A plant manager does not want to hear the word “firewall” during a production run. A CISO does not want to explain to the board why a segmentation project caused a four-hour line stoppage. Yet both outcomes are avoidable when OT and IT network segmentation is planned with operational continuity as the starting point, not an afterthought.
While industrial environments were built for reliability and safety, IT networks were built for identity checks and access control. When these two worlds converge through smart sensors, remote vendor access, and cloud-connected historians, the boundary between them becomes the single most important control a security leader can build. Get that boundary wrong and you either leave the plant floor exposed or break the processes it was meant to protect.
Why OT and IT Convergence Raises the Stakes for Segmentation
Manufacturing floors, utilities, oil and gas facilities, and pharmaceutical plants have spent the last decade connecting PLCs, HMIs, and SCADA systems to corporate networks for reporting, predictive maintenance, and remote monitoring. This convergence delivers efficiency, but it also gives attackers a path from a phishing email in a finance inbox to a control system on the shop floor.
Ransomware groups target industrial organizations because a locked HMI or a halted assembly line creates pressure to pay quickly. Once an attacker lands on a flat, unsegmented network, lateral movement from IT to OT can happen in minutes. Segmentation turns that minutes-long compromise into a contained incident that never touches the process layer. Ampcus Cyber’s work across ICS and OT security engagements consistently shows that organizations without defined zones take far longer to detect and contain incidents originating on the IT side.
What Operational Continuity Means for OT Environments
Operational continuity is not the same conversation as IT uptime. In OT, a five-second latency spike on a control loop can trip a safety interlock, waste a batch, or create a physical safety hazard. A segmentation project that ignores this, by inserting a firewall inline without testing latency, or rebooting switches during a live production cycle, causes the exact disruption security teams are trying to prevent.
This is why OT segmentation needs engineering sign-off, not just security sign-off. Process engineers know which systems tolerate a maintenance window, and which cannot be touched without a planned shutdown. Security teams know attack paths and control requirements. Successful projects treat these as equal inputs rather than security dictating terms to operations.
The table below outlines where IT and OT segmentation priorities diverge, and why a single playbook rarely works for both.
| Factor | IT Segmentation | OT Segmentation |
| Primary objective | Protect data confidentiality and integrity | Protect process safety and physical uptime |
| Scanning approach | Active scanning is standard practice | Passive monitoring only, active scans can crash legacy devices |
| Downtime tolerance | Maintenance windows are frequent and flexible | Changes are tied to planned shutdowns or turnarounds |
| Patch cadence | Regular, often automated | Slow, validated against vendor certification first |
| Change control | Security-led | Joint sign-off between engineering and security |
| Failure mode | Service degradation | Potential safety incident or production loss |
Applying the Purdue Model and Zone-Based Segmentation
The most reliable starting point for OT and IT segmentation remains the Purdue Enterprise Reference Architecture, commonly known as the Purdue Model. It divides the industrial environment into levels, from field devices and controllers at the bottom up through supervisory control, site operations, and the enterprise IT network at the top. Between OT and IT sits Level 3.5, the industrial demilitarized zone, or iDMZ. This layer brokers every data exchange between the plant floor and the business network, hosting the jump servers and historian mirrors that let IT and OT share data without a direct connection into the control network.
NIST SP 800-82 Revision 3 formalizes this layered approach with tailored security control baselines for OT systems of varying criticality. The ISA/IEC 62443 standard builds on the same model through zones and conduits, grouping assets with shared security requirements and treating every connection between zones as a conduit that must be authenticated and restricted to only the traffic it needs.
CISA guidance following joint threat hunts at critical infrastructure operators reinforces the same point: organizations that map their environment against the Purdue Model and validate IEC 62443 compliance detect and contain intrusions faster than those running flat networks.
Building a Phased Segmentation Roadmap Without Halting Production
Segmentation done correctly is a sequence of small, validated steps rather than a single cutover weekend. A roadmap that respects production schedules typically follows this order.
Step 1: Asset Discovery and Dependency Mapping
Before a single rule is written, catalogue every device, protocol, and data flow. Use passive monitoring tools here, since active scanning can crash legacy PLCs never designed to handle unexpected packets.
Step 2: Risk-Based Zone Definition
Group assets by function, criticality, and safety impact rather than physical location alone. A safety instrumented system deserves its own zone, separate from general process control.
Step 3: Conduit Design and Traffic Baselining
Document every legitimate connection between zones before enforcement begins. This baseline becomes the allow list that later blocks anything unexpected. Model remote vendor access as its own conduit, brokered through the iDMZ and governed by the same zero trust principles applied to the corporate network.
Step 4: Shadow Mode Deployment
Run new segmentation rules in monitoring mode first, logging violations without blocking traffic. This catches the undocumented connections that always surface once a network is mapped in detail.
Step 5: Phased Enforcement During Planned Windows
Move from monitoring to blocking one zone at a time, aligned to maintenance schedules that operations teams already control.
Step 6: Continuous Validation
Segmentation is not a project with an end date. New vendors, new devices, and new remote access requests change the environment constantly, and the zone model needs governance to match.
Common Segmentation Mistakes That Disrupt Operations
Most disruption traces back to a handful of repeated errors. Teams enforce blocking rules before completing a full traffic baseline, cutting off legitimate but undocumented communication between a historian and a control system. Teams also treat remote vendor access as an exception rather than a conduit needing its own controls, leaving a permanent backdoor that undermines the architecture.
Cloud connectivity creates a similar risk. As more organizations push OT data to cloud platforms for analytics, the segmentation model must account for that traffic without opening a direct path from the cloud back into the control network. Ampcus Cyber’s guidance on cloud adoption in OT and ICS environments addresses this gap, recommending brokered data flows through the iDMZ rather than direct cloud-to-control connections.
How Ampcus Cyber Helps Segment OT and IT Networks Safely
Security leaders rarely fail at segmentation because they misunderstand the concept. They fail because the rollout was not sequenced around production realities, or because governance around the zone model faded once the project closed. Ampcus Cyber pairs ICS and OT security assessments with a broader governance, risk, and compliance framework so segmentation decisions stay documented, auditable, and aligned with NIST SP 800-82 and IEC 62443 long after go-live.
Getting this boundary right protects the safety of your operations and the resilience of your business.
| Talk to Ampcus Cyber about a segmentation assessment that keeps your OT and IT networks secure without stopping the line. |
Enjoyed reading this blog? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn.










