Service 02
Architecture and segmentation
Zone and conduit design over the Purdue model to separate IT and OT without exposing the industrial process.
- Problem
- IT/OT convergence connects networks designed under incompatible assumptions: IT prioritizes confidentiality and fast patching, OT prioritizes availability and determinism. Without an explicit network architecture, that convergence gets resolved with ad hoc firewall rules that grow without a model, until no one can explain why a given route is open.
- Scope
- Segmentation design into zones and conduits following the standard's reference model (security zones, conduits between them, and target security levels per zone, terminology from IEC 62443-3-2, Security risk assessment and system design), applied over the Purdue model of industrial automation levels. Includes the industrial DMZ between IT and OT, and the conduit rules that document what traffic crosses each boundary and why.
- Deliverables
- Diagram of zones, conduits and target security levels (SL-T) per zone
- Industrial DMZ specification and conduit rules between IT and OT
- Phased segmentation roadmap, for plants that can't apply the whole change at once
- Fit
- It fits when an audit (in-house or third-party) already identified insufficient segmentation and the concrete design is what's missing, or when an IT/OT convergence project needs a reference architecture before touching the plant network. If that diagnosis doesn't exist yet, the IEC 62443 audit is the natural previous step.
Why zones and conduits, not a flat network
An unsegmented industrial network treats a field sensor and a historian server under the same trust perimeter as an engineering workstation. The zone and conduit model from IEC 62443-3-2 starts from the opposite premise: each zone groups assets with comparable security requirements, and every conduit crossing it is explicitly documented — which protocol, in which direction, with what justification.
How the Purdue model is applied
The design relies on the Purdue model levels (field process, basic control, supervision, plant operations, and the boundary with corporate IT) to place each zone at its corresponding level and define where the industrial DMZ lives: the strip where IT and OT exchange strictly necessary data (historians, MES) without a direct route connecting the corporate network to the plant floor.
What this service produces
- A diagram of zones and conduits that any plant engineer can audit visually, not a table of firewall rules without context.
- A target security level (SL-T) per zone, consistent with what that zone can afford to lose if it fails: not every zone needs the same level.
- A phased rollout sequence: segmenting a plant already in production all at once isn’t viable — the design includes the order that minimizes the risk window at each phase.