Most OT incidents that reach the physical process — from Triton/TRISIS to Colonial Pipeline — involved an attacker moving laterally from an IT-connected system into the OT environment. Segmentation limits how far that movement can go.
The Purdue Enterprise Reference Architecture defines six levels of an industrial network — from field devices at Level 0 to enterprise IT at Level 4–5. IEC 62443 uses this model as the basis for zone definition.
Segmentation is an engineering project, not a product purchase. Follow the same structured approach you would for a safety lifecycle — assess current state, define the target, implement, then maintain.
CVE alerts, vendor advisories, and ICS security news — curated daily for controls engineers. Under 5 minutes to read.
Get tomorrow's brief free →