Magic Software
For the CIO · IT Director · VP Enterprise Architecture

You know what good looks like. The plant floor still writes passwords on panels with a sharpie.

DevSecOps. Patch management. Change control. Network segmentation. Audit trails. You run all of it across the enterprise. Five feet past the IDF, none of it applies — and you're the one accountable when the auditor or the insurer asks why.

The Real Problem

It's not a tooling gap. It's a blame loop.

Your IT consultant blames the system integrator. The SI blames corporate IT. Nobody owns the boundary between the data center and the control panel. Nothing ships. The audit findings stay open. The cyber insurance questionnaire gets harder every year.

What corporate sees on paper

An enterprise that runs on policy.

  • Identity governed in Entra. MFA everywhere.
  • Patch SLAs measured in days, tracked in ServiceNow.
  • Change control with approvals, rollback, and audit log.
  • Segmented network, EDR on every endpoint.
  • DR runbooks, tested annually, signed off.

What's actually on the floor

An environment running on tribal knowledge.

  • A shared local account. The password is on a sticky note. Or written on the panel.
  • HMIs on Windows versions Microsoft stopped supporting two presidents ago.
  • “Change control” is a guy named Dale who has been there 22 years.
  • Flat network from the IDF to the PLC. The vendor laptop plugs straight in.
  • If the line goes down, recovery is whoever answers their phone.

Every gap is a finding waiting to happen — and an incident waiting to happen. You can't fix it from the data center. The OT team won't let you near the line during production. Your SI partner builds control logic, not segmentation. That's the gap we close.

The OT-IT Bridge Assessment

A productized assessment. Real BoM. Real implementation quote.

Not a six-month consulting engagement. Not another framework deck. A scoped, fixed-fee assessment that ends with a buildable plan and a number you can take to the budget conversation.

01

Topology

Map what you actually have.

Non-intrusive, read-only discovery of the physical and logical OT environment. Every PLC, HMI, switch, drive, and historian. Every shared credential. Every flat segment. Every unmanaged jump host. The artifact is the map your team has never had.

02

Future-State

Design the bridge.

Software-defined segmentation (Dynics SDN), ICS-aware controls (ICS Defender), modern HMI architecture (Ignition 8.3) and the integration layer that hands clean data to the enterprise. Designed against your real constraints — uptime windows, supported platforms, audit obligations — not a reference architecture from a slide.

03

BoM + Quote

Hand corporate something they can fund.

A real bill of materials. A real implementation quote. A phased plan with sequencing, dependencies, and downtime windows already worked through with operations. You walk into the capex conversation with a number, not a hand-wave.

The flywheel

Assessment → BoM + Implementation Quote → Implementation Contract → Next Plant Assessment.

Scope Your First Plant
Proof in Production

Multi-plant rollout, in flight. Vicksburg first. Manchester next.

Batesville needed an OT environment that could meet enterprise cybersecurity standards without taking the line down to do it. We built the standard at Vicksburg. We're rolling it to Manchester now. Same playbook, plant after plant.

The Vicksburg baseline

A standardized, secure, software-defined OT network.

Dynics SDN switches. ICS Defender appliances. Segmented zones that map to ISA-95, not to whatever the cabling crew did in 2007. Audit-ready by design.

The Manchester rollout

Non-intrusive discovery. Future-state design. Zero downtime.

Mapping the physical and logical topology. Documenting supervisory control dependencies. Designing the same future-state stack — without scanning a production network the wrong way and taking a line down.

The bearing save

$50–100K avoided in the first weeks.

Once enterprise data could flow safely, vibration data flagged a failing bearing within weeks of go-live — six-month replacement lead time avoided. The cybersecurity work paid for itself before the project closed.

One Vendor. Zero Finger-Pointing.

The IT integration experts with the OT muscle on speed dial.

Magic builds the secure API layer, the connectors, and the integration plane that extends the life of your SAP, JD Edwards, or Infor stack — without a risky rewrite. When it comes time to touch the actual machines, our sister practice (Axiom / MartinCSI) handles the physical floor work. Same project plan. Same accountability. One PO if you want it.

  • Decades of SAP, JD Edwards, and Infor integration without rip-and-replace.
  • Premier Ignition integrator on the OT side. Dynics, ICS Defender, ISA-95.
  • End-to-end accountability across the OT/IT boundary — the boundary nobody else owns.
  • Productized deliverables. Fixed-fee assessment. Real BoM. Real quote.

What you're actually accountable for

Cyber risk doesn't stop at the IDF. Neither does your name on the audit.

  • Cyber risk across the enterprise

    Including the OT environment that nobody owns operationally — but that lives on your insurance application.

  • Governance and audit posture

    Including the controls the floor either doesn't know about or quietly ignores.

  • Identity, access, and credential hygiene

    Until it becomes a sharpie-on-a-panel reality five feet past the IDF.

  • Patch and configuration management

    Which has no equivalent on the floor — until somebody builds one that doesn't take the line down.

  • DR and incident response

    Including the OT environment nobody mapped — until now.

Why CIOs Bring Us In

Because the boundary between corporate IT and the plant floor is the one boundary nobody owns — until you make somebody own it.

We speak both sides.

Enterprise architects who understand SAP and JD Edwards. Controls engineers who understand Ignition and Allen-Bradley. The translation layer between them lives in our delivery model, not in a steering committee.

One team, end-to-end.

Magic and Axiom / MartinCSI run as a single project. No SI-vs-IT-consultant blame loop. No integration tax handed to your team to absorb.

Productized, not open-ended.

Weeks, not quarters. Fixed-fee assessment. Decision-ready BoM. A capex package corporate can actually approve.

Frequently Asked

What CIOs ask before booking the call.

Will this disrupt production?+

Discovery is non-intrusive and read-only. We don't run the active scans that take lines down. Future-state changes are designed against real uptime windows worked through with the plant team — not imposed on them.

Do we have to use your implementation team after the assessment?+

No. The assessment ends with a BoM and a buildable plan. You can hand it to your incumbent SI, run an RFP, or have us implement it. Most clients pick the third option — but the deliverable stands on its own.

How does this work with our existing SI / OT integrator?+

We work with them, not around them. Most plants already have an integrator who knows the control logic. Our job is the segmentation, the cybersecurity stack, and the integration plane to corporate — not the PLC code. We bring them in early.

What about prior cyber assessments — do we throw those out?+

No. If you already have a Dragos run, a Claroty deployment, or a recent IT/OT assessment, we start from those findings. The point of the Bridge Assessment is to turn findings into a buildable, funded plan — not to redo the discovery you already paid for.

Where does corporate IT plug in?+

Corporate IT is at the table from kickoff. Identity, MFA, EDR, ServiceNow, network policy — all of that has to extend across the bridge, and your team is the source of truth for how. We don't build a parallel kingdom on the floor.

What does a typical engagement cost?+

The assessment is fixed-fee and scoped per plant. We quote it on the call once we know the plant size, system count, and what's already documented. The implementation BoM that comes out the other side is the number that matters for the capex conversation.

OT-IT Bridge Assessment

Close the audit finding. Keep the line up.

Thirty minutes, no slides. We'll walk through the plants you're worried about, what's already documented, and what a scoped first assessment looks like.

Quick qualification, then a 30-minute working session — no deck.