DevSecOps. Patch management. Change control. Network segmentation. Audit trails. You run all of it across the enterprise. Five feet past the IDF, none of it applies — and you're the one accountable when the auditor or the insurer asks why.
Your IT consultant blames the system integrator. The SI blames corporate IT. Nobody owns the boundary between the data center and the control panel. Nothing ships. The audit findings stay open. The cyber insurance questionnaire gets harder every year.
What corporate sees on paper
What's actually on the floor
Every gap is a finding waiting to happen — and an incident waiting to happen. You can't fix it from the data center. The OT team won't let you near the line during production. Your SI partner builds control logic, not segmentation. That's the gap we close.
Not a six-month consulting engagement. Not another framework deck. A scoped, fixed-fee assessment that ends with a buildable plan and a number you can take to the budget conversation.
Topology
Non-intrusive, read-only discovery of the physical and logical OT environment. Every PLC, HMI, switch, drive, and historian. Every shared credential. Every flat segment. Every unmanaged jump host. The artifact is the map your team has never had.
Future-State
Software-defined segmentation (Dynics SDN), ICS-aware controls (ICS Defender), modern HMI architecture (Ignition 8.3) and the integration layer that hands clean data to the enterprise. Designed against your real constraints — uptime windows, supported platforms, audit obligations — not a reference architecture from a slide.
BoM + Quote
A real bill of materials. A real implementation quote. A phased plan with sequencing, dependencies, and downtime windows already worked through with operations. You walk into the capex conversation with a number, not a hand-wave.
The flywheel
Assessment → BoM + Implementation Quote → Implementation Contract → Next Plant Assessment.
Batesville needed an OT environment that could meet enterprise cybersecurity standards without taking the line down to do it. We built the standard at Vicksburg. We're rolling it to Manchester now. Same playbook, plant after plant.
The Vicksburg baseline
Dynics SDN switches. ICS Defender appliances. Segmented zones that map to ISA-95, not to whatever the cabling crew did in 2007. Audit-ready by design.
The Manchester rollout
Mapping the physical and logical topology. Documenting supervisory control dependencies. Designing the same future-state stack — without scanning a production network the wrong way and taking a line down.
The bearing save
Once enterprise data could flow safely, vibration data flagged a failing bearing within weeks of go-live — six-month replacement lead time avoided. The cybersecurity work paid for itself before the project closed.
Magic builds the secure API layer, the connectors, and the integration plane that extends the life of your SAP, JD Edwards, or Infor stack — without a risky rewrite. When it comes time to touch the actual machines, our sister practice (Axiom / MartinCSI) handles the physical floor work. Same project plan. Same accountability. One PO if you want it.
What you're actually accountable for
Cyber risk across the enterprise
Including the OT environment that nobody owns operationally — but that lives on your insurance application.
Governance and audit posture
Including the controls the floor either doesn't know about or quietly ignores.
Identity, access, and credential hygiene
Until it becomes a sharpie-on-a-panel reality five feet past the IDF.
Patch and configuration management
Which has no equivalent on the floor — until somebody builds one that doesn't take the line down.
DR and incident response
Including the OT environment nobody mapped — until now.
Enterprise architects who understand SAP and JD Edwards. Controls engineers who understand Ignition and Allen-Bradley. The translation layer between them lives in our delivery model, not in a steering committee.
Magic and Axiom / MartinCSI run as a single project. No SI-vs-IT-consultant blame loop. No integration tax handed to your team to absorb.
Weeks, not quarters. Fixed-fee assessment. Decision-ready BoM. A capex package corporate can actually approve.
Discovery is non-intrusive and read-only. We don't run the active scans that take lines down. Future-state changes are designed against real uptime windows worked through with the plant team — not imposed on them.
No. The assessment ends with a BoM and a buildable plan. You can hand it to your incumbent SI, run an RFP, or have us implement it. Most clients pick the third option — but the deliverable stands on its own.
We work with them, not around them. Most plants already have an integrator who knows the control logic. Our job is the segmentation, the cybersecurity stack, and the integration plane to corporate — not the PLC code. We bring them in early.
No. If you already have a Dragos run, a Claroty deployment, or a recent IT/OT assessment, we start from those findings. The point of the Bridge Assessment is to turn findings into a buildable, funded plan — not to redo the discovery you already paid for.
Corporate IT is at the table from kickoff. Identity, MFA, EDR, ServiceNow, network policy — all of that has to extend across the bridge, and your team is the source of truth for how. We don't build a parallel kingdom on the floor.
The assessment is fixed-fee and scoped per plant. We quote it on the call once we know the plant size, system count, and what's already documented. The implementation BoM that comes out the other side is the number that matters for the capex conversation.
Thirty minutes, no slides. We'll walk through the plants you're worried about, what's already documented, and what a scoped first assessment looks like.
Quick qualification, then a 30-minute working session — no deck.