Executive Summary
Meggitt was weighing a significant platform and architecture decision inside a security-critical engineering environment, the kind of decision where the consequence of getting identity, access, segregation, or data protection design wrong extends well beyond IT, into safety, export control, and the trust of prime contractors and regulators across the aerospace supply chain. Internal sign-off alone was not enough to carry that decision with confidence.
Meggitt engaged Epitechnic for an independent assessment of the proposed platform and architecture decisions, reviewing identity, access, segregation, and data protection design against Meggitt's risk appetite and the expectations of its sector. The assessment was designed to produce a decision, not just a description: proceed, proceed with conditions, or do not proceed.
Epitechnic delivered findings and conditions the decision owners could act on directly, giving Meggitt's leadership an evidence-based basis for a decision that would otherwise have rested on the judgement of the same team that proposed it. The engagement concluded in September 2022, as Meggitt's acquisition by Parker Hannifin completed.
That evidence base fed directly into the platform decision Meggitt then carried forward: a large-scale Azure migration, where Epitechnic provided independent assurance over a third party's delivery.
Business Challenge
Aerospace manufacturing sits inside supply chains where a security architecture decision is never purely a technical matter. Identity, access, segregation, and data protection design in a security-critical engineering environment carry consequences for safety, for export-controlled and sensitive programme data, and for the trust of prime contractors and regulators who expect rigorous assurance, not assertion.
A platform or architecture proposal assessed only by the team that designed it carries an inherent blind spot: the people closest to a decision are the least likely to independently stress-test it. Left unaddressed, that gap means a significant decision proceeds on internal confidence rather than independent evidence, a poor position to be in if the decision is later challenged by a customer, a regulator, or an incident.
Success Criteria
- An independent, evidence-based assessment of the proposed platform and architecture decisions
- Identity, access, segregation, and data protection design reviewed against Meggitt's risk appetite and sector expectations
- Findings and conditions decision owners could act on directly
- A clear basis to proceed, proceed with conditions, or not proceed
Epitechnic Approach
Epitechnic's role was to provide the independence the internal proposal could not provide itself. That meant assessing the proposed architecture on its merits against Meggitt's actual risk appetite and the expectations of its sector, rather than against generic best practice, and producing findings framed as decisions rather than observations.
The approach was evidence-led throughout: every finding was tied to a specific condition the decision owners could act on, so the output was something leadership could use directly to approve, condition, or decline the proposal, not a report requiring further interpretation before it was useful.
Solution
Identity and access
The proposed architecture's identity and access design needed to hold up against Meggitt's risk appetite for a security-critical engineering environment, not just against general good practice. Epitechnic decided to assess identity and access design directly against Meggitt's stated risk appetite and sector expectations, rather than a generic benchmark.
A control that satisfies a generic standard can still be wrong for a specific organisation's risk profile. Assessing against Meggitt's actual risk appetite meant the findings were relevant to a real decision, not theoretical compliance. The result was findings on identity and access that decision owners could weigh directly against the risk they were carrying.
Segregation
Segregation design in a security-critical engineering environment determines how far a compromise or an error can reach. Epitechnic decided to assess segregation as a core part of the architecture review, not a secondary check, given the consequence of inadequate segregation in this environment.
Segregation is one of the few controls that directly limits the blast radius of anything that goes wrong elsewhere in the architecture. Assessing it independently meant Meggitt's decision owners understood not just whether the design was secure in principle, but how contained a failure would be in practice. The result was clear findings on segregation design, tied to specific conditions.
Data protection design
The proposed architecture needed to protect sensitive programme and engineering data appropriately for an aerospace manufacturing environment. Epitechnic decided to review data protection design against sector expectations specifically, given the sensitivity of the data involved in aerospace engineering and manufacturing.
Generic data protection assessment misses sector-specific expectations that matter to prime contractors and regulators. Assessing against sector expectations directly meant the findings addressed the standard Meggitt actually needed to meet. The result was data protection findings decision owners could act on with confidence in their relevance.
Outcomes
Decision-making improvements: Decision owners received findings and conditions they could act on directly, replacing internal confidence with independent, evidence-based assurance.
Risk reduction: Identity, access, segregation, and data protection design were assessed against Meggitt's actual risk appetite before commitment, rather than after deployment.
Executive benefits: Leadership had a defensible, independent basis for a proceed, proceed-with-conditions, or do-not-proceed decision on a significant architecture investment.
Governance improvements: The assessment gave Meggitt an evidence trail for a major architecture decision, useful both internally and to the customers and regulators who expect rigorous assurance in this sector.
Why It Worked
The engagement succeeded because it was structured to produce a decision, not a description. Independent assessment only has value if its findings are usable at the point of decision, so every finding was tied to a specific condition rather than left as a general observation. Assessing against Meggitt's actual risk appetite and sector expectations, rather than a generic standard, meant the findings were relevant to the decision Meggitt actually had to make.
Client Testimonial
[Client testimonial to be added]
Key Takeaways
Challenge: A significant platform and architecture decision in a security-critical engineering environment needed independent, evidence-based assurance before commitment, not just internal sign-off.
Approach: Epitechnic assessed identity, access, segregation, and data protection design against Meggitt's actual risk appetite and sector expectations, producing findings tied to specific, actionable conditions.
Outcomes: Decision owners received evidence-based findings and conditions they could act on directly, ahead of Meggitt's acquisition by Parker Hannifin in September 2022.
Lessons: Independent assessment only earns its value when findings are structured as decisions, not observations, so decision owners can act on them directly.
