cd ../portfolio
GRCDoneJune 2026GRCIT/OTIEC 62443EBIOS RMISSP

$ PolyEnergia IT/OT Cybersecurity Strategy (French Project)

A GRC case study completed in French for a fictional industrial site, covering IT/OT asset cartography, IEC 62443 zoning, EBIOS RM-style risk scenarios, Information Systems Security Policy, Business Continuity and Disaster Recovery planning, budget and KPI steering.

PolyEnergia IT/OT Cybersecurity Strategy (French Project)
# Overview

PolyEnergia is a fictional industrial organization used to explore how cybersecurity strategy can be built for a mixed IT and OT environment. The scenario focuses on a polymer production site with internal cogeneration, business-critical flows, industrial constraints and external dependencies that directly affect operational resilience. The analysis starts with the organization itself: key processes, sensitive assets, IT and OT systems, supplier access, production dependencies and critical data flows. From there, the work connects technical exposure to business impact, including ransomware with OT rebound, supplier account compromise, recipe alteration, SCADA cogeneration disruption and leakage of formulas or quality data. The strategy turns those risks into practical governance and security decisions. It covers IEC 62443-inspired zones and conduits, bastion and MFA for remote access, OT change logging, supplier security clauses, vulnerability monitoring, Information Systems Security Policy, Business Continuity and Disaster Recovery planning, crisis exercises, awareness actions, budget framing and KPI-based steering. The project was originally completed in French. English equivalents are used here for the main governance terms so the case study remains easier to read for an international cybersecurity audience.

# Metadata
Role
Cybersecurity strategy author and GRC analyst
Stack / Themes
GRCIT/OTIEC 62443EBIOS RMISSPBCP/DRPRisk Management

# Outcomes

Built a 24-part cybersecurity strategy deliverable for an industrial IT/OT environment.
Mapped critical assets, external dependencies, Purdue-style zones and business-critical flows.
Prioritized five IT/OT threat scenarios and linked them to risk treatment, budget and steering indicators.
Produced governance material covering Information Systems Security Policy, gap analysis, Business Continuity and Disaster Recovery planning, crisis exercises and awareness planning.

# Images

PolyEnergia cybersecurity strategy case study visual 01PolyEnergia cybersecurity strategy case study visual 02PolyEnergia cybersecurity strategy case study visual 03PolyEnergia cybersecurity strategy case study visual 04PolyEnergia cybersecurity strategy case study visual 05PolyEnergia cybersecurity strategy case study visual 06PolyEnergia cybersecurity strategy case study visual 07PolyEnergia cybersecurity strategy case study visual 08PolyEnergia cybersecurity strategy case study visual 09PolyEnergia cybersecurity strategy case study visual 10PolyEnergia cybersecurity strategy case study visual 11PolyEnergia cybersecurity strategy case study visual 12PolyEnergia cybersecurity strategy case study visual 13PolyEnergia cybersecurity strategy case study visual 14PolyEnergia cybersecurity strategy case study visual 15PolyEnergia cybersecurity strategy case study visual 16PolyEnergia cybersecurity strategy case study visual 17PolyEnergia cybersecurity strategy case study visual 18PolyEnergia cybersecurity strategy case study visual 19PolyEnergia cybersecurity strategy case study visual 20PolyEnergia cybersecurity strategy case study visual 21PolyEnergia cybersecurity strategy case study visual 22PolyEnergia cybersecurity strategy case study visual 23PolyEnergia cybersecurity strategy case study visual 24