Years of Operational Silence Masked a Hidden Risk in Critical Gas Infrastructure
A Singapore-based operator managing high-pressure natural gas transmission pipelines had operated without major incident for over a decade. The facility’s operational technology (OT) network, responsible for monitoring pressure levels, flow rates, and emergency shutoff systems, had never undergone a formal security assessment. Internal IT staff were confident in the network’s isolation, but recent regulatory advisories from the Energy Market Authority and heightened scrutiny from corporate auditors forced leadership to confront an uncomfortable truth: they had no verifiable assurance that their control systems were secure. A single undetected breach in the OT environment could lead to unauthorised valve manipulation, pressure miscalibrations, or a catastrophic pipeline rupture—risks that extended beyond financial loss to public safety and environmental compliance.
Initial Access Revealed Critical Blind Spots in Network Segmentation
When TYPENT engineers arrived on-site, the first phase involved network mapping and asset discovery using passive and active scanning techniques. We found that while the OT network was physically separated from the corporate IT network, a legacy maintenance portal—installed by a third-party vendor years earlier—allowed bidirectional traffic between the two zones without authentication. This unauthorised bridge had been undocumented in network diagrams and was unknown to current operations staff. Further analysis with industrial protocol analysers from Nozomi Networks identified unpatched Siemens PLCs running outdated firmware, some of which were susceptible to known CVEs. Alarmingly, log collection was minimal, and no centralised monitoring system existed to detect anomalous behaviour. The lack of visibility meant that even if a compromise had occurred, the organisation would have been unable to detect or respond to it.
We Deployed a Zero-Trust Architecture Across IT and OT Boundaries Using Layered Controls
TYPENT implemented a phased remediation plan focused on visibility, segmentation, and resilience. First, we installed a dedicated OT monitoring platform from Nozomi Networks to provide real-time asset inventory, protocol anomaly detection, and behavioural baselining. This was integrated with a new SIEM system powered by Splunk, enabling correlation of OT events with corporate security logs. Next, we re-architected the network segmentation using Palo Alto Networks firewalls configured with strict zone policies, effectively eliminating the undocumented maintenance tunnel. All inbound access to OT systems was replaced with a jump host model secured by multi-factor authentication and time-bound access windows. We also established a secure, air-gapped backup process using Veeam for critical SCADA configuration files and historian databases, stored on an encrypted HPE storage array with daily integrity checks. Firmware updates were applied to all accessible PLCs and RTUs following vendor-approved change control procedures.
Post-Assessment Validation Showed 99.99% System Availability and Eliminated All Known Attack Vectors
After six weeks of implementation and testing, the client achieved full compliance with ISO/IEC 27001 and the EMA’s cybersecurity guidelines for critical infrastructure. Continuous monitoring confirmed zero unauthorised access attempts over a three-month observation window. Mean time to detect anomalies dropped from undefined to under 90 seconds, and audit readiness improved significantly—what once required weeks of manual checks could now be demonstrated in under two hours. More importantly, the organisation regained confidence in its ability to operate safely. The board approved a new annual OT security assessment cycle, and the operations team now conducts quarterly tabletop exercises based on scenarios modelled from the initial findings.
Assumptions About Air-Gapped Networks Are the Greatest Vulnerability in Industrial Environments
Many industrial operators in Singapore assume that physical isolation equates to security, but our assessment confirms that undocumented connections, legacy protocols, and human oversight erode that assumption over time. The absence of monitoring does not imply the absence of risk—it only delays discovery until a failure occurs. For SMEs managing critical infrastructure, investing in continuous visibility and documented network hygiene is not an IT expense but an operational necessity. Regular, independent assessments should be treated as essential maintenance, just like pipeline integrity testing or valve calibration.
When your control systems operate in silence, the most important signals are the ones you’re not hearing—explore how proactive infrastructure assessments can uncover hidden risks before they escalate.