What the Mackay Sugar Shutdown Reveals About OT Segmentation Readiness

Mackay Sugar, Australia’s second-largest raw sugar producer, disclosed a cybersecurity incident on June 10, 2026 that disrupted operations across its Queensland milling facilities during the annual crushing season, leaving cut cane with nowhere to go. Two mills went offline, and the third avoided disruption only because it was not scheduled to begin operating yet.

By June 12, the company had restarted limited operations, while the systems coordinating cane delivery, harvesting logistics, and mill intake remained offline, as Teiss reported. Although physical capacity survived the incident, production still stopped because a mill runs on the systems that schedule and account for what enters it as much as on the equipment that processes it. 

How Continuous Visibility and Exploit Analysis Enable Effective Segmentation to Protect These Environments

Most manufacturing security teams cannot say, on short notice, how far an intrusion into a business system could travel inside their own plants before it reached something that moves. This is because a lack of comprehensive device visibility across the network makes it difficult to truly assess risk. Additionally, network segmentation, which prevents lateral movement, is often treated as a one-and-done initiative, essentially a time capsule for the network. If fully implemented at all, segmentation efforts may not reflect an accurate device inventory and may contain outdated policies.  

Fully operationalized security requires visibility, which enables segmentation to control both blast radius and restart speed – and it starts with answering these four questions.

  • Is there a current and continuous inventory of every connected device, including IoT, OT, and IT in the plant? Programmable logic controllers, historians, weighbridges, HMI panels, building systems, and older networked equipment rarely tolerate agents. Anything missing from the inventory, including communication patterns between IT and other devices, is also missing from the segmentation plan.
  • Is it known which of those devices carry genuinely exploitable risk? A vulnerability count sorted by severity score produces a remediation queue no plant team can work through during a production window.
  • If a business system were compromised tonight, what could it reach? Not what the network diagram says it could reach, but what observed traffic shows it actually talks to.
  • Could containment be proven quickly enough to restart? Restart decisions stall when nobody can demonstrate which segments were touched and which were not.
Where OT Segmentation Programs Stall

Most industrial organizations already own the enforcement capability. Network access control is deployed, often for years, and frequently limited to authentication rather than segmentation. The gap between a NAC that is installed and a NAC that is operationalized for segmentation is where most programs sit.

The reasons are consistent across plants. Policies have to be written in each NAC platform’s own schema, which concentrates the work in whoever knows that platform. Nobody can say with confidence which flows a new policy would break, so the policy waits for a change window. Change windows in seasonal production sit outside the operating period, which in a sugar mill means a narrow stretch between crushing seasons. And operations holds an effective veto over anything that risks stopping the line, which is a reasonable position when a bad policy costs a day of crushing.

Readiness is what closes that gap. It is not a larger security budget or a new enforcement point. It is the ability to show, before deployment, exactly what a policy would do.

What OT Segmentation Readiness Looks Like in Practice

Asimily is the intelligence and policy orchestration layer that enables your team to segment your environment safely, with or without a NAC. Asimily supplies the device context, risk prioritization, policy generation, simulation, and ongoing maintenance that turn a deployed NAC into working segmentation across IoT, OT, IoMT, and IT.

In sequence, that means:

  • A complete, authoritative inventory captured without disruption. Discovery and classification run through passive monitoring and active safe scanning where appropriate, agentlessly and without disruption, covering services, connections, and firmware versions across production and corporate environments alike.
  • Prioritization based on real exploitability. Asimily’s ATT&CK Analysis determines whether a vulnerability can actually be exploited on a specific device in a specific environment and topology, which narrows the work to the roughly 1% of devices driving most of the risk.
  • Policies generated in the Network Infrastructure’s own format. Asimily’s Policy Auto-Recommendation identifies where to start, and Policy Creation produces the policy in the correct native schema, removing the dependency on a single trained engineer.
  • Impact shown before anything is applied. Policy Simulation validates a policy against real, observed network traffic and shows exactly which devices and connections would be affected. This is the proof that answers the operations veto directly, with data rather than assurance.
  • Enforcement that does not drift. Devices are patched, replaced, moved, and readdressed constantly. Continuous Segmentation tracks whether policies still match the current state of the network and adapts, and Policy Audit merges, deduplicates, and optimizes policies so sprawl does not overload switches.

Segmentation that is designed once and left alone degrades from the day it is deployed and undermines network security across the organization. Treating it as a maintained operational practice is what keeps containment scope predictable when something does get in.

Related: Segmentation Orchestration

What Organizations Can Learn From This Incident

For organizations where production cannot be stalled, and attack containment was never part of the design, the systems that coordinate production sit in a seam: security treats them as business systems, operations treats them as production systems, and segmentation work stalls in the gap. It stalls for the same reason across the sector. Getting from knowing what to segment to enforcing it is manual work, and manual work does not survive contact with a production schedule. Asimily does that work on top of the NAC a plant already owns, which is what moves segmentation from a standing priority to an operational control.

See how Policy Simulation works before you deploy: Request a demo

Secure Every IoT Device.
Automatically.

Cyber threats move fast — so should you. Asimily gives instant inventory and smart, prioritized risk mitigation insights for every IoT, OT, and IoMT device — so you can take action before threats strike.