Client Context
A major rail operator undertaking multiple concurrent technology programmes across operations, with significant IT/OT integration across ISA-95 Levels 1–4.
Ask / Requirement
A transport sector client engaged SIS to develop a risk-driven, enterprise-wide security architecture spanning IT and OT – aligned with business objectives and major technology initiatives across rail operations.
The requirement was to establish a consistent, business-aligned security blueprint across all ISA-95 levels, improve risk visibility, and define a clear transition path from current state to target state.
What We Delivered
SIS delivered a holistic Enterprise-Wide Security Architecture (EWSA) using SABSA aligned with IEC 62443, supported by a prioritised architecture roadmap and implementation plan.
The outcome provided the client with a single, coherent security reference architecture – with full traceability from business drivers to security controls – and a structured pathway to uplift cyber maturity across IT and OT environments.
Outcome
The organisation gained a defensible, unified security architecture capable of keeping pace with its technology programme. New initiatives could be assessed for security alignment before deployment, reducing rework and enabling consistent risk management across rail operations.
If you’d like to know more about our many years of experience in providing industrial cyber security solutions: