Network Segmentation

Purdue-model zones, secure conduits, IT/OT boundary defense, without disruption.

Why It Matters

Network Segmentation: Results-Oriented Approach

Network segmentation splits your OT environment into discrete zones, each governed by tailored firewall rules. This approach stops threats from roaming freely, sharpens monitoring, and boosts performance.

Many OT networks were built in an “air-gap” era, with security by isolation. Today’s connected world and IT/OT convergence have exposed legacy systems to modern ransomware and advanced threats.

Slows Attackers

Slows Attackers: Zonal barriers delay lateral movement, buying crucial response time.

Least Privilege

Least Privilege: Restrict user and machine access strictly to needed segments.

Damage Containment

Damage Containment: Isolate breaches to minimize impact on overall operations.

Data Protection

Data Protection: Shield sensitive repositories behind dedicated security zones.

Performance Gains

Performance Gains: Granular traffic control reduces congestion and latency.

The Process

How We Work

01

Define Scope

Set technical and organizational boundaries.

02

Assessment

Standards-aligned, OT-specific evaluation.

03

Report & Handover

Executive and technical documentation.

Deliverables

What You Get at the End

ISA/IEC 62443 NIST CSF ISO/IEC 27001 ISO/IEC 27019 EU NIS2
Relevant industries

Industries Where This Service Is Critical

This service is particularly valuable in the sectors below, due to their specific regulations, asset base and threat models.

The process

How an OT Segmentation Project Runs

Segmentation delivers the largest risk reduction on an industrial network. It is also the riskiest if done badly, which is why we work in phases and always start in monitoring mode.

01

Communication matrix

Segmentation rests on the asset inventory and knowledge of actual traffic. Writing firewall rules without an inventory means blocking blindly, and after the first outage you will not be allowed near the network again.

02

Zone and conduit design

We divide the network into zones following IEC 62443 logic and define precisely what traffic may cross between them. The most important boundary is the industrial DMZ between IT and OT.

03

Monitoring mode

The rule set first only logs, it does not block. This surfaces rare communications missing from the matrix without live impact. This phase typically runs 2-4 weeks.

04

Phased enforcement

We switch to enforcement zone by zone, in maintenance windows, with a rollback plan. We start with the least critical zone and carry the experience into the next.

Deliverables

What You Receive

Order of return

Where to Start With a Limited Budget

Not everything at once. This order follows risk reduction, and each step delivers value on its own.

StepWhat it preventsTypical effort
1. IT/OT separation, industrial DMZAttack spreading from the office network4-8 weeks
2. Channelling remote accessIntrusion via supplier VPNs2-4 weeks
3. Cell and line separationOne line's compromise spreading6-12 weeks
4. Isolating safety systems (SIS)Compromise of process safety2-4 weeks
5. Segmenting engineering workstationsAbuse of program download rights3-6 weeks
6. Micro-segmenting critical controllersTargeted device-level attackongoing
Frequently asked

Network Segmentation: The Questions We Hear Most

Can production stop during deployment?

This is why we work in phases and start in monitoring mode. The rule set only logs for 2-4 weeks, so rare communications missing from the matrix surface without live impact. Enforcement happens zone by zone in maintenance windows, with a rollback plan and a pre-agreed decision point for every step. The actual cutover is typically a matter of minutes; the preparation takes weeks.

How many firewalls does it need?

Fewer than you would think. The largest return comes from a single well-placed device on the IT/OT boundary with the industrial DMZ. Cell-level separation can often be achieved with existing managed switches (VLANs and ACLs) without additional hardware. A dedicated industrial firewall is warranted where protocol-level filtering is needed, for example so that PLCs are read-only from a given segment.

What is the difference between VLANs and real segmentation?

A VLAN on its own is logical separation but does not control traffic: if routing between layers happens without filtering, VLANs reach each other freely. Real segmentation means a decision point at the zone boundary (firewall or ACL) that denies by default and permits only defined traffic. VLANs are a precondition for segmentation, not its implementation.

What do we do about supplier remote access?

In practice this is the largest concrete risk and also the fastest to fix. The typical state: every machine builder connects with their own tooling, some with permanent tunnels. The goal is a single controlled entry point: central remote access, mandatory MFA, on-demand activation with a time window, session recording for critical systems, and least privilege. This is achievable in a few weeks.

Does it require downtime?

Not for design or monitoring mode. Switching to enforcement typically needs a short maintenance window per zone, because activating firewall rules can drop existing connections. Building the industrial DMZ can be planned so that the intermediate systems come up in parallel and the cutover is a single configuration step.

Network Segmentation
Tailored to Your OT Environment.

Our consultants are ready, let's start with a 30-minute, no-cost scoping call.