How Do You Segment OT and IT Networks Without Disrupting Operational Continuity?

Share:
Learn how to segment OT and IT networks using proven zone models and phased rollouts that protect uptime, safety, and production continuity.

A plant manager does not want to hear the word “firewall” during a production run. A CISO does not want to explain to the board why a segmentation project caused a four-hour line stoppage. Yet both outcomes are avoidable when OT and IT network segmentation is planned with operational continuity as the starting point, not an afterthought.

While industrial environments were built for reliability and safety, IT networks were built for identity checks and access control. When these two worlds converge through smart sensors, remote vendor access, and cloud-connected historians, the boundary between them becomes the single most important control a security leader can build. Get that boundary wrong and you either leave the plant floor exposed or break the processes it was meant to protect.

Why OT and IT Convergence Raises the Stakes for Segmentation

Manufacturing floors, utilities, oil and gas facilities, and pharmaceutical plants have spent the last decade connecting PLCs, HMIs, and SCADA systems to corporate networks for reporting, predictive maintenance, and remote monitoring. This convergence delivers efficiency, but it also gives attackers a path from a phishing email in a finance inbox to a control system on the shop floor.

Ransomware groups target industrial organizations because a locked HMI or a halted assembly line creates pressure to pay quickly. Once an attacker lands on a flat, unsegmented network, lateral movement from IT to OT can happen in minutes. Segmentation turns that minutes-long compromise into a contained incident that never touches the process layer. Ampcus Cyber’s work across ICS and OT security engagements consistently shows that organizations without defined zones take far longer to detect and contain incidents originating on the IT side.

What Operational Continuity Means for OT Environments

Operational continuity is not the same conversation as IT uptime. In OT, a five-second latency spike on a control loop can trip a safety interlock, waste a batch, or create a physical safety hazard. A segmentation project that ignores this, by inserting a firewall inline without testing latency, or rebooting switches during a live production cycle, causes the exact disruption security teams are trying to prevent.

This is why OT segmentation needs engineering sign-off, not just security sign-off. Process engineers know which systems tolerate a maintenance window, and which cannot be touched without a planned shutdown. Security teams know attack paths and control requirements. Successful projects treat these as equal inputs rather than security dictating terms to operations.

The table below outlines where IT and OT segmentation priorities diverge, and why a single playbook rarely works for both.

FactorIT SegmentationOT Segmentation
Primary objectiveProtect data confidentiality and integrityProtect process safety and physical uptime
Scanning approachActive scanning is standard practicePassive monitoring only, active scans can crash legacy devices
Downtime toleranceMaintenance windows are frequent and flexibleChanges are tied to planned shutdowns or turnarounds
Patch cadenceRegular, often automatedSlow, validated against vendor certification first
Change controlSecurity-ledJoint sign-off between engineering and security
Failure modeService degradationPotential safety incident or production loss

Applying the Purdue Model and Zone-Based Segmentation

The most reliable starting point for OT and IT segmentation remains the Purdue Enterprise Reference Architecture, commonly known as the Purdue Model. It divides the industrial environment into levels, from field devices and controllers at the bottom up through supervisory control, site operations, and the enterprise IT network at the top. Between OT and IT sits Level 3.5, the industrial demilitarized zone, or iDMZ. This layer brokers every data exchange between the plant floor and the business network, hosting the jump servers and historian mirrors that let IT and OT share data without a direct connection into the control network.

NIST SP 800-82 Revision 3 formalizes this layered approach with tailored security control baselines for OT systems of varying criticality. The ISA/IEC 62443 standard builds on the same model through zones and conduits, grouping assets with shared security requirements and treating every connection between zones as a conduit that must be authenticated and restricted to only the traffic it needs.

CISA guidance following joint threat hunts at critical infrastructure operators reinforces the same point: organizations that map their environment against the Purdue Model and validate IEC 62443 compliance detect and contain intrusions faster than those running flat networks.

Building a Phased Segmentation Roadmap Without Halting Production

Segmentation done correctly is a sequence of small, validated steps rather than a single cutover weekend. A roadmap that respects production schedules typically follows this order.

Step 1: Asset Discovery and Dependency Mapping

Before a single rule is written, catalogue every device, protocol, and data flow. Use passive monitoring tools here, since active scanning can crash legacy PLCs never designed to handle unexpected packets.

Step 2: Risk-Based Zone Definition

Group assets by function, criticality, and safety impact rather than physical location alone. A safety instrumented system deserves its own zone, separate from general process control.

Step 3: Conduit Design and Traffic Baselining

Document every legitimate connection between zones before enforcement begins. This baseline becomes the allow list that later blocks anything unexpected. Model remote vendor access as its own conduit, brokered through the iDMZ and governed by the same zero trust principles applied to the corporate network.

Step 4: Shadow Mode Deployment

Run new segmentation rules in monitoring mode first, logging violations without blocking traffic. This catches the undocumented connections that always surface once a network is mapped in detail.

Step 5: Phased Enforcement During Planned Windows

Move from monitoring to blocking one zone at a time, aligned to maintenance schedules that operations teams already control.

Step 6: Continuous Validation

Segmentation is not a project with an end date. New vendors, new devices, and new remote access requests change the environment constantly, and the zone model needs governance to match.

Common Segmentation Mistakes That Disrupt Operations

Most disruption traces back to a handful of repeated errors. Teams enforce blocking rules before completing a full traffic baseline, cutting off legitimate but undocumented communication between a historian and a control system. Teams also treat remote vendor access as an exception rather than a conduit needing its own controls, leaving a permanent backdoor that undermines the architecture.

Cloud connectivity creates a similar risk. As more organizations push OT data to cloud platforms for analytics, the segmentation model must account for that traffic without opening a direct path from the cloud back into the control network. Ampcus Cyber’s guidance on cloud adoption in OT and ICS environments addresses this gap, recommending brokered data flows through the iDMZ rather than direct cloud-to-control connections.

How Ampcus Cyber Helps Segment OT and IT Networks Safely

Security leaders rarely fail at segmentation because they misunderstand the concept. They fail because the rollout was not sequenced around production realities, or because governance around the zone model faded once the project closed. Ampcus Cyber pairs ICS and OT security assessments with a broader governance, risk, and compliance framework so segmentation decisions stay documented, auditable, and aligned with NIST SP 800-82 and IEC 62443 long after go-live.

Getting this boundary right protects the safety of your operations and the resilience of your business.

Talk to Ampcus Cyber about a segmentation assessment that keeps your OT and IT networks secure without stopping the line.

Enjoyed reading this blog? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn.

×

7th August 2026

New Delhi, India

Know more
Ampcus Cyber
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Talk to an expert