedGDPRSegmentationA hotel where the guest wifi reached the booking server
The guest network, the point of sale terminal, the cameras and the booking server shared the same addressing. Any guest connected from their room could see the machine holding the reservations and the traveller register.
Guest network isolated, with client isolation between guests as well. Separate segments for the point of sale and for the cameras. Review of how traveller register data is processed and how long it is kept.
We never publish architectures, vendors, versions or console captures. Showing a client's blueprint would itself be a security incident.
Cases illustrating the working method. Client projects are documented under a confidentiality agreement.