We’re exhibiting at

TribalNet 2026

September 20-24, 2026

Dallas, TX

Booth #320

Manufacturing Sector

Three Real-World Purple Team Engagements | Fully Anonymised | ISO 17025 Accredited Methodology

ISO 17025 Accredited · MITRE ATT&CK v15 · All engagements conducted under explicit written authorisation

Sector

Manufacturing

Engagement

Purple Team Exercise

ATT&CK Tactics

MITRE ATT&CK v15

Location

Michigan and Ohio United States

About These Case Studies

The following case studies describe real purple team engagements conducted by GLI Secure across manufacturing sector organisations. All identifying details — organisation names, locations, system names, and personnel — have been fully anonymised. Statistical outcomes, detection improvements, and regulatory findings are accurate as documented during and after each engagement.

 

All purple team exercises described in this document were conducted under explicit written authorisation from the client organisation, using GLI Secure’s ISO 17025-accredited testing methodology. MITRE ATT&CK technique IDs are referenced as documented in ATT&CK Enterprise Framework v15.

Confidentiality Notice: These case studies anonymised; any resemblance to specific organisations is coincidental.

Purple Team Case Studies Manufacturing 1

Case Study MFG-CS-01

IT/OT Production Line Attack — Automotive Tier 1 Supplier

Testing IT/OT segmentation and ICS detection capability against a PIPEDREAM-profile attack on Siemens S7 PLCs

Organisation

A Tier 1 automotive supplier with 8 manufacturing facilities and $1.8B in annual revenue (anonymised)

Sector

Manufacturing — Automotive components, Tier 1 OEM supplier

Location

Michigan and Ohio, United States

Engagement

Purple Team Exercise — IT/OT Convergence Security and Production Line Resilience

Duration

10 weeks (4-week OT scoping, 3-day exercise, 3-week IEC 62443 gap report)

Frameworks

IEC 62443-2-1 and 62443-3-3 | CMMC 2.0 Level 2 (DoD contract components) | VDA TISAX (BMW and Mercedes supply chain) | NIST SP 800-82 Rev 3 | MITRE ATT&CK for ICS v15

The Situation

ICS protocol attacks surged 84% in 2025 versus 2024. The supplier operated 14 Siemens S7-series PLCs across its engine component production lines, all running the Profinet industrial protocol. Every Profinet attack advisory released by CISA in 2024 and 2025 described environments identical to theirs. A production line shutdown was estimated to cost $260,000 per hour.

 

The supplier held BMW Group and Mercedes-Benz supply chain contracts requiring VDA TISAX certification renewal in 8 months, and a DoD components contract with CMMC 2.0 Level 2 requirements. The most pressing concern was the IT/OT convergence that Industry 4.0 adoption had created: PLCs connected to MES connected to ERP connected to the corporate IT network. The air gap that had protected production for decades had been eliminated — and nobody was certain where the actual security boundary was.

Core Challenge

Identify and validate security vulnerabilities in the IT/OT convergence architecture that could allow an attacker on the corporate IT network to reach and disrupt production line PLCs — and determine whether any such activity would be detected.

What GLI Secure Did

We began with a four-week OT asset discovery and architecture review — mapping every production line PLC, HMI, historian server, and OPC-UA server across all eight manufacturing facilities. This produced the first accurate Purdue Model compliance assessment the company had ever had.

 

The exercise used passive and minimally-invasive OT testing throughout. Production line operation was the absolute constraint — any technique that could disrupt production was excluded regardless of security relevance. An isolated test PLC was used for all demonstrations of technique impacts.

 

We mapped all findings to IEC 62443 zone and conduit model requirements, NIST SP 800-82 Rev 3 controls, and CMMC 2.0 practices.

The Purple Team Approach

OT Asset Discovery and Purdue Model Mapping

Found: 14 PLCs in Level 1, 22 HMIs and historian servers in Level 2, MES in Level 3, ERP in Level 4. Discovered: 6 direct connections between Level 2 (SCADA) and Level 4 (ERP) that bypassed the Level 3 boundary — the IT/OT convergence pathway for a production attack.

IT/OT Boundary Penetration

From a simulated compromised IT workstation, tested whether the 6 Level 2-to-Level 4 connections permitted lateral movement to SCADA systems. Found: 4 of 6 permitted inbound communication from the ERP zone to SCADA historian servers.

Engineering Workstation Access

From the SCADA historian server reached via the Level 2-to-Level 4 connection, tested whether the Siemens TIA Portal engineering workstation was reachable. Found: direct reachability confirmed — on the same network segment as the historian server.

OPC-UA Server Security Assessment

Found: OPC-UA server used a self-signed certificate expired 2 years earlier and had anonymous access enabled — both direct violations of ISA-62443-4-2 component security requirements.

Test PLC Interaction (Isolated Environment)

Using an isolated test S7-1500 PLC outside the production network, demonstrated access achievable once the engineering workstation was reached — including the ability to read process values and upload modified ladder logic, the capability documented in the PIPEDREAM/INCONTROLLER campaign.

IEC 62443 / TISAX / CMMC Gap Assessment

Mapped all findings to IEC 62443-3-3 system security requirements, VDA TISAX assessment criteria (Label AL2), and NIST SP 800-171 practices for CMMC Level 2. Produced the three-framework gap assessment and remediation roadmap.

MITRE ATT&CK Techniques Tested

ATT&CK ID Technique Detection Result
T1190 Exploit Public-Facing Application (IT Initial Access) PARTIAL

VPN patched. Web app vulnerability found, not exploited.

T0866 Exploitation of Remote Services (ICS — OPC-UA Anonymous) SUCCESS ON ISOLATED TEST

Anonymous OPC-UA access confirmed against test PLC.

T0812 Default Credentials (ICS — Engineering Workstation) NOT DETECTED

No monitoring on engineering workstation access.

T0836 Modify Parameter (ICS — Isolated Test PLC Only) DEMONSTRATED ON ISOLATED TEST

Ladder logic upload capability confirmed.

T1046 Network Service Scanning (OT Enumeration) Not Detected

No IDS/IPS on OT network.

Key Findings

4 Direct IT-to-SCADA Connections Bypassing Security Boundary:

Four connections bypassed the intended Level 3 manufacturing operations zone boundary, creating a direct path from the corporate ERP system to SCADA historian servers. Created during ERP integration work and never reviewed from a security perspective.

Critical

Critical

Critical

OPC-UA Anonymous Access on Production PLC Data Aggregator:

Anonymous access enabled on the OPC-UA server aggregating data from 14 production line PLCs — one of the attack techniques specifically documented in the PIPEDREAM/INCONTROLLER campaign.

Critical

Engineering Workstation Reachable from SCADA Zone:

The Siemens TIA Portal engineering workstation — with direct PLC programming capability — was reachable once the SCADA zone was accessed. This is the highest-consequence OT attack capability.

High

Zero OT Network Security Monitoring:

No security monitoring infrastructure existed on the OT network across all 8 facilities.

High

Expired OPC-UA Certificate:

The OPC-UA server certificate had expired 2 years prior — a specific ISA-62443-4-2 compliance failure that VDA TISAX assessors specifically examine.

Measurable Outcomes

Direct IT-to-SCADA Connections All 4 removed or routed through monitored OT DMZ
OPC-UA Anonymous Access Disabled within 72 hours. Certificate renewed.
Engineering Workstation Isolated to dedicated OT engineering VLAN with jump server access
OT Network Monitoring Passive OT security monitoring deployed at all 8 facilities
IEC 62443 Zone Model Formally implemented across all facilities within 90 days
TISAX Renewal Assessment completed — Label AL2 certification maintained
CMMC Level 2 OT-related NIST SP 800-171 gap reduced from 22 to 4 practices

Regulatory Impact

The IEC 62443 zone and conduit compliance assessment was required for VDA TISAX Label AL2 renewal. TISAX assessors specifically examine IT/OT network segmentation against IEC 62443 zone model requirements — the 4 direct IT-to-SCADA connections would have been an immediate TISAX finding. Remediating them before the renewal assessment maintained the supplier’s BMW and Mercedes contract qualification.

 

For CMMC 2.0 Level 2 compliance, the OT environment processing DoD contract component data through the MES and ERP integration was within scope for NIST SP 800-171 requirements. The anonymous OPC-UA access and unmonitored OT network represented gaps in NIST SP 800-171 SC.3.177 and CA.2.158 respectively.

 

The OPC-UA anonymous access finding was reported to CISA’s ICS-CERT under the voluntary disclosure programme — consistent with CISA’s recommendation for critical infrastructure operators to report ICS vulnerabilities matching documented threat actor TTPs.

We had Industry 4.0 connectivity between our ERP and our production PLCs. What we did not have was any understanding of what that connectivity meant from a security perspective. The purple team exercise showed us: it meant an attacker who compromised our corporate network could reach the engineering workstation that programs our S7 PLCs. That is a $260,000-per-hour production disruption waiting to happen.

— Vice President of IT and Operations Technology, Automotive Tier 1 Supplier (anonymised)

Key Takeaways

Ready to test your Manufacturing security defences?

Case Study MFG-CS-02

CMMC 2.0 Adversarial Assessment — Aerospace Defence Manufacturer

Full adversarial simulation of a Chinese state-sponsored attack on a Tier 2 aerospace defence supplier

Purple Team Case Studies Manufacturing 2

Organisation

A Tier 2 aerospace components manufacturer with $420M in annual revenue and 11 active DoD contracts (anonymised)

Sector

Manufacturing — Aerospace components, defence industrial base

Location

Southern California, United States

Engagement

Purple Team Exercise — CMMC 2.0 Level 2 Adversarial Assessment and C3PAO Readiness

Duration

12 weeks (5-week CUI discovery, 3-day exercise, 4-week SSP and POA&M development)

Frameworks

CMMC 2.0 Level 2 (NIST SP 800-171 Rev 2 — 110 practices) | DFARS 252.204-7012 and 252.204-7021 | EAR/ITAR | MITRE ATT&CK Enterprise v15

The Situation

CMMC 2.0 requirements became active in DoD contracts in November 2025. The manufacturer held 11 active DoD contracts, all requiring Level 2 compliance, including components for fighter aircraft avionics systems — ITAR-controlled hardware with specific CUI handling requirements. The FBI had briefed the company on documented APT41 activity targeting aerospace defence suppliers in their geographic area.

 

The company’s CISO was concerned that the documentation gap assessment conducted 18 months earlier had not tested whether controls actually worked against a realistic adversary. A C3PAO assessment was required within 6 months. The CISO wanted to know exactly where the gaps were — from the attacker’s perspective, not the documentation reviewer’s.

Core Challenge

Identify operationally exploitable gaps in the manufacturer’s CMMC Level 2 controls that would be found in a C3PAO assessment or exploited by an APT41-profile adversary targeting ITAR-controlled aerospace CUI.

What GLI Secure Did

We began with a five-week CUI data discovery programme — mapping all CUI data flows across 11 DoD contracts, identifying every system storing, processing, or transmitting CUI, and assessing whether each met NIST SP 800-171 requirements.

 

The adversarial assessment simulated an APT41-profile attack: spear-phishing targeting engineering staff with avionics programme access, lateral movement through the engineering computing environment, and CUI exfiltration.

 

All findings were mapped to NIST SP 800-171 practices and structured as a CMMC 2.0-ready SSP and POA&M.

The Purple Team Approach

CUI Data Discovery and Scope Definition

Mapped all CUI across 11 contracts. Found: CUI existed in 34 systems across engineering, programme management, supply chain, and IT functions. The prior documentation assessment had scoped 22 systems — 12 CUI-handling systems were missing from the prior assessment scope.

ITAR-Specific CUI Identification

Found: ITAR-controlled CAD files were stored on personal cloud storage (Google Drive) by 4 engineering staff. ITAR-controlled data on personal cloud storage constitutes an unlicensed export violation — a criminal offence under 22 USC §2278.

Spear-Phishing Simulation (APT41 Engineering Targeting)

Sent targeted spear-phishing to 14 engineering staff with avionics programme access using programme-specific lures. 6 of 14 clicked (43%). 3 provided credentials on the simulated harvest page.

Engineering Network Lateral Movement

Found: no segmentation boundary between the engineering workstation environment and the CAD server network. Any compromised engineering workstation could reach all CUI repositories.

CUI Repository Access and Exfiltration Testing

Found: no DLP on the engineering network. ITAR files could be emailed externally, copied to USB, or uploaded to cloud storage without any alert.

CMMC Practice Gap Assessment

Identified 41 practices with gaps. Highest-concentration gaps: Access Control (12 gaps), Audit and Accountability (9 gaps), Configuration Management (8 gaps), System and Communications Protection (7 gaps).

MITRE ATT&CK Techniques Tested

ATT&CK ID Technique Detection Result
T1566.001 Spear Phishing Attachment (Engineering Targeting) SUCCESS

43% click rate. 3 credentials harvested.

T1078 Valid Accounts (Engineering Network Access) Not Detected

No UEBA on engineering network.

T1039 Data from Network Shared Drive (CAD Repositories) Not Detected

No monitoring on file server access.

T1048 Exfiltration over HTTPS (Cloud Upload — CUI) Not Detected

No DLP on engineering network.

T1552 Unsecured Credentials (Engineering Network) Detected

EDR flagged credential dumping attempt on engineering workstation.

Key Findings

Critical

ITAR-Controlled Data on Personal Cloud Storage — Export Violation:

ITAR-controlled avionics CAD files on personal Google Drive accounts. ITAR-controlled technical data on commercial cloud storage constitutes an unlicensed export under 22 USC §2778 with up to 20 years imprisonment and $1M per violation.

Critical

12 CUI-Handling Systems Not in Assessment Scope:

The prior documentation assessment missed 12 CUI-handling systems. The C3PAO assessment would find these systems and could not certify Level 2 compliance for a materially incomplete programme scope.

Critical

Zero DLP on Engineering Network:

ITAR-controlled technical data could be emailed externally, uploaded to cloud storage, or copied to USB without generating any alert.

High

43% Spear-Phishing Success Against Engineering Staff:

APT41 specifically targets engineering staff at aerospace suppliers — this success rate represents the primary initial access vector the adversary would exploit.

medium

41 NIST SP 800-171 Practice Gaps:

Significantly higher than the prior documentation assessment had indicated — demonstrating the gap between documentation review and operational adversarial assessment.

Measurable Outcomes

ITAR Cloud Storage All personal cloud storage cleared and access blocked within 48 hours
CUI Scope All 12 missing systems added to CMMC assessment scope and assessed
DLP Engineering network DLP deployed within 60 days
Engineering Network Segmentation Engineering-to-CAD boundary implemented within 90 days
NIST SP 800-171 Gaps 41 gaps reduced to 8 within 90 days — C3PAO readiness achieved
System Security Plan Complete 110-practice SSP delivered — 214-page document

Regulatory Impact

The ITAR cloud storage finding was the most immediately consequential regulatory issue. ITAR-controlled technical data on personal Google Drive accounts constitutes an unauthorised export under the Arms Export Control Act. The company’s export compliance counsel determined that voluntary self-disclosure to DDTC was appropriate.

 

The 12 missing systems created a DFARS 252.204-7012 compliance gap. Contractors must implement the 110 security requirements of NIST SP 800-171 on all systems that process, store, or transmit CUI covered by the contract — making the prior self-attestation materially inaccurate.

 

The absence of DLP on the engineering network created specific exposure under both CMMC Level 2 (AU.2.042) and DFARS 252.204-7012. A C3PAO assessment finding no DLP on a network containing ITAR-controlled technical data would be unable to certify Level 2.

We had a documentation assessment that said we were 85% of the way to CMMC Level 2. The adversarial assessment found ITAR files on personal Google Drive, 12 systems missing from our scope, and an engineering network where any compromised workstation could reach every classified technical drawing we own. The documentation review tested the policies. The adversarial assessment tested reality.

— Chief Information Security Officer, Aerospace Defence Manufacturer (anonymised)

Key Takeaways

Ready to test your Manufacturing security defences?

Case Study MFG-CS-03

Automotive Supply Chain Intelligence Theft — VDA TISAX Validation

Testing TISAX control effectiveness against industrial espionage targeting proprietary vehicle component IP

Purple Team Case Studies Manufacturing 3

Organisation

A specialty automotive components manufacturer with €290M in annual revenue and TISAX AL2 certification (anonymised)

Sector

Manufacturing — Automotive, specialty components, European supply chain

Location

Baden-Württemberg, Germany

Engagement

Purple Team Exercise — TISAX Operational Effectiveness Validation and IP Protection Assessment

Duration

7 weeks (3-week scoping, 2-day exercise, 2-week TISAX evidence update)

Frameworks

VDA TISAX (AL2) | ISO/IEC 27001:2022 | NIS2 Directive (manufacturing — important entity) | MITRE ATT&CK Enterprise v15

The Situation

The manufacturer held VDA TISAX Label AL2 certification and supplied precision-engineered components to BMW Group, Stellantis, and a Japanese OEM under a new contract. The TISAX assessment had been conducted 14 months earlier — primarily a document review of the company’s ISO 27001-based ISMS.

 

The information security manager had a concern: the controls were documented correctly, but were they operationally effective? The German BfV had briefed the company’s sector association on documented Chinese and Russian industrial espionage targeting automotive component IP — specifically proprietary surface treatment processes this manufacturer had developed.

 

The new Japanese OEM contract required security evidence beyond TISAX certification. The OEM’s security questionnaire asked explicitly whether the manufacturer had conducted adversarial testing of controls protecting technical IP. The manufacturer needed to answer yes with evidence.

Core Challenge

Validate that the manufacturer’s TISAX-documented information security controls were operationally effective against an industrial espionage threat actor targeting proprietary manufacturing process IP.

What GLI Secure Did

We constructed an industrial espionage attack profile based on BfV advisories and documented campaigns against German automotive component suppliers targeting proprietary process technology.

 

The exercise focused on IP protection controls: access controls on the proprietary surface treatment process documentation, DLP for CAD and process specification files, and detection capability for insider-facilitated IP exfiltration.

 

All findings were mapped to TISAX assessment criteria (IS Controls catalogue) and structured as evidence for both the OEM security questionnaire and the next TISAX renewal cycle.

The Purple Team Approach

IP Asset Identification and Classification

Mapped all proprietary IP assets: 12 surface treatment process specification documents, 847 component CAD designs, customer vehicle application data. Assessed access controls on each category against TISAX AL2 requirements.

Process Documentation Access Testing

Found: 23 employees had access to process documents beyond their job function requirement — a TISAX IS Control 1.1.2 (need to know) gap.

Simulated Industrial Espionage Attack

Sent spear-phishing to 9 engineers with process documentation access using automotive engineering conference lures. 3 of 9 clicked (33%). 2 provided simulated credentials.

DLP Effectiveness Testing

DLP blocked email of files tagged as confidential. Untagged documents (62% of the proprietary process docs) bypassed DLP entirely — they were not classified in the DLP policy.

PLM Security Testing

Found: all engineers shared a single PLM service account — individual access logging was impossible, making insider threat detection non-viable.

TISAX IS Controls Gap Assessment

Identified 8 controls rated as ‘implemented’ in the prior TISAX assessment documentation that were not operationally effective when tested adversarially.

MITRE ATT&CK Techniques Tested

ATT&CK ID Technique Detection Result
T1566.002 Spear Phishing Link (Engineering Targeting) SUCCESS

33% click rate. 2 credentials harvested.

T1078 Valid Accounts (PLM Service Account) Not Detected

No individual user audit trail on PLM service account.

T1005 Data from Local System (Process Specifications) PARTIAL

Tagged documents blocked. Untagged documents exfiltrable.

T1048 Exfiltration over HTTPS (Untagged Documents) Not Detected

DLP did not cover untagged documents.

T1567 Exfiltration to Cloud Storage (Tagged Confidential) Detected

DLP blocked upload of tagged confidential documents.

Key Findings

Critical

Shared PLM Service Account — No Individual Audit Trail:

All 23 engineers with PLM access used a shared service account. Individual access to component CAD designs was unauditable. An insider who exfiltrated IP via PLM would leave no individual audit trail — a direct TISAX IS Control 6.1 and ISO 27001 Annex A.8.15 gap.

Critical

62% of Process Documents Not Classified in DLP Policy:

62% of proprietary process specification documents had no classification tag and were therefore outside the DLP policy scope. These documents — including the surface treatment process IP specifically targeted by documented industrial espionage — could be emailed externally without any alert.

High

23 Employees with Excessive Process Document Access:

23 of 67 employees had broader access than their job function required — a TISAX IS Control 1.1.2 need-to-know violation.

medium

8 TISAX IS Controls Operationally Non-Effective:

8 controls rated as ‘implemented’ in the prior documentation-based TISAX assessment were not operationally effective when tested adversarially.

Measurable Outcomes

PLM Individual Accounts Shared service account replaced with individual accounts within 30 days
Document Classification All 12 process specification documents classified within 14 days
DLP Coverage Extended to cover unclassified documents in process specification directories
Access Rights Review 23 excess access permissions removed within 21 days
TISAX Evidence Exercise findings accepted as TISAX AL2 renewal evidence supplement
OEM Security Questionnaire Japanese OEM accepted adversarial test evidence — contract confirmed

Regulatory Impact

The shared PLM service account finding has direct NIS2 compliance implications. NIS2 classifies manufacturing as an important sector and requires audit logging sufficient to detect and investigate ICT incidents. A PLM system with no individual user audit trail cannot satisfy NIS2’s monitoring and logging requirements.

 

The 8 operationally non-effective TISAX IS controls highlight a systemic limitation of document review-based TISAX assessments. The OEM security questionnaire environment is moving toward requiring adversarial testing as a supplement to certification.

 

The exercise findings were structured as TISAX renewal supporting evidence — demonstrating to the accredited TISAX assessment provider that the manufacturer had conducted adversarial validation of control effectiveness between assessment cycles.

We had a TISAX certificate that said our information security controls were implemented. The purple team exercise showed us that 62% of our most valuable IP documents were outside our DLP policy entirely, that every engineer was sharing a single PLM account with no individual audit trail, and that a third of our engineers would click on a spear-phishing email. We had documentation compliance and operational vulnerability — and they were both true at the same time.

— Information Security Manager, Automotive Components Manufacturer (anonymised)

Key Takeaways

Book a Free Manufacturing Purple Team Discovery Call

GLI Secure | ISO 17025 Accredited

Strengthen your cybersecurity posture today.

Strengthen your cybersecurity posture and protect your organization from evolving threats. Discover how GLI Secure reduces risk, simplifies compliance, and protects customer trust.

Font Resize