All case studies
Zero TrustAerospace & Manufacturing

Shrinking the blast radius: segmentation and access governance in a high-consequence environment

Meggitt · UK

Executive Summary

In a high-consequence engineering environment, the question that matters most is not only whether a compromise can happen, but how far it can reach if it does. Meggitt needed to reduce that reach, through segmentation and access governance, but could not accept a security programme that disrupted the engineering delivery the business depended on. Those two constraints are often treated as a trade-off; Meggitt needed them satisfied together.

Epitechnic focused the engagement on three things: workload isolation, least privilege, and the ongoing governance of exceptions and recertification. Each was sequenced deliberately so that security improvement was delivered alongside live engineering work, not instead of it.

The result was a reduced reachable attack surface, achieved without disrupting engineering delivery, and an ongoing governance model for exceptions and recertification that sustains the improvement rather than letting it decay once attention moves elsewhere.

Business Challenge

Segmentation and access governance are what determine how far a compromise can reach in any environment, but the stakes are higher in a high-consequence engineering environment, where the systems involved carry safety, programme, and export-sensitive significance. An unmanaged reachable attack surface in that context is not a theoretical risk; it is a direct measure of how much damage a single compromise could do.

The harder problem is usually not technical design, it is sequencing. Security programmes that disrupt engineering delivery invite resistance, and resisted controls get worked around, which quietly reintroduces the risk the programme was meant to close. Left unaddressed, Meggitt faced a choice between an unacceptably large reachable attack surface, or a security programme that risked stalling the engineering delivery the business depended on.

Success Criteria

  • A measurably reduced reachable attack surface, through workload isolation and least privilege
  • Exceptions and recertification governed on an ongoing basis, not cleaned up once and left to decay
  • Security improvement delivered without disrupting engineering delivery
  • A model engineering teams would sustain, rather than resist or route around

Epitechnic Approach

Epitechnic treated sequencing as a first-order design decision, not an afterthought to be managed once the technical design was set. Segmentation and access governance work was structured so it could be delivered incrementally, alongside live engineering delivery, rather than as a single disruptive change.

Prioritisation was driven by consequence: which workloads and access patterns represented the greatest reduction in reachable attack surface for the least disruption to delivery, addressed first. This reflects a broader principle in Epitechnic's Zero Trust work, that access behaviour only actually changes when the sequencing respects how the organisation delivers, not just what the end state should look like.

Solution

Workload isolation

Workloads in the high-consequence environment were not adequately isolated, meaning a compromise in one area could reach further than necessary. Epitechnic decided to prioritise isolation by the consequence of compromise, rather than isolating uniformly across the environment.

Isolating the highest-consequence workloads first delivers the greatest reduction in reachable attack surface earliest, rather than spreading effort evenly regardless of risk. The result was workload isolation that reduced the reachable attack surface where it mattered most, first.

Least privilege

Access in the environment was not governed by least privilege, increasing the paths available to a compromise. Epitechnic decided to redesign access around least privilege, phased so it would not disrupt the engineering teams who depended on that access daily.

A least-privilege redesign delivered all at once risks breaking legitimate engineering workflows and inviting resistance or workarounds. Phasing it protected both the security outcome and delivery continuity. The result was access governed by least privilege without disrupting engineering delivery.

Governance of exceptions and recertification

Exceptions to access policy and recertification of existing access were not consistently governed, allowing access to persist beyond its original justification. Epitechnic decided to establish ongoing governance for exceptions and recertification, rather than treat access governance as a one-time clean-up exercise.

A one-time access clean-up degrades over time without ongoing governance behind it. Building governance into the operating model was what made the reduction in attack surface sustainable rather than temporary. The result was exceptions and recertification governed on an ongoing basis.

Outcomes

Risk reduction: A reduced reachable attack surface, achieved through prioritised workload isolation and least privilege.

Operational improvements: Security improvement delivered without disrupting the engineering delivery the business depended on.

Governance improvements: Ongoing governance of exceptions and recertification, sustaining the reduction rather than letting it decay after the engagement ended.

Executive benefits: Leadership in a high-consequence environment has confidence the attack surface has been actively reduced and is governed on an ongoing basis, not just documented as a residual risk.

Why It Worked

The engagement succeeded because sequencing was treated as core to the design, not a delivery afterthought. Security improvements that disrupt engineering delivery invite resistance and get routed around, which quietly undoes the improvement. By prioritising isolation according to consequence and phasing least-privilege changes around live delivery, the reduction in reachable attack surface was sustainable, not a one-off event that decayed once attention moved elsewhere.

Client Testimonial

[Client testimonial to be added]

Key Takeaways

Challenge: A high-consequence engineering environment needed a materially reduced reachable attack surface, but could not accept a security programme that disrupted engineering delivery.

Approach: Epitechnic prioritised workload isolation and least privilege by consequence, phased to respect live delivery, and built ongoing governance for exceptions and recertification.

Outcomes: A reduced reachable attack surface, delivered without disrupting engineering delivery, sustained by ongoing governance rather than a one-time clean-up.

Lessons: Security programmes in engineering environments succeed or fail on sequencing as much as on technical design; controls that disrupt delivery get resisted or routed around, which quietly reopens the risk.

Start the conversation

Facing a similar situation?

Talk to us

We use analytics cookies to understand how this site is used. See our Privacy Notice for details. You can change your choice at any time.