Skip to main content

Network Segmentation is the practice of dividing a network into smaller, controlled areas so that systems, users and devices only communicate where there is a clear business or operational need. In industrial environments, this is especially important because OT networks often support production lines, PLCs, HMIs, engineering workstations, historians, remote access routes and safety-related systems.

For manufacturers, utilities and critical infrastructure operators, segmentation is a practical cyber security control that can help reduce lateral movement, limit the spread of malware, protect critical assets and make network traffic easier to monitor. When an OT network is flat, one compromised device may have a wider route to other systems. A segmented design reduces that exposure by creating clear boundaries.

What Is Network Segmentation?

Network Segmentation separates a larger network into smaller zones, subnets or security areas. Each segment can then have its own access rules, monitoring controls and permitted communication paths. In simple terms, not every device should be able to talk to every other device.

In an OT environment, this may mean separating enterprise IT, production control, safety systems, engineering workstations, remote access, wireless devices and machine cells. The aim is to keep communication controlled while allowing production systems to operate safely and reliably.

Why Network Segmentation Matters In OT

Network Segmentation matters in OT because industrial systems are often difficult to patch, hard to replace and built for long service life. Many environments include legacy controllers, older operating systems, unmanaged switches and vendor-maintained equipment. These systems may not support the same controls as modern IT devices, so network design becomes a critical layer of protection.

Good segmentation can help contain a cyber incident before it affects wider production. It can also make traffic flows easier to understand. If engineers know which systems should communicate, unexpected traffic becomes easier to investigate. This supports better incident response, safer remote access and clearer responsibility between IT, OT and suppliers.

Network Segmentation

Network Segmentation And Network Segregation

The terms Network Segmentation and network segregation are often used together. Segmentation usually means dividing the network into controlled areas. Segregation often implies stronger separation, sometimes using physical separation or strict boundary controls.

A standard VLAN may be suitable for lower-risk separation, but high-criticality assets may need stronger controls such as dedicated switches, industrial firewalls, strict access control lists, data diodes or a demilitarised zone between IT and OT. The right choice depends on risk, operational need and the consequences of failure.

Industrial Network Segmentation: Zones, Conduits And The Purdue Model

Industrial segmentation is commonly planned using zones and conduits. A zone groups assets with similar function, risk or security requirements. A conduit is the controlled communication path between zones. This approach helps teams define what should be allowed, what should be blocked and where traffic should be inspected or logged.

The Purdue model can also help structure industrial networks by separating enterprise systems, site operations, supervisory systems, control systems and field devices into layers. Many modern sites adapt this model because of cloud services, remote access, IIoT gateways and data platforms, but the principle remains useful: critical control systems should not be directly exposed to higher-risk networks.

Network Segmentation Best Practice Checklist

A successful segmentation project starts with visibility. Before changing firewall rules or VLANs, teams should understand what is connected, which systems communicate and which data flows are required for production.

  • Build an accurate asset inventory across IT and OT systems.
  • Map communication flows between PLCs, HMIs, servers, workstations and external services.
  • Group assets by function, criticality, location and trust level.
  • Define zones for control systems, safety systems, engineering access and remote access.
  • Use firewalls or other boundary devices to control traffic between zones.
  • Apply least privilege so only required protocols, ports and destinations are allowed.
  • Log and monitor traffic at key boundaries.
  • Test changes carefully before applying them to live production systems.

Common Network Segmentation Mistakes

Poorly planned Network Segmentation can create operational issues or false confidence. One common mistake is creating VLANs without enforcing rules between them. Another is allowing broad “any to any” firewall access because a system owner is unsure what traffic is needed.

Industrial sites should also avoid assuming that segmentation is a one-off project. New machines, vendor links, software updates, remote support tools and cloud data projects can all introduce new paths. Rules need review after site expansions, major automation changes or incident response activity.

How Network Segmentation Supports OT Cyber Security

Network Segmentation works best as part of a wider OT cyber security programme. It should be combined with asset visibility, access control, endpoint protection, backup and recovery, removable media controls, version control and incident response planning.

For example, segmentation can help control how engineering workstations access PLC networks. Version control through AMDT Octoplant can help track configuration changes within those environments. TXOne Networks can support OT-native zero trust controls, including segmentation and asset shielding. Wider OT cyber security support can help align these controls with risk, operations and site policy.

Where machine networks, gateways or industrial communication routes are involved, machine communications design should also be considered. Connectivity and security need to work together; otherwise, teams may create data routes that are useful but difficult to control.

Network Segmentation Implementation Steps

Start with a practical assessment rather than a major redesign. Identify critical assets, understand current architecture and confirm which communication paths are essential. From there, prioritise the highest-risk connections, such as direct IT to OT access, uncontrolled remote access, exposed engineering systems and shared networks between production lines.

Once priorities are clear, define a target architecture. This may include separating office IT from OT, adding an OT DMZ, grouping production areas into zones, protecting safety systems more strictly and creating managed remote access routes. Implementation should be staged carefully to reduce disruption and allow production teams to validate behaviour at each step.

Network Segmentation FAQs

What Is Network Segmentation?

Network Segmentation is the process of dividing a network into smaller controlled areas so that traffic can be restricted, monitored and managed more effectively.

Why Is Network Segmentation Important For OT?

It helps reduce the spread of incidents, protect critical systems, control access between zones and support safer operation of industrial environments that may include legacy devices or continuous production requirements.

Is A VLAN Enough For Network Segmentation?

A VLAN can be part of a segmentation design, but it is not always enough on its own. Higher-risk OT environments often need firewalls, strict rule sets, monitoring and documented approval processes.

How Do You Start A Network Segmentation Project?

Begin by identifying assets, mapping data flows and reviewing current access paths. This gives teams the evidence needed to design practical controls that support production as well as security.