An independent follow-up assessment of technical resilience, Microsoft 365, network segmentation, vulnerabilities and demonstrable control.

The organisation

An internationally operating industrial company processes and markets steel products. Availability of IT, logistics systems, applications and network connections is important for daily production and service.

The reason

A few years earlier, the organisation had carried out a comprehensive cybersecurity audit. With an independent follow-up assessment, the organisation wanted to identify the progress actually made, the risks that were still present and the priorities that made sense for the following year.

The approach

Kynexis Information Security combined documentation review, interviews, Microsoft 365 rating and firewall, network scans, vulnerability scans, segmentation research, WiFi controls, physical tour and assessment of vendor and change processes.

The general picture

The overall image was positive. Network segmentation, WiFi separation, Microsoft 365 security, hardening, awareness, monitoring and disaster recovery were significantly improved.

Strong improvement of network segmentation

Office and guest networks were well separated, client isolation worked, unwanted categories were blocked and the network drawing was quickly available.

Microsoft 365 at a good basic level

The Microsoft 365 environment showed a super-average Secure Score, Conditional Access, MFA requirements and no recent active non-compliant devices.

Monitoring was demonstrable

During the audit, increased network activity was generated. This was detected by external monitoring and led to a warning. At the same time, it remained unclear who checked whether all the logs were delivered correctly.

Disaster recovery

The organisation had a disaster recovery facility almost fully operational. The next step was to formally define recovery tests, RTO, RPO, results, deviations and responsibilities.

The biggest governance problem: proof implementation

The IT service provider worked with RFCS and change records. These describe the planned change, but often do not contain sufficient evidence that the change was actually carried out, tested and accepted.

A planned security measure is not yet a demonstrable security measure.

Fragmentary policy documentation

The organisation had several policy documents, forms, RFCs, tickets and procedures, but without one identifiable document structure or single source of truth.

Vulnerabilities significantly reduced

The quantity and severity of technical vulnerabilities had clearly decreased. The remaining critical and high vulnerabilities were mainly in outdated web and application servers, embedded equipment, industrial components, legacy protocols and weak encryption standards.

Application and server lifecycle management

It was necessary to clarify who was responsible for the application layer, which supplier patches performed, which deadlines were applicable and how compatibility was tested.

Industrial and embedded equipment

The audit also included printers, hand scanners, industrial components, debug services and OT-like systems. This underlined that industrial cybersecurity goes beyond office IT.

Firewall and additional security

The firewall was actively managed. There were still opportunities around sandboxing, device visibility, IoT detection, threat feeds, outbreak prevention, log retention and clear monitoring responsibilities.

AI policy, data leaks and incident response

The documentation review provided improvement points for acceptable ICT use, data breach procedures, AI usage, patch management, incident response and privacy statements.

Follow-up with board-level risk analysis information security

The next step was to prioritize risks more administratively. Risk analysis helps to identify opportunity and impact, prioritise measures, weigh costs and benefits and consciously accept residual risks.

The result

  • objective understanding of progress since the previous audit;
  • confirmation that network segmentation had improved significantly;
  • Microsoft 365 security insight;
  • evidence that monitoring functioned;
  • an overview of remaining vulnerabilities;
  • application and server management improvement points;
  • understanding of OT and embedded risks;
  • an improvement plan for demonstrable assurance;
  • advice for a risk analysis information security.

Why this approach worked

The audit did not only assess whether technical measures were in place. It was also checked whether they were correctly executed, tested, effective, periodically assessed, linked to an owner and were part of board-level control.

Follow-up: assessment of a new logistics application

From Kynexis Information security is now also accompanied by an IT security assessment for a new logistics application and the links with internal systems. The application should support transport and logistics settlement. That is why we assess the application, access, data flows, links, supplier responsibilities and continuity as a whole.

Have a cybersecurity audit done?

  • Cybersecurity audits and technical assessments
  • Vulnerability scans and Microsoft 365 security audits
  • Firewall reviews and network segmentation
  • OT and IoT risk analyses
  • Information security risk analysis and periodic follow-up assessment