Client
A UK regional airport group operating several passenger terminals, managing IT, retail concessions networking and airfield operational technology under a single security function
Sector
Aviation & Transport
Engagement
Unified vulnerability intake, prioritisation and patch response platform spanning IT, OT and third-party concessions networks - phased delivery over two quarters.
What the client needed
Our client's security team was, on paper, well resourced: a mature IT vulnerability scanner, a separate OT monitoring tool covering baggage handling and airfield systems, and a manual review process for the retail concessions network run mostly by tenant operators rather than the airport itself. In practice, none of those three pictures talked to each other. A critical vulnerability disclosed against a piece of network infrastructure might show up in the IT scanner's report within hours, sit unreviewed against the OT asset register for days because nobody owned the cross-check, and never reach the concessions network's operators at all unless someone remembered to email them. The security team could tell you, with real confidence, what was patched in each silo. Nobody could tell you, with any confidence, what was still exposed across the airport as a single attack surface - and after watching several unauthenticated, no-password-required flaws in network management infrastructure get exploited within days of disclosure elsewhere in the industry, the client's leadership decided that gap had moved from theoretical to unacceptable.
How we worked
- Built a single asset register spanning IT, OT and concessions network infrastructure, with each asset tagged by criticality and blast radius rather than by which team happened to manage it.
- Integrated existing IT and OT scanner feeds into one intake pipeline, so a disclosed vulnerability is matched against every affected asset automatically instead of requiring a manual cross-check.
- Built a prioritisation model weighted toward management-plane and internet-facing infrastructure specifically, after review showed these had consistently been under-prioritised relative to production systems despite carrying wider blast radius.
- Brought concessions network operators into a shared notification and remediation workflow, with contractual SLAs replacing the informal email chain that previously carried critical alerts.
- Built an executive dashboard showing time-to-remediate against severity, by domain, so leadership could see exposure trends rather than point-in-time patch counts.
- Ran a live-fire test using a recent real-world unauthenticated network infrastructure vulnerability as the exercise scenario, timing the full response from disclosure to verified remediation.
Measured results
All figures verified with the client. Specific site, vendor and network detail withheld in line with our standard confidentiality terms and aviation security sensitivity.
- Median time-to-remediate for critical, actively exploited vulnerabilities fell from several weeks to under 48 hours across IT and OT combined.
- The live-fire exercise found and closed two previously unrecognised instances of internet-facing management infrastructure that predated the programme, neither of which had appeared as a priority in any prior audit.
- Concessions network operators now respond to critical notifications inside contractual SLAs in the large majority of cases, against an informal process that previously had no measurable response time at all.
- The executive dashboard is now a standing item at the client's monthly security steering meeting, replacing a quarterly written report that was often several weeks out of date by the time it was read.
- The unified asset register has since been extended beyond vulnerability management to inform the client's broader network segmentation and third-party risk work.
"We had three good tools and three good teams, and still couldn't answer a simple question fast: are we exposed to this, right now, everywhere. The platform didn't replace any of our tools. It made them answer that question together instead of separately."
Working on something similar?
If this engagement looks like the kind of problem you are facing, we would be glad to compare notes by email.
Why the concessions network was the hardest part, not the airfield
Most people assume the highest-risk part of an airport's technology estate is the operational technology running baggage handling or airfield systems, given how directly it touches safety. In our client's case, the harder governance problem sat somewhere less obvious: the retail and concessions network, run day to day by dozens of individual tenant operators with their own point-of-sale systems, their own local IT contractors, and no consistent relationship with the airport's own security team beyond a lease agreement. Vulnerabilities in that network were neither invisible nor unmanaged, exactly - they simply had no clear owner accountable for closing them on any defined timescale, which in practice produces the same outcome as invisibility. Bringing concessions operators into a shared, SLA-backed workflow took longer than the technical integration work and required commercial as well as security engagement, but it closed the largest actual gap in the client's exposure.
Building a prioritisation model around blast radius, not asset type
The client's original approach implicitly ranked vulnerabilities by which system type they affected - production IT first, then OT, then everything else - rather than by what an attacker could actually reach from that point of compromise. We rebuilt the prioritisation logic around blast radius instead: a flaw in an internet-facing management console that could reach dozens of downstream devices was scored above a more severe-sounding flaw in an isolated, non-networked system, regardless of which domain either technically belonged to. That reordering is what surfaced the two unrecognised instances of exposed management infrastructure during the live-fire exercise - both had previously scored as lower priority under the old, asset-type-based model, despite being exactly the kind of unauthenticated, internet-reachable control-plane exposure that has caused several of this year's highest-profile network infrastructure breaches elsewhere in the industry.
The live-fire exercise mattered more than the dashboard
Executive dashboards are useful, but they measure what the organisation believes is true about its own response speed, and belief and reality can drift apart quietly over months without anyone noticing. Running a live-fire exercise against a real, recent, unauthenticated vulnerability scenario - timed end to end from disclosure to verified remediation across every domain, not just IT - forced the same honesty test a real incident would, on a schedule the client controlled rather than one an attacker chose. We'd recommend this as a standing quarterly exercise for any organisation running infrastructure across genuinely different domains with genuinely different ownership, because the gaps that live-fire testing finds are consistently the ones point-in-time audits miss.
Lessons learned
The first lesson was that fragmented ownership, not fragmented tooling, was the real problem. The client already owned good scanners in every domain; what it lacked was a single accountable view stitching their output together, and building that view mattered more than replacing any individual tool.
The second lesson was that management-plane and control-plane infrastructure consistently under-scores in prioritisation models built around asset type rather than blast radius, and that gap is exactly where several of this year's most damaging network infrastructure vulnerabilities have landed industry-wide.
The third lesson was that third-party and tenant networks need contractual, not informal, notification obligations before a shared security programme can actually function, and that commercial conversation is worth having well before an incident forces it.
If your organisation is managing security across genuinely different technology domains with genuinely different ownership, and can't currently answer "are we exposed to this, right now, everywhere" with confidence, we would be glad to discuss what a programme like this might look like for you. Email sales@halfteck.com.