A production line stops responding, and the first decision is rarely technical. Operations must decide whether to pause work before an unclear network problem reaches systems that keep the plant running, as maintenance teams work without trusted visibility.
A factory network security architecture is a layered design for separating production systems by operational consequence, limiting communications to approved routes, and controlling who reaches critical assets. It gives IT, OT, engineering, and security leaders a shared way to govern connections, contain problems, and preserve safe, available production when a device or session requires attention.
Modern plants depend on connections that older designs did not anticipate. Service laptops, supplier sessions, cloud analytics, historians, and enterprise identities all support maintenance or decision-making, but each route still needs an owner, a defined purpose, and a recovery plan. Think of the design as a loading-bay system: every delivery enters through an approved gate and reaches only its assigned area.
This article explains how Purdue and IEC 62443 guide functional layering, risk-based zones, conduits, and an industrial demilitarized zone (DMZ). It then covers asset inventory, controlled traffic routes, access governance, containment testing, and the remote-maintenance workflows that often cross plant boundaries. The outcome is a defensible design that protects production continuity without treating every connection as equally trusted.
Why Factory Network Security Architecture Is Now Strategic
A plant’s network design shows its value when an ordinary support issue reaches a production decision. If a supplier connection, engineering workstation, or enterprise identity can reach too far, operations leaders must judge availability and safety before they know the incident’s scope.
A factory network security architecture is a layered design that separates critical functions, limits communication to approved routes, and preserves safe production when a connection or device is compromised. It gives IT, OT, engineering, and security leaders clear decision rights over what connects, why it connects, and how quickly it can be contained.
That discipline has a clear business case. Manufacturing represented 25.7% of incidents across IBM X-Force’s ten most-attacked industries in 2023, ranking first for the third consecutive year (IBM Security, X-Force Threat Intelligence Index 2024, 2024). Connectivity supports analytics and maintenance, yet every new path changes the production-continuity decision.
The useful question is not whether to connect systems. It is whether every connection has an owner, a purpose, a permitted route, and a recovery plan. Purdue provides the functional map, IEC 62443 supplies the risk method, and controlled boundaries turn those decisions into operating practice.
What Defines a Resilient Factory Security Architecture?
A resilient factory security architecture makes critical communications explicit and containable. It uses layered zones, approved conduits between them, and recovery-aware controls so that a problem in one area does not automatically spread into production systems.
The scale of the problem supports a design response. Verizon recorded 2,305 security incidents and 849 confirmed data breaches in manufacturing in its dataset (Verizon, 2024 Data Breach Investigations Report – Manufacturing snapshot, 2024). A perimeter control alone cannot show whether a service laptop, historian, or cloud integration has a justified path to a control environment.
NIST SP 800-82 Rev. 3, Guide to Operational Technology Security (2023) frames segmentation through levels or zones, boundary controls, and an OT/enterprise demilitarized zone (DMZ). That approach treats boundaries as a defense-in-depth design, rather than a network-performance exercise.
- Connectivity expansion: Enterprise, cloud, industrial internet of things (IIoT), and supplier links add paths into OT.
- Production criticality: Availability and safety set limits on disruptive security changes.
- Legacy constraints: Some assets cannot follow an ordinary IT patch timetable.
- Accountability pressure: Audits and customer reviews require defensible access evidence.
The target state is a network where leaders can explain why each route exists and what happens when it fails. That creates the foundation for framework-led zoning.
How Do Purdue and IEC 62443 Work Together?
Purdue and IEC 62443 answer different parts of the same design question. The Purdue Reference Model maps functional relationships from enterprise systems to process assets, and IEC 62443 uses risk-based zones and conduits to decide which communications belong together and which protections they require.
Industrial connectivity has changed faster than many plant diagrams, making this distinction important. Dragos documented 1,693 ransomware attacks targeting industrial organizations in 2024, an 87% increase from the prior year (Dragos, 8th Annual OT Cybersecurity Year in Review, 2025). Christopher Warner, OT Security Lead at GuidePoint Security, said in a Cybrsec Media interview: “The traditional Purdue Model assumed isolated layers and data flows that flowed only in one direction. That doesn’t match reality anymore. Attackers are exploiting remote access paths and flattened networks we never planned for.”
What Does the Purdue Model Clarify?
Purdue gives teams a shared planning language for reviewing interactions among enterprise services, site operations, supervisory systems, basic control functions, and field assets. It should guide communication review, not dictate a fixed physical topology.
An industrial DMZ commonly sits between enterprise and OT functions so corporate services do not connect directly to control systems. NIST SP 800-82 Rev. 3 (2023) recommends this separation point: approved services can be inspected and managed at a defined boundary.
How Do Zones and Conduits Set Risk Boundaries?
IEC 62443 turns the functional map into accountable security decisions. Think of zones as fire compartments in a production facility and conduits as controlled doors: assets with similar protection needs stay together, and each approved crossing has rules for who and what may pass.
SINTEF’s Security Aspects of Zones and Conduits in IEC 62443 (2024) explains that risk assessment assigns security levels across industrial automation and control systems, grouping components with common requirements into zones. The review must consider more than IP ranges.
- Asset criticality: What production or safety consequence follows loss of the asset?
- Communication necessity: Which data flow is necessary for the process to run?
- Access assurance: Which identity, approval, and session controls govern the route?
- Recovery consequence: How quickly must the function return, and what evidence supports investigation?
| Framework dimension | Executive question | Primary evidence | Common misreading |
|---|---|---|---|
| Functional layering | Where does this system operate? | Purdue relationship map | Layers alone create security |
| Asset criticality | What fails if access changes? | Process and safety review | All OT assets need identical controls |
| Communication necessity | Why must this route exist? | Approved flow register | Existing traffic is automatically justified |
| Recovery consequence | What must be restored first? | Tested response plan | Backups alone prove resilience |
Together, the models replace assumed trust with documented operational choices. The next task is proving that those choices work in the network.
Which Controls Make OT Segmentation Defensible?
Defensible segmentation combines asset knowledge, risk-based zones, controlled conduits, a DMZ, governed access, and tested response. Each control must produce evidence that a boundary operates as designed, particularly when an older device cannot receive a timely update.
Patching cannot carry this burden alone. Of 670 industrial control system and operational technology (OT) common vulnerabilities and exposures (CVEs) disclosed by the Cybersecurity and Infrastructure Security Agency (CISA) in the first half of 2023, 34% had no vendor patch or remediation available (SynSaber and ICS Advisory Project, ICS Vulnerabilities – First Half of 2023, 2023). Compensating controls must limit reachability and record activity around those assets.
The Cybersecurity and Infrastructure Security Agency states: “Network segmentation can be achieved by breaking up the network into smaller segments and controlling traffic between them. This helps to limit the impact of a potential breach by containing it within a single segment.”
- Asset inventory and criticality classification: Identify each device, firmware state, owner, function, and permitted connection.
- Zones, conduits, and deny-by-default traffic policy: Allow only documented communications across boundaries.
- Industrial DMZ and brokered service patterns: Place approved exchange services between enterprise and control environments.
- Identity-bound remote access and privileged activity evidence: Tie every session to an approved user and task.
- Detection, containment, and recovery validation: Test whether teams can isolate a zone without creating unsafe operating conditions.
| Component | Leadership signal | Decision supported | Common interpretation error |
|---|---|---|---|
| Asset inventory | Known ownership and criticality | Remediation priority | Discovery is a one-time activity |
| Zone policy | Approved routes are documented | Boundary investment | VLANs alone equal segmentation |
| Industrial DMZ | Enterprise-to-OT exchange is controlled | Service design | A firewall alone proves separation |
| Governed access | Session evidence links identity to activity | Supplier accountability | Authentication proves authorization |
| Response validation | Containment is tested | Recovery planning | A written plan proves readiness |
Maturity scores are useful only when they show change over time. Leaders need trend evidence that boundaries, access routes, and recovery decisions still match the plant’s operating reality.
When Should Leaders Redesign Factory Boundaries?
A redesign is warranted when the network no longer reflects how the plant actually operates. Acquisitions, line expansions, new cloud services, inherited equipment, and supplier workarounds often create paths that the original design never assessed.
That pattern appears often in field work. In 2023, 28% of Dragos services engagements identified segmentation issues, and manufacturing represented 58% of those engagements (Dragos, Lessons Learned from the Frontlines of OT Defense – 2023 Year in Review, 2024). The report identified missing OT DMZs, authentication spanning zones, unsecured external connections, unsafe historian designs, and safety-system environments without segmentation.
- Establish the current-state truth: Compare diagrams with active devices, accounts, routes, and contractor workflows.
- Define the target risk boundary: Set zones around process consequence and operational dependency.
- Sequence controls around production windows: Use change control that respects safety checks and engineering ownership.
- Validate containment and recovery: Test the decisions during realistic operating conditions.
| Operating context | Architecture priority | Implication |
|---|---|---|
| Greenfield facility | Design zones before commissioning | Requirements reach suppliers early |
| Brownfield plant | Build visibility before major change | Controls must fit legacy constraints |
| Multi-site manufacturer | Set common boundary principles | Local differences need documented exceptions |
| Regulated operation | Preserve evidence and approvals | Governance must withstand review |
A factory network security architecture does not require a single disruptive replacement program. It requires a sequenced plan that removes unjustified pathways before they become a production issue.
Where Does Remote Access Break Factory Boundaries?
Remote maintenance often crosses the boundaries that zoning was built to protect. The problem is not remote access itself; it is standing trust that lets a supplier identity, device, or connection reach beyond the task it was approved to perform.
Supplier complexity makes this harder in practice. The World Economic Forum’s Building a Culture of Cyber Resilience in Manufacturing (2024) notes that manufacturing plants commonly rely on multiple vendors across diverse operating environments. Each workflow needs a clear sponsor, limited scope, and record of the work performed.
- Persistent supplier connectivity: Replace broad standing access with approved, time-bound sessions.
- Cross-zone credentials: Keep identities from automatically spanning enterprise, DMZ, and control zones.
- Unobserved maintenance activity: Record sessions and preserve access evidence.
- Emergency access exceptions: Define accountable emergency procedures and post-event review before an incident occurs.
The Cybersecurity and Infrastructure Security Agency advises, “Use DMZs to segregate business and control architectures.” A DMZ works only when the remote workflow enforces identity checks, authorization, monitoring, and a defined end to access.
How RealVNC Closes the Factory Network Security Gap
An industrial DMZ, zones and conduits, and documented firewall rules lose value when engineers, original equipment manufacturers, or service partners retain broad and unlogged access to production-adjacent systems. The gap sits in the workflow: who enters, which system they reach, what actions they perform, and what evidence remains after the session closes.
RealVNC Connect supports role-based access controls and granular action-based permissions, allowing organizations to govern keyboard, mouse, and file-transfer activity separately. Multi-factor authentication (MFA) and single sign-on (SSO) with Microsoft Entra ID or Okta connect remote support to established identity controls. Session monitoring, recording, and detailed audit logs give authorized administrators evidence of who connected, when they connected, and which permissions applied. For short-lived third-party support, Code Connect uses 9-digit time-bound session codes rather than issuing standing credentials.
These controls do not replace segmentation, an industrial DMZ, or OT monitoring. They make the approved remote path more enforceable by limiting vendor intervention to the task and time required, and retaining evidence for incident investigation and supplier accountability across distributed facilities.
Final Words
When a production network issue crosses from enterprise systems into OT, the decision is no longer confined to a firewall rule or a support ticket. A factory network security architecture depends on joint ownership of asset criticality, approved communications, and recovery priorities. Purdue helps teams map where systems interact, and IEC 62443 gives them a way to set risk-based zones and conduits around the processes that matter most. Asset inventories, industrial demilitarized zones (DMZs), controlled traffic routes, and tested containment plans turn those principles into operating discipline.
Remote maintenance deserves the same level of design. RealVNC Connect adds role-based access controls, session recording, and detailed audit logs to the approved support path, so authorized teams can govern third-party activity and retain evidence for review. That gives IT, OT, engineering, and security leaders a clearer basis for protecting production continuity without leaving supplier access unmanaged. Arrange a meeting to explore how RealVNC Connect can support governed, auditable remote access across your factory environment.
FAQs
These answers connect the article’s architecture framework to the questions leaders typically raise during design reviews, supplier-access assessments, and investment planning.
What Framework Guides Industrial Network Zoning?
A factory network security architecture combines Purdue’s functional reference model with IEC 62443’s risk-based zones-and-conduits method. Purdue maps how enterprise systems, operations services, control functions, and process assets relate, and IEC 62443 assigns security expectations according to risk and consequence (SINTEF, Security Aspects of Zones and Conduits in IEC 62443, 2024). Use both models as decision aids, then validate the result against asset knowledge, process requirements, and engineering change controls.
How Is OT Security Different From IT Perimeter Security?
OT security protects production availability and process integrity alongside confidentiality and access control. Industrial assets often have long service lives, narrow maintenance windows, and safety implications that make disruptive changes unacceptable without engineering review. Security, IT, OT, and engineering leaders need shared decision rights for segmentation, access, monitoring, and recovery.
What Does an Industrial DMZ Accomplish?
An industrial demilitarized zone (DMZ) creates a controlled exchange point between enterprise and operational technology environments. NIST recommends implementing a DMZ to separate OT from the enterprise network (NIST SP 800-82 Rev. 3, Guide to Operational Technology Security, 2023). Its value depends on approved services, defined data flows, authentication, monitoring, and enforcement; placing another firewall in the path does not establish those controls by itself.
What Should an Industrial Network Security Diagram Show?
An industrial network security diagram should show functional zones, conduits between them, the industrial DMZ, approved data flows, and ownership for each boundary. It should identify remote-maintenance routes, supplier access points, enterprise connections, and the systems that require special recovery treatment. A useful diagram explains why each connection exists and what happens when that route is unavailable or requires containment.
How Does RealVNC Support Factory Access Governance?
RealVNC Connect supports factory access governance through role-based access controls, granular action-based permissions, multi-factor authentication (MFA), single sign-on (SSO), session recording, and detailed audit logs. These controls help organizations link remote maintenance to an authorized identity, limit permitted activity, and retain evidence for review. RealVNC Connect supports the access workflow around an industrial DMZ and segmented environment; it does not replace OT segmentation, boundary design, or incident-response planning.


)
)