One Laptop Away from Chaos
A mid-sized FMCG manufacturer based in Tuas operated a single, flat network across its office, warehouse, and production floor. All devices — from executives’ laptops to warehouse handheld scanners and PLCs on packaging lines — shared the same broadcast domain. When a contractor’s infected USB drive introduced ransomware into the environment, the malware spread laterally within minutes, encrypting files on a server used for production scheduling and reaching a finance workstation storing unreleased quarterly reports. The incident halted line operations for 14 hours and triggered a PDPC data breach notification requirement. With expansion plans underway and third-party audits looming, the company faced not only reputational risk but also potential non-compliance with Singapore’s Cyber Essentials Mark framework for SMEs.
Flat Design, Hidden Exposure
Initial assessment revealed a network segmented only by function at the physical level — servers in a locked room, workstations in the office — but logically unified under a single /24 subnet. There were no VLANs, no firewall enforcement between zones, and no NAC controls. The production VLAN, which hosted HMIs for batch mixing and filling machines, was accessible from any user port. Guest Wi-Fi terminated on the same switch stack as the ERP database. NetFlow analysis showed constant SMB traffic between workstations and SCADA-adjacent systems, confirming lateral movement paths. The client believed their firewall at the internet edge was sufficient, unaware that internal compromise could bypass it entirely. VLAN tagging was disabled across all switches, and routing between segments was handled by a consumer-grade router masquerading as a core gateway.
Divide, Isolate, Enforce
We redesigned the network architecture around zero-trust segmentation principles using hardware from HPE and Palo Alto Networks. First, we deployed an HPE Aruba 5400R core switch to serve as the backbone, enabling full VLAN segmentation across 12 new broadcast domains. Separate VLANs were established for finance, HR, production control, warehouse logistics, guest access, and IoT devices such as temperature sensors in cold storage. We installed a Palo Alto PA-3220 firewall in active-passive high availability and configured it to enforce inter-VLAN policies, blocking unauthorized traffic by default. For example, the warehouse handheld VLAN can only initiate connections to the WMS server on TCP 1433, while the production VLAN is restricted to outbound traffic on port 502 (Modbus) to specific PLCs. We implemented 802.1X authentication using RADIUS integration with Active Directory, ensuring only registered devices gain access to corporate VLANs. Guest traffic is now routed through a dedicated SSID on Aruba access points, terminated at the firewall with bandwidth throttling and DNS filtering. All switch ports were reconfigured with port security and BPDU guard to prevent rogue device bridging.
From Fragile to Fault-Tolerant
Post-implementation, internal penetration tests showed a 98% reduction in exploitable lateral paths. A simulated ransomware event on a user workstation failed to reach any system outside its VLAN, including the ERP and production servers. Network uptime improved from 97.2% to 99.95% monthly average, with mean incident resolution time dropping from 3.8 hours to 22 minutes. The client passed its subsequent ISO 27001 surveillance audit with no findings related to network architecture. Over six months, the number of detected and blocked internal suspicious connections rose to 47 — evidence that threats were being contained rather than spreading. The finance team reported faster ERP response times due to reduced broadcast traffic, and the operations manager confirmed no downtime incidents linked to network issues in the 10 months since the redesign.
Assume Breach, Design Accordingly
For Singapore-based manufacturers, the lesson isn’t just about deploying firewalls or VLANs — it’s about recognizing that network security begins at layer two. A flat network may work for 20 users, but it becomes a liability the moment production systems go digital. The real cost isn’t the hardware or configuration time; it’s the risk of a single endpoint bringing down an entire line during peak fulfillment. We now advise all clients in process-driven industries to treat internal segmentation as a baseline control, not an upgrade — especially when regulatory scrutiny and supply chain dependencies are non-negotiable.
When your production line runs on the same network as guest Wi-Fi, risk isn’t theoretical — it’s inevitable. See how modern network segmentation strategies can protect your operations before the next incident hits.