From reactive IT management to a detection-driven security organization
How a mature manufacturing company with no security operations quickly transitioned to a controlled, detectable environment — without overhauling the entire organization.

Intro
An international organization in the manufacturing industry had its operational processes, governance, and quality management firmly in order. They actively managed based on KPIs and continuous improvement.
However, due to rapid growth, increasing dependence on IT, and stricter compliance requirements (such as ISO 27001 and NIS2), a critical challenge emerged: cybersecurity was not part of this mature model. The IT environment — a mix of on-premise and Microsoft 365 — was managed by external parties, but central monitoring or a Security Operations Center (SOC) were completely absent.
Problem
The biggest vulnerability was not in the basic technology, but in the lack of priority, the right security tooling, and proactive detection capabilities within the internal IT department. A security assessment exposed several critical security gaps:
- Identity management: Identity was not set up as a security control; MFA and monitoring were missing.
- Infrastructure: Systems were relatively exposed to the outside, and the network was completely flat (no segmentation).
- No security operations: While there was regular IT management, there was no central logging, no SIEM, and no active detection capability.
In practice, this meant that a simple phishing attack could lead to the full compromise of the network environment without being noticed internally. The organization needed a factual baseline assessment and an immediate transition to a controlled, 24/7 monitored environment.
Solution
Rather than completely overhauling the existing infrastructure, we opted for a pragmatic gap analysis to integrate security monitoring directly into current business processes. The core of the solution was the phased onboarding of the Managed Security Operations Center (SOC):
- Immediate risk reduction: Enforcing MFA on all accounts, closing open external ports (access via VPN), and immediately patching critical vulnerabilities to eliminate the primary attack vectors.
- Infrastructure control: Implementation of network segmentation to isolate users, servers, and management systems. Additionally, internal firewalling was applied and Endpoint Detection and Response (EDR) was rolled out in preparation for SOC integration.
- Visibility and detection: Setting up the central SIEM (logging) and onboarding critical data sources. From this point on, advanced detection rules have been active to identify threats such as credential abuse and lateral movement within the network.
- Maturity and governance: Full integration of 24/7 SOC monitoring into the organization's risk management and internal KPIs. Application of Zero Trust principles and continuous tuning in preparation for formal ISO 27001 and NIS2 audits.
Role of the SOC
Before
- No detection
- No logging
- No incident response
After onboarding
- 24/7 monitoring via SIEM + EDR
- Detection of anomalous logins, privilege escalation, and lateral movement
- Immediate follow-up (L1 → L2 escalation)
From reactive to detection-driven security. Logging became a mandatory control, not a "nice to have."
Case study: SOC services in action
During the rollout phase, an employee fell for a phishing email and attempted to log in to a malicious page. Thanks to conditional access, the login was blocked, but the SOC immediately identified the underlying trend: an anomalous login pattern from an unknown location involving a combination of failed and successful authentication attempts. The SOC analysts intervened immediately: the session was blocked, the account was reset, and the internal IT department was notified. What could have escalated into a data breach was nipped in the bud by proactive monitoring.
Result
The organization has successfully shifted from a reactive stance to a detection-driven security organization, with the SOC serving as the central safety net.
- 24/7 visibility and follow-up: Whereas the organization previously had no insight into what was happening in the background, the managed SOC service now provides continuous monitoring based on SIEM and EDR. Anomalies are not only detected but are immediately addressed by analysts.
- Clear governance: Absolute clarity has been established regarding the responsibilities between the organization itself, the existing IT service provider (MSP), and the SOC. Management and security operations are now effectively separated.
- Demonstrable compliance: Security is anchored in the risk register and internal KPIs. Incidents are integrated into the existing quality improvement cycle (CAPA).
An organization does not need to be fundamentally immature to be at risk; it often simply lacks the capacity for its own security operations. With this setup, the organization has laid a solid foundation for demonstrable NIS2 compliance and further alignment with ISO/IEC 27001:2022.
You aren't just "deploying a tool," you are providing structure. Immediate risk reduction without long-term projects, 24/7 monitoring that wasn't feasible internally, and clear accountability.
Grip op jouw performance, kosten en security?
Veel IT-omgevingen groeien zo snel dat de grip op prestaties, budgetten en risico's ongemerkt verwatert. Met Aumatics als proactieve IT- en cybersecuritypartner elimineer je inefficiënties en optimaliseer je jouw infrastructuur continu — maximaal presterend, veilig én kostenefficiënt.
Bekijk andere case studies
From blind spots to full control, from overprovisioning to a grip on cloud costs. This is how we help enterprise organizations move forward with IT and cybersecurity.
