- Sector: Offshore Oil & Gas Operator
- Delivery Scope: OT Asset Discovery, Device Backups, Malware Scanning, Security Benchmarking, Port-Blocking Enforcement, Offshore Workforce Training, Patching
- Standards Applied: CIS Benchmarks that comply with Industrial Cyber Standards
- Environment: Multiple Live Offshore Production Platforms
Project Impact at a Glance
>90%
Operational assets inventoried and verified
Offshore
Complex North Sea Operational Platforms safely audited
CIS Alignment
Systems hardened against CIS security benchmarks
Zero Outages
Live production maintained during permit controlled activities



The Challenge: Securing Industrial Control Systems in Live Offshore Environments
The client sought to harden its offshore Operational Technology (OT) cyber security posture. However, the company faced limited inventory visibility, legacy operating systems, restricted offshore access, and the risk that intrusive activities could cause production shutdowns.
- Unmapped Legacy Devices: Control networks contained legacy devices without consolidated inventory records or verified backups
- Live Production Risk: Offshore systems run continuous industrial processes; intrusive security interventions risk tripping systems and causing costly downtime
- Ingrained Cultural Practises: Offshore engineering teams were often hesitant about security protocols that might interfere with daily platform operations
The Solution: Systematic OT Asset Discovery
Sword implemented a structured, non-disruptive discovery and remediation programme across offshore assets, auditing more than 90% of devices, creating recovery backups, scanning for malware, and hardening ports against unauthorised access.
Non-Intrusive Asset Inventorying
Identified and verified over 90% of previously untracked OT assets, reviewing Windows event logs without interrupting operations.
Threat Eradication & Backup Creation
Executed targeted malware scans, generated system recovery backups, and applied CIS security benchmarks.
Cultural Collaboration & Network Hardening
Worked closely with offshore engineers to explain the rationale behind security controls, while locking unused physical ports to prevent accidental or malicious breaches.



Measurable Business Outcomes
Commercial / Efficiency Gain
Created verified disaster recovery backups across critical devices, eliminating potential multi-million-pound production halts
Operational Resilience / Risk Mitigation
Inventoried >90% of offshore control systems, scanned for malware, and applied rigorous CIS benchmark controls
Speed, Agility & User Experience
Non-disruptive discovery protocols ensured comprehensive device inspection with zero downtime to operations
Future Proof Scalability & Independence
Cultural education and port-blocking controls empowered platform staff
"Sword’s expertise improved the client’s cyber security posture, ensuring compliance, operational resilience, and educating personnel on critical security measures effectively."
More Information
Automated IT vulnerability scanners can overwhelm sensitive serial connections and programmable logic controllers (PLCs), causing emergency shutdowns. Sword uses non-intrusive methods to ensure systems run safely.
Physically and logically locking unneeded USB and Ethernet ports on platform consoles stops unauthorised flash drives from introducing malware into isolated control networks
More case studies
Need help?
Whether you are strengthening operational resilience, securing critical infrastructure, or improving organisational preparedness, our UK-based experts are ready to support your mission-critical operations















