How a UK Defence-Aligned Heavy Manufacturer Cut Detection Times by 70% With Unified IT/OT SOC

In brief:

A UK manufacturer of precision components for the defence supply chain replaced its business-hours IT-only SOC with 24/7 unified IT and OT monitoring under CUMULO Enterprise. Mean time to detect fell by 70 percent. Compliance reporting effort fell by 80 percent. Asset discovery identified 100 percent of OT devices on the network.

Outcomes at a Glance

70

Reduction in mean time to detect

80%

Less compliance reporting effort

100%

OT asset visibility at first scan

24/7

Unified IT/OT SOC SC-cleared analysts

The Challenge: Transformation Outpacing Security

The organisation operates multiple manufacturing sites producing precision-engineered components for the UK defence supply chain. Revenue sits in the mid-hundreds of millions. The environment is mixed: legacy SCADA systems running alongside newer OT networks introduced as part of a wider digital transformation programme. IT infrastructure spans on-premise and cloud. Regulatory obligations include NIS2, IEC 62443, and defence-specific supply chain security requirements.

The transformation programme was accelerating. New production lines were coming online. A new OT network was being rolled out across facilities. And the attack surface was growing faster than the security team could map it.

Their existing managed security provider covered IT endpoints and perimeter during business hours only. That left nights, weekends, and the entire OT estate without active monitoring. No one was watching the plant floor. No one was correlating IT and OT events as a single kill chain.

Why an IT-only SOC was structurally insufficient

The incumbent provider was not underperforming against their original brief. The brief had simply been overtaken by the business.

  • No OT visibility

    The existing SOC had no capability to ingest or interpret ICS/SCADA telemetry. OT assets were invisible to the security operation.

  • Business-hours-only coverage

    Monitoring ran during the working day. The manufacturing floor runs around the clock. An incident at 2am on a Saturday would go undetected until Monday morning.

  • No unified kill-chain view

    IT and OT were treated as separate domains. Lateral movement between environments would not be tracked as a single incident.

Why correlation matters: Attackers cross the IT-to-OT boundary deliberately. A phished credential becomes lateral movement, which becomes a hop toward a process controller. If IT events and OT events sit in separate systems, the analyst sees two unrelated incidents. With unified correlation, the analyst sees one kill chain.

The e2e-assure Approach: Cumulo Enterprise Across the Estate

The engagement began with a scoping exercise across all manufacturing sites to map the OT estate, identify protocol types, and baseline normal operational behaviour. e2e-assure deployed the Cumulo Enterprise platform to deliver a unified IT/OT SOC, covering both existing IT infrastructure and the newly expanded OT network.

Detection and visibility

The OT Telemetry Analyser was deployed across the client’s manufacturing sites with minimal operational disruption. It was configured to passively scan ICS and SCADA protocols without interfering with production systems.

Telemetry from the OT environment was correlated inside Cumulo alongside EDR, cloud, identity, and log sources from the IT estate. This gave the SOC a single, unified view of the entire attack surface  from plant floor to cloud.

OT assets were discovered, baselined, and grouped by process zone. Each asset was mapped with a risk index, safety impact rating, and business criticality score, giving analysts the context they need to make containment decisions in minutes rather than hours. The deployment also supported disconnected “war room” scenarios, ensuring SOC operations could continue even if connectivity to the wider network was severed during an incident. 

Response and containment

SC-cleared analysts now monitor the full estate 24/7 from e2e-assure’s UK-based SOC. All telemetry, case data, and encryption keys remain within UK borders at every stage.

Detection rules are mapped to MITRE ATT&CK for ICS, with OT-specific playbooks and escalation procedures agreed with the client’s plant management team. Safe-shutdown sequences were pre-agreed and tested before go-live, so containment decisions during a live incident do not risk unplanned production stoppages.

Triage follows published SLAs with a full case audit trail. The client’s team has direct analyst contact through Cumulo’s web interface and a dedicated SOC Channel app in Microsoft Teams, giving plant managers and the CISO visibility of live cases from their phones

We knew the OT network was a blind spot. What surprised us was how quickly the SOC started finding things we did not know were there. Within the first week, the asset discovery alone changed how we thought about risk across our sites.

The Outcome in Numbers

The organisation now has continuous, 24/7 threat detection and response across its entire IT and OT estate. Security is no longer a constraint on the transformation programme.

70%

Reduction in mean time to detect

From over 12 hours under the previous arrangement to under 15 minutes. Threats that would have gone unnoticed for an entire weekend are now surfaced and triaged in real time.

24/7

Unified IT/OT coverage

Every manufacturing site, every shift, every protocol. No more gaps between business-hours IT monitoring and round-the-clock production.

80%

Reduction in compliance reporting effort

Live dashboards mapped to NIS2 and IEC 62443 replaced manual evidence gathering. Audit preparation that took weeks now takes days.

100%

OT assets discovered and baselined

The initial deployment identified assets the client did not know existed on the network, including legacy devices with unpatched firmware communicating on unexpected ports.

What This Means for Defence Manufacturers

Three patterns from this engagement transfer cleanly to other defence supply chain manufacturers.

  • First, transformation programmes outpace IT-only security by default.
    New OT networks emerge faster than IT-trained tooling can map them. Continuous OT discovery is the only sustainable way to keep pace.
  • Second, defence supply chain compliance is moving from periodic attestation to continuous evidence.
    Defstan, NIS2 and the UK Cyber Security and Resilience Bill all tighten in that direction. Live dashboards mapped to recognised frameworks compress audit overhead while making evidence reviewable on demand.
  • Third, the analyst tier matters as much as the platform tier.    SC-cleared, UK-based analysts with OT-specific experience are the scarcest resource in the UK cyber labour market.  Outsourcing to a UK-sovereign provider is the only realistic way most defence supply chain manufacturers will obtain that depth in 2026.

Why e2e-assure

e2e-assure operates a UK-based SOC with SC-cleared analysts across every role. The Cumulo Enterprise platform unifies IT and OT detection within a single case workflow. Every telemetry record, every case file, every encryption key remains within UK borders.

Detection content is mapped to MITRE ATT&CK for ICS. Compliance dashboards are mapped to NIS2, IEC 62443, the NCSC Cyber Assessment Framework, and the MOD Cyber Security Model. Partnerships with EmberOT and Trinity OT provide additional protocol depth when required.

The engagement model is built around defence supply chain assurance from the design stage, not retrofitted to it.

Ready to close your OT blind spot?

Schedule a discovery call to learn how unified IT/OT monitoring can transform your security posture.

Related Service

Unified IT/OT Threat Detection clarity across your entire organisation

Frequently Asked Questions

What is unified IT/OT SOC monitoring?

Unified IT/OT SOC monitoring correlates telemetry from corporate IT systems (endpoints, identity, cloud, network logs) with industrial protocol telemetry from SCADA, ICS, and PLCs inside a single platform. Analysts see the full kill chain  from a phished credential to lateral movement toward a plant controller  as one incident rather than two separate ones.

In this engagement, mean time to detect dropped from over 12 hours to under 15 minutes, which is a 70 percent reduction. Outcomes are environment-specific, but a step-change of this scale is consistent across UK manufacturers moving from business-hours IT-only to unified 24/7 coverage with OT-specific detection content.

UK defence supply chain manufacturers handle data covered by the MOD Cyber Security Model and contractual security clearance obligations. SC clearance is the minimum bar for analysts who triage and contain incidents on those networks. Arrangements that route alerts through non-cleared analysts during out-of-hours periods do not meet the requirement.

Yes. Every telemetry record, case file, and encryption key remains within UK borders at every stage. Data residency is built into the platform deployment rather than added as a contractual overlay, which is what the MOD Cyber Security Model and the UK Cyber Security and Resilience Bill increasingly require.

Cumulo Enterprise is e2e-assure’s unified IT and OT detection platform. It ingests telemetry from corporate IT estates alongside industrial protocol telemetry from OT environments, producing a single case workflow. Cumulo Standard OT is the OT-focused tier for manufacturers with an existing IT SOC who need to add OT-specific coverage.

In this engagement, OT Telemetry Analysers were deployed across all production sites, asset discovery and behavioural baselining were completed, and live operation began within the first quarter. New facilities were onboarded as they were commissioned.

Safe-shutdown protocols are agreed with plant management before go-live and tested in controlled scenarios. During a live incident, analysts execute against pre-authorised playbooks rather than seeking real-time approval producing the step-change in containment time without increasing operational risk.

The OT Telemetry Analyser supports Modbus, DNP3, OPC-UA, and the common SCADA, ICS, and DCS protocols found across UK manufacturing. Coverage is passive. No packets are injected and no operational risk is introduced. Partnerships with EmberOT and Trinity OT extend the supported set.

Detection content is mapped to MITRE ATT&CK for ICS. Compliance dashboards are mapped to NIS2, IEC 62443, the NCSC Cyber Assessment Framework, and the MOD Cyber Security Model. Audit evidence comes from the same platform that runs live detection. No parallel reporting layer to maintain.

Ready to Strengthen Your Cyber Posture?

Schedule a discovery call with our expert team to learn how unified IT/OT monitoring can protect your defence organisation