In brief:
A UK food manufacturer had strong IT security and no OT monitoring. After UK manufacturing ransomware made national press, the board asked how long the business could afford to be down. The answer was 30 minutes. e2e-assure directed the manufacturer to a strategy partner first, then deployed Cumulo Standard OT. Result: 100 percent OT asset visibility, detection inside the 30-minute window, and a committed transition to full IT/OT under Cumulo Enterprise.
OT asset visibility
achieved from a zero baseline
Detection inside the
tolerable downtime window
Confidence in documented
business recovery plan
Committed transition to
Cumulo Enterprise
The organisation is a well-established UK food manufacturer operating production lines across multiple facilities. Uptime is critical to both business operations and revenue generation. Retail customers, distribution contracts, and shelf-life constraints mean that when production stops, the consequences compound by the hour. Spoiled product. Missed deliveries. Contractual penalties. Reputational damage with buyers who have alternative suppliers on speed dial.
The manufacturer had invested in IT security. Endpoint detection, cloud monitoring, and a managed IT SOC were in place and functioning. The corporate side of the business was covered but the production floor was not.
OT assets, the programmable logic controllers, SCADA systems, sensors, and industrial networking equipment that keep production lines running, had no security monitoring whatsoever. No asset inventory. No visibility into what was communicating across the production network. No detection of anomalous behaviour. If something was wrong, the first indication would be a line stopping.
The wake-up call came from outside the organisation. A series of cyber attacks on UK manufacturers made national news. Production plants were shut down. Output was lost. The stories were specific enough and close enough to home that the board asked a straightforward question: how long could we afford to be down? The answer was 30 minutes.
Thirty minutes of unplanned downtime before contractual penalties begin, before perishable product is at risk, before downstream supply chains start to feel it. And at the time, the organisation had no OT monitoring, no detection capability, and no way to identify a threat to production systems before it caused a physical impact.
What is tolerable downtime? Tolerable downtime is the time a production environment can be offline before commercial, contractual, or regulatory consequences begin. For UK food and beverage manufacturers, it is often measured in minutes due to perishability, retail penalty clauses, and just-in-time supply contracts. Detection capability needs to operate inside that window, not outside it.
The IT security operation was doing its job. But it stopped at the boundary of the production environment.
No monitoring of any kind on the production network. OT assets were unmanaged, uninventoried, and invisible to the security operation. The manufacturer did not have a complete picture of what was running on its own plant floor.
The manufacturer initially contacted e2e-assure without a defined OT security plan. Rather than push a deployment before the strategy was clear, e2e-assure directed the client to one of its trusted partners who specialise in OT security strategy and architecture.
That partner worked with the manufacturer to assess the OT estate, define security priorities, and build a phased plan for bringing production assets under monitored coverage. The output was a clear, actionable strategy that the manufacturer owned, not a vendor-led scope designed to maximise contract value.
With the strategy in place, the manufacturer chose e2e-assure to implement it through the Cumulo Standard OT platform.
The OT Telemetry Analyser was deployed across the manufacturer’s production facilities. Passive network scanning mapped every OT asset on the production network, many of which had never appeared in any previous inventory. Controllers, sensors, HMIs, and industrial networking equipment were identified, catalogued, and grouped by production line and criticality.
Each asset was profiled with a risk index and business criticality rating. A PLC controlling a primary packaging line carries a different risk weighting than a temperature sensor on a secondary cooling loop. That distinction matters when an analyst needs to decide how fast to escalate and what the operational impact of containment would be.
A behavioural baseline was established across the OT estate. Normal communication patterns, firmware states, and protocol usage were mapped so that deviations, whether from a misconfigured device, an unauthorised change, or something more deliberate, are flagged immediately. This is the layer of detection that did not exist before. It is also the layer that makes the 30-minute tolerable downtime window achievable rather than aspirational.
OT-specific detection rules were mapped to MITRE ATT&CK for ICS, tuned to the manufacturer’s environment rather than generic signatures.
SC-cleared analysts monitor the OT estate 24/7 from e2e-assure’s UK-based SOC. OT-specific playbooks and escalation procedures were developed with the manufacturer’s production management team. Containment protocols account for the physical consequences of action on a live production environment. Stopping a process incorrectly creates its own safety and commercial risks, and the playbooks reflect that.
Triage follows published SLAs with a full case audit trail. The manufacturer’s security and operations teams have direct analyst contact through Cumulo’s web interface and the SOC Channel app in Microsoft Teams.
The deployment also gave the manufacturer the evidence it needed for its business recovery plan. The board’s original question, “how long could we afford to be down,” now has a credible answer backed by live monitoring, defined response times, and tested escalation paths. That changed the board conversation from a risk they could not quantify to one they could demonstrate they were managing.
We came to e2e-assure not really knowing what we needed. They did not try to sell us something before we were ready. They pointed us to the right people to help us build a plan, and then they helped us deliver it. The fact that we can now show the board we have the OT environment monitored and a response time inside our tolerable downtime window is what changed the conversation at that level.
Operations Director - UK Food Manufacturer
The manufacturer now has continuous visibility across its entire OT production estate for the first time. The gap between tolerable downtime and actual detection capability has been closed. The board has confidence in the business recovery plan because it is built on live monitoring and tested response procedures, not assumptions.
100%
Every device on the production network is identified, catalogued, and monitored. The initial discovery found assets the manufacturer had no record of, including legacy controllers that had been running unmanaged for years.
<30m
Behavioural baseline monitoring and OT-specific detection rules mean threats to production systems are identified and escalated within minutes. The manufacturer moved from zero OT detection to a response time that fits within the window the board defined as critical.
Board
The resilience assessment that started this engagement now has a credible security foundation. The board sees live OT monitoring, defined SLAs, and tested escalation paths rather than an unquantified risk on a register.
Next
The manufacturer has been sufficiently confident in the Standard OT deployment that it has committed to transitioning to the full Enterprise IT/OT platform when its current IT incumbent contract expires. That will bring IT and OT monitoring under a single SOC operation, unifying the kill chain across both environments.
The engagement began with strategy and is expanding toward full convergence. The relationship started before the first sensor was deployed and will continue as the manufacturer brings its IT monitoring into the same platform.
Three patterns from this engagement transfer to other UK food, beverage, and FMCG manufacturers with strong IT security and limited OT monitoring.
For food manufacturing organisations evaluating OT SOC coverage, Unified IT/OT Threat Detection covers how e2e-assure structures detection and response for environments like this one.
e2e-assure operates a UK-based SOC with SC-cleared analysts across every role. Cumulo Standard OT is the OT-focused starting tier; Cumulo Enterprise is the unified IT/OT tier. The platform deployment includes asset discovery, behavioural baselining, and OT-specific detection content as standard.
The strategy-first approach is the engagement model. Where the right answer is to introduce a strategy partner before deploying platform, that is what happens. The credibility that follows is one of the reasons UK manufacturers continue to consolidate around the e2e-assure portfolio over time.
Schedule a discovery call to understand how Cumulo Standard OT can close the gap on your production floor.
Unified IT/OT Threat Detection – from OT-only coverage to full convergence under one platform.
Tolerable downtime is the time a production environment can be offline before commercial, contractual, or regulatory consequences become unacceptable. For UK food and beverage manufacturers, the threshold is typically measured in minutes rather than hours because of perishability, retail penalty clauses, just-in-time supply commitments, and seasonal demand patterns. The number drives every subsequent design decision: detection latency target, response time, containment authority, recovery procedures, and platform tier.
Trace the commercial, contractual, and regulatory consequences of a production stop across time, then identify the point at which those consequences become unacceptable. For food manufacturers, the inputs typically include perishable product value at risk, retail supply contract clauses, just-in-time replenishment commitments, energy and refrigeration constraints during shutdown, and brand or reputational exposure. The output is a single number, measured in minutes for most food and beverage operators, that becomes the design parameter for every subsequent decision.
Start with strategy, not technology. A clear OT security strategy defines priorities, scope, and a phased plan before any platform is deployed. Once the strategy is owned by the manufacturer, technology selection can be matched to it. A vendor-led approach inverts this order, which leads to scope inflation, the wrong outcomes being measured, and slower deployment. Engaging a trusted OT strategy partner before platform selection is the structural shortcut.
Cumulo Standard OT is e2e-assure’s OT-focused detection platform. It delivers OT-specific monitoring, asset discovery, behavioural baselining, and OT-tuned detection content for manufacturers with an existing competent IT SOC. It is typically the right starting tier when the production floor needs OT-specific coverage but the IT SOC arrangement is otherwise sound. Cumulo Enterprise (full unified IT/OT) is the natural progression when the IT contract renews and unification becomes operationally sensible.
Discovery and baselining typically take weeks rather than months when the right passive scanning approach is used. The exact duration depends on site count, network segmentation, and the level of existing documentation. In this engagement, the discovery phase produced the first verified OT inventory the manufacturer had ever had, including controllers that had been added during commissioning and never returned to the central inventory.
The IT SOC alone cannot cover OT properly. IT detection tools are built around endpoint, identity, and corporate network telemetry. They do not understand industrial protocols, cannot accurately fingerprint OT assets, and produce false positives on routine industrial traffic. OT environments need passive protocol-aware scanning, a behavioural baseline of normal operations, and OT-specific detection content authored against that baseline. The platform tier and the analyst tier both need to be OT-aware.
Both engagements address UK manufacturers with significant OT estates, but the starting positions differ. The defence manufacturer was running an IT-only SOC during business hours and needed unified 24/7 coverage immediately. The food manufacturer had a competent IT SOC and needed OT-specific coverage built from a zero baseline, with a clear strategy in place first. Cumulo Enterprise applies in the first case; Cumulo Standard OT with a planned transition to Enterprise applies in the second.
Response playbooks distinguish between situations where a controller can be isolated quickly and situations where containment needs to be timed against production realities. Stopping a line mid-batch can produce ruined product and contractual exposure that compounds the cyber incident. The playbooks are authored with operations and production management at the table, not in a security team away-day. Each containment action has a defined authorisation path, operational impact, and response time.
Schedule a discovery call with our expert team to learn how Cumulo Standard OT can build visibility from zero inside your tolerable downtime window.