REM / REM-05
Compensating controls and legacy-system protection
Reducing exposure of systems that cannot be fixed immediately, with explicit risk tracking and a replacement roadmap.

WHEN IT HELPS
A focused response
to a defined need.
Infrastructure or business owner; legacy applications, unsupported equipment or industrial constraints preventing updates.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Dependency analysis
- segmentation and access restriction
- increased monitoring and a legacy exit plan
Deliverables
- Compensating-control file
- residual risks
- protective architecture and review milestones
Acceptance evidence
Required flows work and other flows are blocked in testing; protection limitations are documented.
DELIVERY
How the work is structured.
Approach
Validate findings; prioritise and assign; prepare changes and rollback; implement or coach; retest and document closure.
Prerequisites & responsibilities
Customer: approvals, change windows, application owners and business acceptance. Provider: implementation only when included; otherwise advice, coordination and evidence review.
Scope factors
Number and complexity of root causes, environments, dependencies and retests. Time and materials, scoped package or recurring support; effort confirmed after report review.
Questions to clarify
Why is a fix impossible? For how long? Who accepts the risk and funds replacement?
IMPORTANT BOUNDARIES
A compensating control reduces selected risks without removing the vulnerability; duration and responsibilities must be bounded.
Findings remain explicitly classified as fixed, mitigated, accepted, deferred or unverified. Closure is supported by evidence rather than the administrative status of a ticket.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A factory relies on an old workstation controlling an irreplaceable machine. Project: isolate it and control remote maintenance. Target outcome: restricted access and appropriate monitoring, while production safety remains the priority.
Scenario 02
An SME needs unsupported business software for another year. Project: reduce exposure and privileges while planning migration. Target outcome: explicit risk acceptance and milestones, without claiming obsolete software can be made permanently secure.
Technology and reference context
Segmentation, privileged-access gateway, filtering and logging as system compatibility permits.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
