01
Client Profile & Background
A multinational manufacturing company with factories in Bekasi and Surabaya, employing over 5,000 staff across production, R&D, and administrative departments. The company operates a converged IT/OT network with over 500 devices, including PLCs, SCADA systems, and enterprise servers. They handle sensitive intellectual property and comply with ISO 27001 standards. Their existing network infrastructure consisted of flat Layer 2 switching from multiple vendors, lacking any segmentation between departments or between IT and OT environments.
02
Technical Challenge
The flat network architecture posed severe security risks: a single malware infection in the administrative LAN could propagate to production PLCs, causing 8-hour downtime per incident. In the past year, they experienced three ransomware attempts, each requiring 24-hour recovery. Additionally, broadcast storms from the R&D department's high-traffic applications degraded performance for critical SCADA systems, leading to 15% production inefficiency. Compliance audits revealed 12 non-conformities due to lack of network isolation. They needed to segment over 200 VLANs without disrupting ongoing operations.
03
Implemented Solution
Intilogy designed a multi-layered segmentation architecture using Cisco Catalyst 9300 switches at the core and distribution layers, implementing 802.1Q VLAN tagging for 250 logical segments. Fortinet FortiGate 600E firewalls were deployed for inter-VLAN routing with stateful inspection, enforcing least-privilege policies. OT networks were isolated using Ruijie RG-S2928G switches with private VLANs to prevent lateral movement. The solution integrated with existing VMware NSX for micro-segmentation in the virtualized server environment. All segmentation rules were automated via Microsoft System Center for consistent policy enforcement. The project was executed over 12 weekends to minimize downtime.
04
Results & ROI
Post-implementation, the attack surface reduced by 90%: no lateral movement from IT to OT was possible, eliminating ransomware propagation risk. Broadcast traffic dropped by 70%, improving SCADA response times by 40%. Compliance audit passed with zero non-conformities. The company achieved a 3-month ROI through avoided downtime costs estimated at IDR 2 billion per incident. Network performance improved, enabling a 20% increase in production throughput. The solution also simplified troubleshooting, reducing mean time to resolution (MTTR) from 4 hours to 30 minutes. Future scalability is ensured with support for up to 1,000 VLANs.