Why the usual advice does not land
Enterprise segmentation guidance assumes you can change a firewall rule, observe what breaks, and roll back. On a production line that assumption does not hold: the cost of an unplanned stop is measured in lost output and sometimes in safety, and the equipment may be running software that cannot be patched, restarted casually, or in some cases even scanned.
The result is a widespread pattern of plants that are nominally segmented — there is a firewall between the business network and the plant network — while in practice carrying a long list of exceptions, a flat plant network behind that firewall, and vendor remote access that bypasses it entirely.
Stage one: see the traffic before you change anything
Passive network monitoring on span or tap ports changes no configuration and risks nothing on the control network, and it reliably contradicts the documentation. In almost every assessment we find flows nobody expected: a historian reaching the internet for updates, a vendor laptop with a persistent tunnel, a controller talking directly to a business-network server, an engineering workstation bridged to both networks at once.
Four to six weeks of observation across a full production cycle, including a maintenance window, gives you the real communication matrix. Everything afterwards is cheaper and safer because of it.
Stage two: zones and conduits on paper
IEC 62443 models an industrial system as zones — groupings of assets with a shared security requirement — connected by conduits, which are the controlled paths between them. The model is useful here because it is a shared language: plant engineering thinks in process areas and criticality, IT security thinks in trust boundaries, and zones and conduits map cleanly onto both.
In practice the first cut is usually: enterprise, a demilitarised zone for the systems that legitimately need to exchange data in both directions, supervisory control, basic control, and safety instrumented systems as their own zone with the tightest constraints. Every flow you observed in stage one is then either assigned to a conduit or marked for removal.
- Define zones by shared security requirement and consequence of failure, not by physical location.
- Make every permitted flow an explicit conduit with a named owner and a business reason.
- Put all enterprise-to-plant data exchange through a demilitarised zone; no direct flows.
- Treat safety systems as a separate zone with no routine conduit to anything else.
Stage three: enforce in increments
Deploy the enforcement points in monitor mode first, so they report what they would have blocked without blocking it. Review that report with plant engineering, resolve the surprises, then move to alert, then to block one conduit at a time, each during a planned window with a rollback that has been tested.
This is slower than a single cut-over and it is the reason the work actually completes. Segmentation projects on production networks fail far more often from one unplanned stoppage destroying organisational confidence than from technical difficulty.
The two exceptions that undo everything
Vendor remote access is the most common uncontrolled conduit we find. Equipment suppliers legitimately need to reach their machines, and the arrangements are frequently older than the current security programme: a cellular modem installed by the vendor, a persistent tunnel, shared credentials, no logging. Bring every one of these into a single brokered path — authenticated per engineer, time-bound, session-recorded, approved per access.
The second is the dual-homed engineering workstation. A laptop connected to both the plant network and the business network is a routed path regardless of what the firewall says, and the same applies to removable media carried between zones. These need to be addressed by policy and by host configuration, because no amount of network architecture compensates for them.
Take this with you
The PDF edition carries the same content, formatted for printing and circulation inside your organisation.
