What is IT & OT Network Segmentation?
Do not place the office, visitors, CCTV, servers and production machines in one open room with every door unlocked. Segmentation creates rooms and checkpoints. Information can still pass where the business needs it, but one infected laptop should not have a direct path to every factory device.
The Technical Explanation
IT/OT network segmentation separates office systems, servers, guests, internet-facing services and factory control equipment into controlled zones. Firewalls and approved data paths limit unnecessary communication.
Business Impact
This can reduce the chance that an office malware incident spreads into PLC, HMI or SCADA environments.
Warning Signs
- Factory machines share the same network as guest Wi-Fi
- Vendors connect directly using shared remote-access accounts
- Unsupported Windows HMI computers can browse the internet
- No diagram shows communication between ERP, MES and PLC networks
- Backup or management traffic uses the same unrestricted network
Practical Solution
1. Discover devices and communication flows 2. Create zones based on function and risk 3. Place firewalls or industrial controls between IT and OT 4. Use controlled jump hosts and MFA for vendor access 5. Allow only required ports and destinations 6. Monitor logs and test production impact before enforcement
Frequently Asked Questions
Will segmentation stop production?
Poorly planned changes can, so discovery, testing and staged implementation are essential.
Is a VLAN alone enough?
A VLAN separates broadcast domains, but security usually requires controlled routing and firewall policy between zones.
Can old HMI systems be protected without upgrading them?
Risk can often be reduced through isolation, application control, controlled access and backup, although replacement planning may still be needed.