OT and critical systems

OT Network Segmentation and Physical Isolation: A Practical Architecture Guide

Plan layered OT network zones, conduits and physically isolated access paths while preserving safety, availability and maintainability.

External network Potentially exposed
AIRGAPNET physical network isolation device Ethernet path disconnected by default
Protected system Connected when authorised

Operational technology networks control physical processes, so cybersecurity decisions must respect safety, reliability, deterministic behaviour and long equipment lifecycles. A segmentation design that looks elegant on an office network may interrupt production, create unsafe states or depend on features that legacy controllers cannot support.

A practical OT architecture uses zones for assets with similar trust and operational requirements, tightly governed conduits between those zones, and physical isolation at selected boundaries where connectivity is exceptional. The objective is not to disconnect everything. It is to make every connection intentional, limited and supportable by the people operating the facility.

Key takeaways

The short version

  • OT security architecture must begin with process safety and availability requirements.
  • Zones and conduits reduce broad reachability while preserving required industrial communication.
  • Physical isolation is best reserved for high-consequence paths with infrequent connectivity needs.
  • Temporary connections require the same inspection, identity and monitoring controls as permanent ones.

Build the architecture from process knowledge

Start with an inventory of controllers, operator stations, historians, engineering workstations, safety systems, remote-access gateways and supporting services. Record protocols, communication direction, timing, vendor dependencies and the consequence of delay or loss. Passive discovery can help, but asset owners and control engineers must validate the result.

NIST SP 800-82 emphasises the unique performance, reliability and safety requirements of OT. Those requirements should drive boundaries. A safety instrumented system, a production cell and a corporate reporting service may all handle related data, but they should not automatically share the same trust zone.

Define zones and narrow conduits

Group assets by function, criticality and security capability. Then document the minimum communication needed between groups. Industrial firewalls, routing policy, application proxies and unidirectional gateways can enforce these conduits. Default-deny rules are useful only when operations know which flows are genuinely required.

Avoid a single flat OT network or a broad connection from the corporate environment. Place services that exchange data across trust levels in an industrial DMZ where possible. Protect management interfaces and ensure that changes to network policy follow the same operational discipline as changes to control logic.

Choose physical boundaries selectively

Physical isolation can add value where a zone needs no routine inbound connection or where maintenance occurs only at planned times. Candidate paths include access to dormant production lines, engineering interfaces, recovery systems and legacy cells that cannot host modern endpoint controls.

Do not place a physical break into a safety-critical communication path without a full engineering assessment. The default and failure states must be understood, and authorised access must not interfere with process timing. AIRGAPNET is intended for Ethernet paths that can be unavailable by default; suitability depends on the protocol, topology and operating process.

Design the operating procedure

A secure architecture includes people and timing. Define who requests a connection, who approves it, how the maintenance endpoint is checked, what traffic is allowed and who confirms closure. Use change windows and work permits already familiar to the facility rather than creating a parallel process that operators are likely to ignore.

Collect logs from boundary controls and systems on both sides. Where continuous monitoring cannot cross the boundary, plan an appropriate export method. The monitoring design should not silently recreate the broad bidirectional path that isolation was meant to remove.

Maintain the architecture through change

OT environments evolve through vendor updates, line expansions and temporary projects. Review zone diagrams, allowed flows and physical paths after each change. Temporary remote-access solutions deserve particular attention because they often outlive the maintenance event that justified them.

Test boundary failure modes during planned exercises. Verify that operators can identify the physical connection state, safely restore the intended configuration and continue essential processes when the control or authorisation channel is unavailable.

Use a staged deployment sequence

Begin in monitoring mode where possible: confirm the proposed boundary, capture required traffic and remove obsolete routes before introducing physical enforcement. Next, test the disconnected state during an approved outage or maintenance period. Only then automate connection windows for repeatable tasks.

Prepare rollback criteria before each stage. The team should know which symptoms require restoration of the previous topology and who can make that decision. Keep spare hardware and current configurations appropriate to the site's availability needs. A staged approach gives operators evidence that the new boundary supports production rather than competing with it.

After rollout, include the boundary in maintenance schedules and site acceptance tests. Contractors and new operators should receive the same state-verification procedure so the design does not depend on knowledge held by one engineer.

Decision checklist

Questions to resolve before implementation

  1. Validate the asset and communication inventory with control engineers.
  2. Group assets by process function, consequence and security capability.
  3. Document minimum flows through every conduit and deny unnecessary traffic.
  4. Reserve physical isolation for paths that can safely be unavailable.
  5. Integrate access approval with maintenance and change-control procedures.
  6. Review diagrams, rules and temporary connections after each plant change.

Common questions

Questions teams ask first

Should an OT network be completely air-gapped?

Not automatically. Many OT environments require reporting, maintenance and coordination with business systems. The architecture should preserve required operations while reducing unnecessary paths, using physical isolation only where the process can support it.

Can physical isolation replace an industrial DMZ?

No. An industrial DMZ supports controlled ongoing exchange between trust levels. Physical isolation is appropriate for a different pattern: no continuous path or a deliberately limited connection window.

What is the most important first step?

Understand the physical process and its communication dependencies. Implementing boundaries without an accurate, operations-validated inventory can create outages or encourage unsafe workarounds.

Official references

Further reading

Apply the principle

Review one critical network path.

Start with a system that is continuously reachable but only occasionally needs the connection.

Request a consultation