scieee AI-readable full text Open interactive document viewer

CYBERSECURITY INFRASTRUCTURE OPTIMIZATION IN ENGINEERING ENVIRONMENTS: A CASE STUDY AT GENTILE ENGENHARIA

Maycon A. Zuliani

Abstract

This paper provides an expanded analysis of a cybersecurity infrastructure optimization project conducted in2023 at Gentile Engenharia, a mid-sized engineering firm located in São Paulo, Brazil. The organizationexperienced accelerated digital expansion between 2022 and 2023, which exposed systemic vulnerabilitiesincluding flat network topology, inconsistent security controls, legacy protocols, and ineffective firewallgovernance. To address these issues, the internal IT team executed a structured modernization plan involvingfirewall policy redesign, segmentation of network architecture, server consolidation, and alignment withinternational cybersecurity frameworks. The intervention improved system resilience, reduced operationalincidents, and established a scalable foundation for information security governance. These findings offerpractical insights for engineering companies undergoing similar infrastructure growth.

Full text

Volume-08 Issue 03, March-2024 ISSN: 2456-9348 Impact Factor: 7.936 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [269] CYBERSECURITY INFRASTRUCTURE OPTIMIZATION IN ENGINEERING ENVIRONMENTS: A CASE STUDY AT GENTILE ENGENHARIA Maycon A. Zuliani Senior Systems and Network Analyst; IT Infrastructure and Cybersecurity Specialist, São Paulo, Brazil ABSTRACT This paper provides an expanded analysis of a cybersecurity infrastructure optimization project conducted in 2023 at Gentile Engenharia, a mid-sized engineering firm located in São Paulo, Brazil. The organization experienced accelerated digital expansion between 2022 and 2023, which exposed systemic vulnerabilities including flat network topology, inconsistent security controls, legacy protocols, and ineffective firewall governance. To address these issues, the internal IT team executed a structured modernization plan involving firewall policy redesign, segmentation of network architecture, server consolidation, and alignment with international cybersecurity frameworks. The intervention improved system resilience, reduced operational incidents, and established a scalable foundation for information security governance. These findings offer practical insights for engineering companies undergoing similar infrastructure growth. Keywords: cybersecurity, infrastructure optimization, network segmentation, firewall governance, engineering environments, NIST compliance. INTRODUCTION The digital transformation of engineering firms has intensified the dependency on interconnected systems, shared computational resources, and high-availability environments (Stallings, 2017). Unlike traditional corporate offices, engineering organizations rely on specialized applications—CAD, structural analysis tools, geoprocessing software—that demand low latency, stable networks, and consistent security controls. Between 2022 and 2023, Gentile Engenharia transitioned from a localized IT structure of seven basic workstations to an environment supporting over sixty employee devices, multifunction printers, cloud-connected services, and an expanding perimeter exposed to external contractors and field teams. This rapid expansion occurred without proportional reinforcement of cybersecurity governance, which led to operational bottlenecks and increased exposure to threats, including malware, unauthorized lateral movement, and data availability issues. Such challenges are widely documented in NIST SP 800-53 (2020) and CIS Controls v8 (2021), particularly in environments that scale faster than their security baselines. In 2022, recognizing the operational risks, the company initiated a structured modernization effort. This study examines the technical, procedural, and architectural measures implemented and evaluates their impact on security posture and operational stability. OBJECTIVES The main objectives of this study are: 1. Identify key vulnerabilities in the legacy infrastructure of an engineering environment experiencing rapid technological expansion. 2. Document the cybersecurity optimization measures, including architecture redesign, firewall restructuring, and server centralization. 3. Evaluate outcomes using performance logs, event records, and compliance benchmarks. 4. Present a transferable framework applicable to small and mid-sized engineering organizations facing similar challenges. METHODOLOGY This research uses a qualitative descriptive case-study methodology based on: Volume-08 Issue 03, March-2024 ISSN: 2456-9348 Impact Factor: 7.936 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [270] • Internal documentation and technical reports from Gentile Engenharia (2022); • Configuration baselines from network devices, firewalls, and Windows Server environments; • Pre-intervention and post-intervention logs (connectivity events, malware alerts, ticket volumes); • Mapping of measures to NIST SP 800-53, NIST SP 800-41, ISO/IEC 27001, and CIS Controls v8. 3.1 Environment Baseline The infrastructure under analysis included: • ~60 workstations (mixed unmanaged Windows devices) • On-premises Windows Server domain (post-2022) • Legacy unmanaged switches • Single perimeter firewall running outdated firmware • Absence of VLANs, segmentation, QoS, or traffic policies • Engineering applications dependent on stable shared network folders This configuration represents a typical “organic growth” environment described in the cybersecurity literature, where scalability precedes formal governance. 3.2 Limitations This study is limited to internal data available from the 2022 modernization cycle. No external penetration tests or long-term threat intelligence feeds were used. RESULTS AND DISCUSSION 4.1 Identification of Security Weaknesses The diagnostic phase revealed systemic vulnerabilities spanning multiple security domains. When mapped to established frameworks such as NIST SP 800-53 Rev.5, MITRE ATT&CK, ISO 27002:2022, and CIS Controls v8, the environment demonstrated characteristics consistent with organizations at Maturity Level 1 (Initial/Ad-Hoc) under the CMMI Cybersecurity Maturity Model. (a) Access Control and Network Trust Boundaries The environment functioned as a monolithic Layer-2 broadcast domain, characteristic of a legacy flat network. Technical implications included: • Absence of micro-segmentation: Allowed unrestricted east-west lateral movement, increasing susceptibility to propagation techniques such as T1021 (Remote Services) and T1046 (Network Service Scanning) from the MITRE ATT&CK matrix. • Decentralized workstation authentication: Each host operated under local authentication models, which impeded unified credential governance, increased the surface for credential compromise, and violated NIST AC-2 and AC-17 controls. • Lack of privileged access separation: Administrative privileges were locally managed, creating inconsistent enforcement of least privilege and exposure to privilege escalation vectors. (b) System Integrity and Configuration Management The infrastructure lacked a coherent configuration management strategy, with direct consequences for system integrity: • Prevalence of SMBv1: This deprecated protocol, classified by Microsoft as “critically vulnerable,” was leveraged by global ransomware campaigns (e.g., WannaCry leveraging EternalBlue). Its presence indicated non-compliance with NIST SI-2 (“Flaw Remediation”). • Nonexistent baseline configurations: The absence of hardened images or GPO-enforced configurations led to heterogeneous security states across endpoints. • Patch management inconsistencies: Several devices exhibited multi-year patch gaps, increasing exploitability through known vulnerabilities (CVEs) documented in NIST NVD. (c) Firewalls and Boundary Protection Boundary protection controls were significantly deficient: • Overly permissive ACLs (“allow any”) contradicted the principles of Zero Trust Architecture (ZTA) as defined in NIST SP 800-207. • Lack of outbound traffic governance: Enabled shadow IT, unauthorized SaaS usage, and potential data exfiltration pathways (ATT&CK T1041). • Firewall firmware fragmentation: Outdated firmware reduced the effectiveness of IPS signatures and risk engines, diverging from CIS Control 4 (“Secure Configuration of Enterprise Assets”). Volume-08 Issue 03, March-2024 ISSN: 2456-9348 Impact Factor: 7.936 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [271] These issues collectively represented a high-risk posture for an engineering environment dependent on continuous availability and data integrity. 4.2 Redesign of Firewall Policies The firewall restructuring was conducted according to the principles of least privilege, zero trust, and defense in depth, integrating recommendations from NIST SP 800-41 Rev.1 and ISO 27033 (Network Security Controls). (a) Implementation of Stateful Packet Inspection (SPI) Migration from stateless packet filtering to SPI enabled context-aware validation of traffic sequences, improving: • Session integrity verification • Detection of anomalous TCP flag sequences • Precision in drop/allow decisions SPI is widely recognized in academic literature as a baseline requirement for modern perimeter protection. (b) Least-Privilege Rule Model The redesign employed a top-down approach: • Service-defined ACLs: Each rule tied explicitly to application requirements, minimizing surface exposure. • Rule provenance tracking: Documenting purpose, owner, and revision history brought governance in line with ISO 27001 A.8 and A.12. • Outbound restrictions: Previously unrestricted outbound flows were constrained to business-critical services, significantly reducing opportunities for C2 (command-and-control) callbacks (ATT&CK T1071). (c) Geo-Blocking and Threat-Intelligence Integration Blocking traffic from high-risk regions relied on: • Reputation databases • Threat intelligence feeds • GeoIP-based heuristics This approach effectively mitigated high-volume scanning and brute-force attempts originating from known malicious geographies. (d) URL & Content Filtering Content filtering aligned with OWASP guidelines and enhanced: • Prevention of drive-by downloads • Mitigation of access to malicious repositories • Blocking of encrypted anonymization tunnels often used for evasion (e) Intrusion Detection Patterns Custom IDS/IPS rules were harmonized with: • Snort signature families • CVE-based detection heuristics • Behavioral correlation models Quantified Impact Post-implementation log analysis revealed: • 47% reduction in unauthorized outbound attempts • 33% reduction in anomalous inbound probes • Significant suppression of suspicious encrypted traffic lacking SNI metadata • Increased visibility of east-west traffic anomalies This demonstrates the efficacy of structured firewall governance in SMEs. 4.3 Network Segmentation and Architecture Reorganization Network segmentation represented the most impactful architectural advancement. The environment transitioned from a flat L2 topology to a hierarchical, zone-based, policy-enforced architecture. (a) Segmented VLAN Architecture The new architecture included: 1. Administrative VLAN: Restricted to management protocols (SSH, RDP, SNMPv3, WinRM). Volume-08 Issue 03, March-2024 ISSN: 2456-9348 Impact Factor: 7.936 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [272] 2. Engineering VLAN: Optimized for I/O-intensive engineering software traffic. 3. Server VLAN: Running AD DS, file services, and backup systems, protected by inter-VLAN firewall rules. 4. Guest VLAN: Fully isolated, routed directly to the internet with no access to internal networks. (b) Security and Performance Implications Benefits included: • Containment of compromise domains: Lateral threat movement now required multiple choke points, reducing blast radius (aligned with zero trust). • Reduction in broadcast storms: Engineering applications demonstrated measurable latency reductions after segmentation. • Controlled inter-VLAN communication: Policies applied per zone reflected a trust-minimization philosophy. • Alignment with ISO 27001 A.13.1.3: Ensuring networks are segmented according to functional and security requirements. (c) Comparison with Industry Findings Studies in network security for industrial/engineering environments (e.g., Kim & Solomon, 2018) show segmentation reduces security incident propagation by up to 70%, aligning closely with the outcomes in this case. 4.4 Server Infrastructure Consolidation The deployment of a centralized Windows Server domain established a unified governance model. (a) Role-Based Access Control (RBAC) Migrated from ad-hoc local account structures to AD-driven RBAC: • Strong alignment with NIST AC-3 and AC-6 • Significant reduction in permission sprawl • Clear auditability of file-system operations (b) Automated Backup Framework Backup optimization incorporated: • Incremental and differential routines • Off-site replication policies • Validation cycles ensuring data recoverability This represented substantial progress toward compliance with ISO 27001 A.12.3 (“Backup”). (c) Decommissioning Peer-to-Peer Shares Peer-to-peer networks, recognized as high-risk in SME environments, were systematically replaced with: • NTFS-governed directory structures • Group-managed access policies • Auditable file operations (d) Unified Authentication and Hardening Active Directory enabled: • GPO-based security baselines • Enforcement of password and lockout policies • Centralized software deployment • Standardized patching windows Collectively, these improvements elevated the environment from a fragmented identity model to a complianceready infrastructure. 4.5 Impact on Operational Stability A 12-month post-intervention evaluation demonstrated significant improvements across operational performance, reliability, and risk metrics. (a) Reduction in Security Incidents • ~60% decrease in malware detections • Complete elimination of SMBv1-based exploit attempts • Fewer brute-force authentication attempts due to rule refinement (b) Network Performance Gains Volume-08 Issue 03, March-2024 ISSN: 2456-9348 Impact Factor: 7.936 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [273] Segmentation and optimized routing provided: • Lower latency for CAD and engineering applications • Improved throughput for server-client communication • Less packet loss attributed to reduced broadcast traffic (c) Decrease in Maintenance Overhead After the intervention: • Helpdesk tickets fell by 40–45% • Backup-failure incidents dropped significantly due to standardization • Fewer configuration drift issues, thanks to centralized control (d) Enhanced Business Continuity The modernization increased: • Predictability of system behavior • Reliability of engineering workflows • Resistance to ransomware and propagation-based threats (e) Alignment with Research Outcomes mirror findings in peer-reviewed studies on SME cybersecurity optimization, which highlight segmentation, RBAC, and centralized governance as the most impactful measures for risk reduction. ACKNOWLEDGEMENT The authors express their profound appreciation to the Information Technology Department of Gentile Engenharia for their decisive collaboration throughout the infrastructure modernization cycle conducted in 2022. The intervention described in this study required not only access to sensitive operational records, network configuration archives, and historical performance logs, but also detailed technical validation from the professionals directly responsible for maintaining the corporate technological environment. The authors acknowledge, in particular, the contributions of the senior systems and network specialists who supported the diagnostic, planning, and implementation phases of the cybersecurity optimization program. Their longstanding familiarity with the organization’s technological evolution — from the original seven-workstation layout of the early 2020s to the more than sixty interconnected assets present by 2022 — provided essential contextual insight into the architectural challenges addressed in this research. Special recognition is extended to the lead infrastructure analyst, whose two decades of experience at Gentile Engenharia — including extensive involvement in server deployment, network scaling, endpoint governance, protocol modernization, firewall configuration, and security hardening — ensured the technical accuracy of the reconstructed implementation model presented in this case study. His practical knowledge of legacy systems, client-server transitions, VLAN deployment, access control structures, and operational workflow dependencies was indispensable for validating the sequencing and reliability of the interventions evaluated herein. The authors also thank the engineering and administrative teams whose operational routines supplied the empirical baseline used to analyze system stability before and after the cybersecurity restructuring. Their feedback, incident reports, and production data made it possible to quantify the effects of segmentation, rule governance, and server centralization on business continuity. Finally, the authors acknowledge the organizational leadership of Gentile Engenharia for authorizing the controlled release of configuration data, performance metrics, and non-confidential internal documentation essential to achieving methodological rigor in this study. Without the institution’s commitment to transparency, collaboration, and continuous modernization of its information systems, the findings presented here would not have been possible. CONCLUSION The 2022 cybersecurity optimization at Gentile Engenharia demonstrates the importance of structured intervention when organizations undergo rapid digital expansion. The redesign of firewall rules, segmentation of Volume-08 Issue 03, March-2024 ISSN: 2456-9348 Impact Factor: 7.936 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [274] network layers, and centralization of server governance produced significant improvements in operational stability, security posture, and compliance alignment. The case contributes to the understanding of cybersecurity challenges in engineering environments, which depend on stable and high-performance networks. It further provides a replicable framework for mid-sized companies seeking to modernize infrastructure using internationally recognized controls such as NIST SP 80053, NIST SP 800-41, ISO 27001, and CIS Controls. Future work may explore quantitative risk scoring, long-term monitoring metrics, and the integration of SIEM solutions to expand detection capabilities. REFERENCES [1] NIST. Security and Privacy Controls for Information Systems and Organizations (SP 800-53). 2020. [2] Scarfone, K., et al. Guide to Firewalls and Firewall Policy (SP 800-41 Rev.1). NIST, 2009. [3] ISO/IEC 27001:2022. Information Security, Cybersecurity and Privacy Protection. [4] CIS Controls v8. Center for Internet Security Critical Security Controls. CIS, 2021. [5] Stallings, W. Network Security Essentials: Applications and Standards. Pearson, 2017.