In brief:
A large UK retailer believed its incumbent managed security service provider was monitoring operational technology across its logistics estate. A compliance audit revealed otherwise. The MSSP had applied IT detection tools to OT traffic. e2e-assure replaced the arrangement with Cumulo Enterprise: 60 percent better detection rule quality, 80 percent faster detection, full asset visibility, live board-level compliance dashboards.
Improvement in detection
rule quality on OT traffic
Reduction in mean time
to detect across logistics
OT asset visibility including
previously unknown assets
Compliance dashboards
reporting to the board
The organisation is a large UK retailer operating a large-scale logistics and distribution network. Automated warehousing, conveyor systems, environmental controls, and inventory management infrastructure run on OT networks across multiple sites. The IT estate is equally substantial: cloud services, point-of-sale systems, e-commerce platforms, and a corporate network supporting thousands of employees.
Retail logistics runs on uptime. A conveyor system failure at a regional distribution centre during peak trading does not just cost money. It delays deliveries, disrupts store replenishment, and damages customer trust in ways that take months to recover from.
The retailer had recognised the growing risk to its OT environment and asked its incumbent MSSP to extend monitoring to cover logistics assets. The provider confirmed this was in hand. For months, the organisation believed it had OT coverage.
Then came the compliance audit.
The verification questions: Ask any MSSP claiming to monitor OT for three artefacts: the verified OT asset inventory, the behavioural baseline, and the list of industrial protocols being parsed. If any are absent, the MSSP is most likely applying IT detection tools to OT traffic.
The audit revealed that the MSSP had not deployed OT-specific monitoring. Instead, it applied IT detection tools to OT network traffic. The result was a setup that could not accurately identify OT assets, distinguish normal operational behaviour from anomalous activity, or parse the industrial protocols running across the logistics estate.
The organisation had no verified asset inventory. No behavioural baseline. And no way to demonstrate to auditors that its OT environment was being properly monitored.
The provider had not acted in bad faith. It had used the tools it had. But IT security tooling is not designed for OT environments. It generates false positives against normal SCADA and ICS traffic patterns, misses protocol-level threats it was never built to detect, and cannot provide the asset-level visibility that compliance frameworks require.
e2e-assure was selected through a competitive process that explicitly tested for the three verification artefacts before any commercial discussion began.
IT detection tools are built around endpoint, identity, cloud, and corporate network telemetry. Their signature libraries assume the protocols, traffic patterns, and asset behaviours of corporate IT estates. They do not understand Modbus, DNP3, or OPC-UA.
The gap was not effort. It was tooling and expertise.
The incumbent used enterprise IT detection technology to monitor industrial network segments. These tools do not understand OT protocols, cannot accurately fingerprint OT assets, and produce unreliable alerts when applied to traffic patterns they were not designed to interpret.
Without passive OT-specific scanning, the organisation had no authoritative record of what was running on its logistics network. Shadow assets, legacy controllers, and devices communicating on unexpected ports were invisible.
IT detection relies on known-bad signatures and endpoint telemetry. OT security requires a baseline of normal operational behaviour so deviations, such as unexpected firmware updates, configuration changes, or unusual communication patterns between controllers, are flagged before they become incidents.
Cumulo Enterprise was deployed across the retailer’s OT estate with passive OT Telemetry Analysers at each distribution centre. Asset discovery ran first. Devices were identified by protocol fingerprint and by behavioural signature, then classified by business criticality (production-critical, safety-related, supporting, observational).
Behavioural baselining followed asset discovery. Normal protocol patterns, normal firmware states, normal communication windows were recorded across the estate. Detection content was authored against the baseline rather than against generic IT signatures, so rules fire on deviations that matter to OT, not on traffic patterns that simply look unusual to an IT engine.
IT telemetry from endpoint, identity, cloud, and network estates fed the same Cumulo Enterprise platform. The SOC now triages IT and OT events through one case workflow, with one team, mapped to one set of compliance outcomes.
The OT Telemetry Analyser was deployed across the retailer’s logistics infrastructure. Passive network scanning identified and catalogued every OT asset, including devices the organisation did not know were on the network.
Each asset was profiled with a risk index and business criticality rating tied to its role in the distribution chain. A conveyor controller at a primary distribution centre carries a different risk weighting than an environmental sensor in a secondary warehouse. That context matters when an analyst is deciding how fast to escalate.
A behavioural baseline was established across the OT estate, mapping normal communication patterns, firmware states, and protocol usage. This is what IT tools cannot replicate. Once the baseline is in place, the SOC sees deviations from expected behaviour rather than relying on signature-based detection that was never built for industrial protocols.
OT telemetry was correlated inside Cumulo alongside the retailer’s existing IT sources: EDR, cloud, identity, and log data. The SOC now tracks threats as a single kill chain across both environments. An attacker moving from a compromised corporate endpoint toward a logistics controller appears as one incident, not two unrelated alerts in separate dashboards.
SC-cleared analysts monitor the full estate 24/7 from e2e-assure’s UK-based SOC. Detection rules are mapped to MITRE ATT&CK for ICS, with OT-specific playbooks tailored to the retailer’s logistics environment. Escalation procedures and containment actions were agreed with the operations team before go-live, so an alert on a distribution centre controller follows a defined path that accounts for operational impact.
Triage follows published SLAs with a full case audit trail. The retailer’s security team and operations leadership have direct analyst contact through Cumulo’s web interface and the SOC Channel app in Microsoft Teams, giving them real-time case visibility without waiting for email reports.
Compliance dashboards now run live, mapped to the frameworks that triggered the original audit failure. The board sees OT security posture in the same reporting cycle as IT, with evidence chains that auditors can verify without weeks of manual preparation.
The audit was uncomfortable. We thought we had OT monitoring in place and we did not. What changed is not just that we have visibility now. It is that we can prove it. The compliance dashboards go straight to the board and the conversation has shifted from 'are we covered' to 'here is what we are seeing.
CISO, UK Retail Organisation
The retailer now has verified, continuous visibility across its entire OT logistics estate and IT environment, monitored as a single operation. The compliance gap that triggered the engagement has been closed. More importantly, the organisation now has the detection quality and speed it needs to protect infrastructure that directly supports trading operations.
60%
OT-specific detection rules replaced repurposed IT signatures. False positives dropped. The alerts that reach the SOC are actionable, not noise generated by tools that do not understand industrial traffic.
80%
Behavioural baseline monitoring catches deviations in OT traffic patterns as they happen, not hours or days later. Threats that would have been invisible under the previous arrangement are now surfaced in minutes.
100%
The initial discovery phase identified assets the retailer had no record of, including legacy controllers and devices communicating on undocumented ports. The asset inventory is now authoritative and maintained continuously.
Live
Audit preparation that previously required weeks of manual evidence gathering now runs from CUMULO’s compliance dashboards, mapped to the frameworks the organisation is measured against.
The engagement is ongoing. As the retailer expands its automated warehousing and logistics infrastructure, new sites are onboarded into the CUMULO platform during commissioning. The SOC scales with the operation.
Two patterns from this engagement transfer to other retailers and logistics operators with significant OT estates.
For retail organisations evaluating 24/7 SOC coverage, Unified IT/OT Threat Detection covers how e2e-assure structures detection and response for environments like this one.
e2e-assure operates a UK-based SOC with SC-cleared analysts across every role. CUMULO Enterprise unifies IT and OT detection inside one case workflow. Asset discovery, behavioural baselining, and OT-specific detection content are built into the platform deployment, not retrofitted afterwards.
The case-study verification model used during procurement is the same model used during ongoing operations: any claim about OT coverage is testable by the artefacts that prove it.
Schedule a discovery call to verify your OT coverage and learn how CUMULO Enterprise can close the gap.
Unified IT/OT Threat Detection for clarity across your entire estate, from warehouse floor to cloud.
Ask for three artefacts: the verified OT asset inventory, the behavioural baseline of normal operations, and the list of industrial protocols being parsed by the detection content. An MSSP that genuinely monitors OT can produce all three on request. An MSSP that has been applying IT detection tools to OT traffic cannot. The verification is structural; reporting cadence and dashboard count do not test it. Run the verification before your next compliance audit does.
IT detection tools are built around the protocols and traffic patterns of corporate IT estates: HTTPS, SMB, Kerberos, DNS, EDR telemetry, identity logs. Their signature libraries are tuned to those patterns. When the same signatures hit Modbus, DNP3, or OPC-UA traffic, routine industrial protocol exchanges look anomalous and fire alerts. Volume rises. Analysts stop reading the OT alerts. The MSSP’s dashboards still look healthy, because they show signature counts rather than detection accuracy.
A behavioural baseline is a record of how a specific OT estate normally communicates: which devices talk to which, on which protocols, at which intervals, with which firmware versions, and through which sequences. Detection content authored against the baseline fires on deviations that matter operationally. Detection content authored against a generic signature library fires on traffic that looks unusual to the library but is routine on the production line. The two approaches produce very different outcomes.
In this engagement, discovery and baselining across automated warehousing, conveyor systems, and regional distribution centres were completed during the early phase of the deployment. The exact duration depends on site count, network segmentation, and the level of existing documentation. Across UK retail logistics estates, discovery typically takes weeks rather than months when the right passive scanning approach is used. The output is a verified inventory that the previous arrangement could not produce.
Yes, where the retailer operates automated warehousing, conveyor and distribution systems, environmental controls, or industrial networking equipment. NIS2 extends regulatory scope to more retail operators than the original NIS Directive. Audit and insurance pressure already requires verified OT monitoring evidence. IT-only coverage misses the parts of the business that produce the most operational impact when they fail.
Cumulo Enterprise is e2e-assure’s unified IT and OT detection platform. It ingests telemetry from corporate IT estates (endpoints, identity, cloud, network logs) alongside industrial protocol telemetry from OT environments, and produces a single case workflow across both. Detection content includes OT-specific rules authored against behavioural baselines rather than IT signature libraries applied to OT traffic.
Compliance dashboards are mapped to the frameworks the retailer’s board and auditors actually report against. NIS2, IEC 62443, NCSC CAF, and internal audit requirements all map cleanly. The dashboard reports the same underlying telemetry that the SOC uses operationally, so there is no parallel reporting layer. Evidence is produced from the same source data that runs live detection, which is what compresses audit cycles.
The structural pattern is similar: passive OT discovery, behavioural baselining, OT-specific detection content, unified case management with IT. The procurement trigger is different. In retail, the trigger here was an audit failure with an existing MSSP. In food manufacturing, it is typically a board-level question about tolerable downtime. In CNI, it is regulatory pressure around data sovereignty and dual-SOC consolidation. The platform and operating model are consistent across all three.
Schedule a discovery call with our expert team to learn how unified IT/OT monitoring can protect your retail and logistics estate.