A routine corporate-system incident reaches a plant network, and the consequences do not stay with IT. Operators lose visibility, maintenance work pauses, and leaders must account for interrupted output as teams determine which connections remain safe to use.
IT/OT network segmentation separates corporate IT, operational technology (OT), and industrial control systems into risk-based security zones, allowing only approved communications through defined conduits. It contains an intrusion within its affected area, limits unnecessary movement between devices, and keeps key process equipment reachable only through connections that operations has validated and approved.
The boundary has become harder to manage. Cloud services, remote support, shared historian data, and connected sensors create valid links between enterprise and plant systems. Many legacy OT assets cannot accept endpoint software or frequent changes. A broad access rule may solve an immediate maintenance need, then remain long after its owner and purpose are forgotten.
This guide explains how to validate assets and normal traffic, use Purdue and IEC/ISA 62443 concepts to define zones and conduits, and place controls at the crossings that matter. It covers industrial demilitarized zones (DMZs), least-privilege rules through firewalls and access-control lists (ACLs), time-bound remote access, and isolation testing. Governance reviews keep approved pathways aligned with plant operations.
Why IT/OT Network Segmentation Matters Now
The boundary between enterprise systems and plant operations now carries far more traffic than most original network designs anticipated. IT/OT network segmentation creates risk-based zones and permits only governed communications between them. It gives leaders a way to contain an intrusion without cutting off the data, maintenance, and support services that production depends on.
Public exposure shows why perimeter assumptions are insufficient. Censys’s The 2024 State of the Internet Report: Industrial Control Systems identified more than 145,000 internet-connected industrial control system services globally in 2024. The board question is not whether every connection is avoidable; it is whether each connection has an owner, a stated purpose, and a control point.
A historian, patch relay, shared identity service, or vendor-support route may have a valid role. Each also creates a route across trust boundaries. The framework below turns those routes into named conduits that operations, security, and engineering teams can review together.
Why Is IT/OT Network Segmentation a Board Issue?
Weak internal boundaries turn a corporate security event into an operational-resilience event when enterprise access reaches equipment that runs a process. A compromised office workstation should not automatically gain a route to a production-line controller. Segmentation limits that route through explicit zones, approved conduits, and accountable access decisions.
The urgency has a business basis. Of 107 industrial cyber incidents publicly confirmed by victims in late 2024, at least half involved ransomware, according to Kaspersky ICS CERT’s A Brief Overview of the Main Incidents in Industrial Cybersecurity, Q4 2024 (2024). Prevention still matters, but containment determines whether one affected endpoint becomes a wider production interruption.
ENISA’s Technical Implementation Guidance on Cybersecurity Risk Management Measures (2025) identifies zero trust as relevant to remote access, service-provider access, network segmentation, and device control. For leaders, zero trust means each request crosses a defined decision point rather than inheriting trust from its network location.
Which pressures make the boundary a business priority?
The recurring pressures are operational exceptions that become permanent pathways unless someone owns their review.
- Ransomware containment: Separate control zones limit the systems reachable after an enterprise incident.
- Uptime protection: A shared historian or engineering workstation needs a tested communication path, not broad network reach.
- Regulatory accountability: Leaders need evidence that critical conduits have a purpose, approver, and review date.
- Third-party access governance: Vendor sessions require identity checks and expiry rules instead of standing credentials.
| Legacy assumption | Modern segmentation principle | Executive consequence |
|---|---|---|
| Internal systems are trusted | Every cross-zone flow needs a stated purpose | Decision rights become visible |
| One firewall is enough | Controls sit at each material conduit | Containment has defined boundaries |
| Vendor access is operational overhead | Vendor paths are governed services | Maintenance access gains accountability |
| Recovery starts after an event | Isolation is tested before an event | Operations can validate continuity plans |
The decision is straightforward: if a conduit cannot be explained, approved, and tested, it does not belong in a production design.
Which Architecture Creates Controlled IT/OT Boundaries?
A controlled architecture starts with the communication a process requires, then places enforcement around that need. The Purdue Reference Model maps functional relationships across enterprise, operations, and process layers. IEC/ISA 62443 adds a risk-based method for grouping assets with common security requirements and defining the conduits between them.
Think of the design as a factory with controlled loading bays. Zones are the secured work areas; conduits are the loading bays where deliveries are checked before moving inside. The model does not prescribe one physical topology, but it makes every crossing visible and governable.
Visibility remains an unfinished task in many environments. SANS Institute’s 2024 State of ICS/OT Cybersecurity reported OT-specific monitoring by 52% of respondents in 2024, up from 33% in 2019. Monitoring helps teams learn traffic patterns, yet an inventory still needs validation from engineering and maintenance owners.
How do Purdue and IEC 62443 serve different roles?
Purdue helps teams map devices by function and criticality. NERC’s Zero Trust Security for Electric Operational Technology (2023) describes the model as useful for grouping OT devices by function or criticality. It is a planning reference, not a complete policy engine.
IEC/ISA 62443 adds the security-requirement lens. Cisco’s ISA/IEC 62443-3-3 guidance (2024) defines zones as asset groups with common security requirements and conduits as logical communication channels between zones. Two systems at the same Purdue level may belong in separate zones when their consequence, ownership, or change tolerance differs.
Purdue model: Maps functional and trust relationships across industrial operations.
Zone-and-conduit model: Defines which asset groups share security requirements and how their communications are governed.
What belongs in an industrial DMZ?
An industrial demilitarized zone (DMZ) is a brokered-services layer between enterprise IT and OT operations. NIST SP 800-82 Rev. 3 (2024) states that enterprise-to-control-center communications should transit services in a DMZ separating the OT environment from the enterprise network. It is a controlled transfer point, not another route for direct corporate-to-control traffic.
CISA’s Configuring and Managing Remote Access for Industrial Control Systems (2023) advises organizations to “Use DMZs to segregate business and control architectures.” Appropriate DMZ services include:
- Patch-management relays
- Historian-data mirrors
- Proxy and application-broker services
- Remote-access gateways and hardened jump hosts
Conceptual flow: Enterprise IT → industrial DMZ → OT operations → process-control zones, with governed conduits at each boundary and a separately controlled vendor-access path.
| Framework dimension | Leadership question | Evidence input | Design output | Common misread |
|---|---|---|---|---|
| Asset criticality | What fails if this asset is unavailable? | Process analysis | Criticality tier | IP address defines importance |
| Zone definition | Which assets share requirements? | Ownership and change tolerance | Zone boundary | One subnet equals one zone |
| Conduit purpose | Why must this flow exist? | Protocol inventory | Approved flow record | Persistent access is normal |
| Enforcement point | Where is traffic checked? | Device capability | Firewall, ACL, or broker | One control fits every asset |
| Accountable owner | Who accepts the exception? | Service ownership | Review authority | Security owns operations alone |
The 5 Decisions That Make Segmentation Enforceable
Segmentation becomes enforceable when leaders turn architecture into evidence-backed decisions. The sequence is consistent: discover what communicates, classify what matters, authorize necessary flows, place controls, and validate isolation with operations involved.
This discipline compensates where patching is unavailable or unsafe. SecurityWeek’s analysis of SynSaber data reported that CISA disclosed 670 ICS/OT product vulnerabilities in the first half of 2023. Of those vulnerabilities, 34% lacked a patch or remediation, compared with 13% in the first half of 2022. Network controls reduce reachable pathways as asset owners manage longer remediation decisions.
- Establish the OT protocol inventory. Use passive discovery, engineering records, and maintenance schedules to identify assets, owners, protocols, and normal flows. Avoid active scanning where fragile equipment could be affected. Owners must validate the resulting inventory.
- Define zones by common security requirements. Group assets by consequence, function, and change tolerance. Do not treat an IP range as a security boundary simply because it is convenient.
- Design conduits and allowed flows. Record each cross-zone connection, its business purpose, protocol, owner, and whether it is persistent, brokered, time-bound, or removed.
- Choose enforcement points. Match industrial firewalls, access-control lists (ACLs), microsegmentation, jump hosts, and identity controls to each conduit. Some legacy assets cannot run endpoint software, so controls must fit the equipment.
- Test isolation and recovery. Validate authorized services and failed unauthorized paths during approved maintenance windows, with a rollback plan and documented exception expiry.
CISA’s People’s Republic of China-Linked Cyber Actors Hide in Router Firmware advisory (2024) warns that organizations need connection awareness before severing enterprise internet access since isolation changes may interrupt critical functions. A mature program values tested exceptions and reliable trend evidence over a single maturity score.
| Decision | Required evidence | Leadership decision | Success check |
|---|---|---|---|
| Inventory | Asset and flow records | Scope production-critical assets | Owners validate records |
| Zone design | Criticality and process analysis | Approve separation boundaries | Zones match requirements |
| Conduits | Data-flow diagrams | Approve or remove each flow | Purpose is documented |
| Enforcement | Device capability and protocol behavior | Select control points | Controls fit operations |
| Validation | Test and rollback plans | Approve test windows | Required services operate safely |
How Do Leaders Sequence IT/OT Segmentation Safely?
The safest program does not begin with a site-wide policy change. It begins with the conduits whose failure or misuse carries the greatest operational consequence, then adds enforcement after teams observe and validate the communications those services require.
This approach recognizes a real trade-off: broad access reduces short-term friction. Untested restrictions can interrupt production. In its CIP-008-6 Annual Report (2023), NERC recorded three reports involving attempted compromise; none met the reporting threshold for a Cyber Security Incident. That finding is a reporting observation, not a measure of all industrial activity, but it reinforces the need to test and document response decisions.
- Prioritize consequential conduits first. Start with enterprise-to-OT, vendor, historian, and engineering-workstation paths.
- Use monitor-before-enforce gates. Observe communications, validate dependencies, then apply restrictive rules with a tested rollback path.
- Assign exception decision rights. Every broad or persistent conduit needs an OT owner, justification, expiry date, and review point.
- Measure resilience through exercises. Confirm that unauthorized paths fail, approved maintenance remains possible, and recovery works when a zone is isolated.
TechTarget’s report on Dragos findings (2025) observed that industrial organizations assisted during 2024 that enforced strict separation and tested offline backups shortened recovery times and avoided ransom payment. That is an incident-response observation, not a universal guarantee. It supports phased change management that puts production evidence ahead of policy volume.
| Sequencing approach | Implication | Appropriate context |
|---|---|---|
| Immediate broad enforcement | Fast boundary change, greater service-interruption risk | Small, well-mapped environments |
| Monitor then enforce | Slower rollout, stronger dependency evidence | Uptime-sensitive sites |
| Start with critical conduits | Focuses effort on material pathways | Complex multi-site operations |
| Exception-led remediation | Preserves services while reducing access over time | Legacy-heavy environments |
Boundary Bypasses: Where Governance Breaks Down
A sound network diagram fails when workarounds cross it without ownership. Direct corporate-to-SCADA paths, dual-homed systems, undocumented historian access, and permanent exceptions often arise during maintenance or incident response, then remain after the immediate need has passed.
The remedy is governance that treats each bypass as a time-bound risk decision. ENISA’s Technical Implementation Guidance recommends that in-scope entities consider separation from third-party systems as part of cybersecurity risk management. CISA’s DMZ guidance provides the architectural pattern: terminate and inspect services at the boundary rather than allowing direct enterprise-to-control connections.
- Direct connections: Corporate clients reach control services without a brokered path.
- Dual-homed systems: One host joins two zones and bypasses intended controls.
- Remote vendor access: External support retains standing access beyond maintenance needs.
- Shared services: Historian, file, or identity dependencies cross boundaries without clear ownership.
- Rule creep: Temporary permissions remain after the original work is complete.
| Boundary bypass | Governance owner | Control evidence |
|---|---|---|
| Direct control connection | OT service owner | Approved conduit record |
| Dual-homed host | Infrastructure owner | Architecture review |
| Vendor session | Service sponsor | Identity and session record |
| Shared historian service | Data owner | DMZ placement decision |
| Persistent rule exception | Security and OT approver | Expiry and quarterly review |
Review conduit ownership and exception expiry quarterly. IEC 62443, NIS2, and NERC CIP-aligned programs require evidence that control decisions match the organization’s sector and legal obligations; one architecture does not establish compliance by itself.
How RealVNC Closes the IT/OT Network Segmentation Gap
A zone-and-conduit model often weakens at the point where people need intermittent access. Original equipment manufacturers, integrators, field engineers, and IT support teams may need to reach human-machine interfaces, engineering workstations, or supporting services. Their route must remain identity-bound, time-limited, observable, and aligned with an approved conduit rather than becoming a permanent boundary bypass.
RealVNC Connect governs the remote-support session inside that broader industrial DMZ, jump-host, and conduit-policy design. It does not replace industrial firewalls, zones, or a DMZ. Instead, it supports controlled access through four workflow controls:
- Multi-factor authentication and single sign-on (SSO): MFA and SSO with Microsoft Entra ID or Okta support centralized identity verification before an approved session begins.
- Role-based permissions: Role-based access controls and granular action-based permissions let administrators separately govern keyboard, mouse, and file-transfer actions.
- Code Connect: Single-use nine-digit session codes provide time-bound access for third-party or ad hoc support without issuing standing credentials.
- Session evidence: Session monitoring, recording, and detailed audit logs create a reviewable record of remote activity.
That distinction matters during maintenance and incident review. RealVNC Connect helps teams make authorized remote access controllable and observable within IT/OT network segmentation, and operations retains the approved path required to keep critical systems running.
Final Words
A production environment stays resilient when its boundaries reflect the way work actually moves. IT/OT network segmentation starts with a validated inventory of assets and normal communications, then groups systems by common security requirements and gives every cross-zone conduit a stated purpose, owner, and review point. Purdue helps teams map functional relationships. IEC 62443 turns that map into risk-based zone-and-conduit decisions. An industrial DMZ keeps shared services and remote routes at a managed boundary, rather than leaving direct enterprise-to-control paths in place.
The work only holds when maintenance, vendor support, and incident response follow those same approved paths. Monitor before enforcing new restrictions, assign expiry dates to exceptions, and test isolation with operations teams before a live event forces the decision. RealVNC Connect complements this operating model with role-based access controls, time-bound Code Connect sessions, and session recording with detailed audit logs, so authorized support activity remains reviewable inside the wider boundary design. That gives security, engineering, and operations teams evidence they can use to protect critical services without turning necessary access into a permanent bypass. Arrange a meeting to discuss how RealVNC Connect can help make controlled remote access an auditable part of your IT/OT network segmentation program.
FAQs
These answers focus on the architecture, governance, and access decisions that shape industrial network security.
What is the framework for IT/OT network segmentation?
The framework for IT/OT network segmentation combines asset discovery, risk-based zones, documented conduits, industrial DMZ services, least-privilege controls, and isolation testing. The NIST SP 800-82 Rev. 3 guidance (2024) supports separating OT environments into levels or zones. NERC’s Zero Trust Security for Electric Operational Technology (2023) describes the Purdue Model as useful for grouping devices by function or criticality. Together, these references help leaders connect architecture decisions with operational risk.
What is the difference between zoning and microsegmentation?
Zoning separates groups of assets that share security requirements. Microsegmentation applies finer controls between individual hosts, workloads, or device groups. IEC/ISA 62443-3-3 guidance (2024) defines zones and the conduits connecting them; microsegmentation adds narrower enforcement where the operational benefit justifies more policy and testing effort. Legacy OT equipment may require controls at firewalls, gateways, or jump hosts instead of on the device itself.
What is an OT network compared with an IT network?
An OT network connects systems that monitor or control physical processes; an IT network primarily supports business computing, information, and communication services. OT environments place greater weight on process continuity, equipment constraints, and safe change windows. Their connection must be governed through defined conduits, approved services, and operational ownership rather than assumed trust between internal networks.
What are the types of network segmentation?
Common types include physical separation, virtual local area network (VLAN) separation, firewall-based zoning, industrial DMZs, and microsegmentation. Physical separation creates the clearest boundary. VLANs organize traffic logically and require additional enforcement to provide meaningful security. The appropriate design depends on asset capability, process requirements, communication paths, and the consequence of an unavailable service.
Is network segmentation the same as a VLAN?
Network segmentation is the broader practice of separating systems and controlling communications; a VLAN is one logical method for organizing devices on a network. A VLAN alone does not document why a connection exists, authenticate a user, or govern traffic between zones. Leaders need to assess the enforcement point, conduit policy, and testing evidence around each VLAN.
Which standards guide OT boundary governance?
IEC/ISA 62443 provides the core zone-and-conduit structure. NIS2-related guidance informs cybersecurity risk management for in-scope EU entities. ENISA’s Technical Implementation Guidance (2025) addresses network separation and third-party systems, and NERC CIP-005-8 addresses electronic security perimeters in applicable bulk electric system environments. Organizations must map controls to their sector and legal scope.
How does RealVNC support controlled OT access?
RealVNC Connect supports controlled remote-access workflows through multi-factor authentication, single sign-on with Microsoft Entra ID and Okta, role-based access controls, and granular action-based permissions. Code Connect provides time-bound session codes, while session monitoring, session recording, and detailed audit logs support review of authorized activity. These controls complement industrial DMZs, jump hosts, and conduit policies; they do not replace them.


)
)