Segmenting OT From IT: A Plain-English Guide for Operators

Network segmentation is the most useful early step in industrial security. Learn what zones mean and how to plan segmentation without stopping operations.

3 min readBy Ironfield Cyber Team

If you operate pumps, compressors, a treatment plant, or a small substation, you have likely heard that your control network should be separated from your business network. The advice is correct, but it is often delivered in jargon that leaves operators wondering what to actually do. This guide explains segmentation in plain terms and offers a planning approach that respects the realities of keeping a process running.

Why separate the networks

Imagine a phishing email that lands on an accountant's laptop. If that laptop shares a flat network with your control equipment, malware on it can scan, probe, and potentially reach controllers. Segmentation puts a controlled checkpoint between those worlds so that a compromise in the office does not automatically become a problem on the plant floor.

It works in the other direction as well. An issue on the control side, such as a misbehaving device, is less likely to disrupt business systems.

The core ideas

Zones and conduits

The ISA/IEC 62443 family of standards describes grouping assets with similar security needs into zones, and controlling the communication paths between zones, called conduits. You do not need to adopt the entire standard to use the idea. Think of zones as rooms and conduits as doors with locks and a log.

A simple layout may include:

  • A business zone for office computers and email.
  • A demilitarized zone, or DMZ, for systems that need to exchange data with both sides, such as historians or remote access gateways.
  • A control zone for supervisory systems and operator stations.
  • A device zone for controllers, drives, and field equipment.

Deny by default

A good firewall rule set starts by blocking everything and then allowing specific, documented traffic. Each allowed path should have a purpose, an owner, and a reason.

A planning approach

1. Map what talks to what

Before changing anything, document which systems communicate, over which protocols, and why. Surprises are common: an engineering laptop with two network connections, an old modem, or a vendor device that phones home.

2. Define the zones

Group assets by function and risk. Safety-related and critical control assets deserve the tightest boundaries.

3. Choose the checkpoints

Place industrial-aware firewalls at the zone boundaries. Choose equipment that is suited to the environment, including temperature, power, and rack space constraints, and that operations staff can maintain.

4. Start in monitoring mode

Where possible, first observe the traffic before enforcing rules. This reveals legitimate dependencies you did not know about and prevents an outage on cutover day.

5. Schedule changes with operations

Plan the cutover during planned maintenance windows, with a rollback plan and operators involved. Test each change and confirm the process behaves normally.

Remote access belongs in the DMZ

Vendor and employee remote connections should terminate in a controlled gateway rather than reaching control devices directly. Require multi-factor authentication, individual accounts, session logging, and approval for vendor access. Eliminate standing, always-on connections wherever possible.

Common mistakes

  • Putting a firewall in place with a rule that allows everything.
  • Forgetting about wireless links, cellular modems, and technician laptops that bypass the firewall.
  • Segmenting without documenting, so no one knows why rules exist.
  • Failing to include operations staff in planning.
  • Treating the project as finished rather than reviewing rules periodically.

Where regulation fits

Utilities subject to NERC CIP standards and pipeline operators under TSA Security Directives have specific obligations that include electronic security perimeters and access controls. Even operators outside those regimes can use the same concepts to guide their approach.

Talking with Ironfield Cyber

Ironfield Cyber helps energy and construction-related operators plan segmentation and secure remote access, in coordination with the engineers and vendors who support your equipment. If you are considering separating your networks, we can help you map current traffic and propose a staged plan that avoids surprises.