The challenge
For an energy supplier, cybersecurity is becoming a core part of supply security. As metering, monitoring and control go digital, information technology and operational technology, historically kept physically apart, converge. That convergence opens new attack vectors, and the network and security concepts built for the old, separated world no longer fit.
Eniwa needed a foundation it could build its digital transformation on: an architecture that was secure, but also efficient and organisationally manageable, not a security model the organisation could not actually run.
The approach
We worked through it with Eniwa in three deliberate steps: understand the reality first, design against it, then turn the design into something executable.
-
Status quo: from office IT to the power plant
In department workshops we recorded the current network, infrastructure and organisation across the whole company. On that basis, the requirements of the organisation as a whole could be discussed and specified.
-
A shared target architecture
We developed an IT and OT target architecture together, one that optimises security while respecting the real organisational and technical circumstances. Its design pillars:
- Segmentation and zoning by security level
- A strong focus on endpoint security
- Building on the existing system landscape and toolchain
- Automation and self-service where they reduce effort
-
A pragmatic road map
From the target architecture we defined concrete work packages and formulated the decisions they required. Each was prioritised by urgency and effort, weighed against other projects and internal capacity, and turned into a realistic, sequenced road map.
The result
Eniwa has a secure, stable foundation for its digital transformation, and just as importantly a road map it can actually execute with the team and resources it has. The architecture is built for security, efficiency and organisational manageability at once, rather than trading one against the others.