← Resources·Network Security Guide

OT network segmentation: zones, conduits, and the Purdue model

Network segmentation is the single most effective control you can apply to an OT environment. This guide covers the Purdue Reference Model, IEC 62443 zones and conduits, and the practical steps to segment a real industrial network.

12 min read
·
For controls and OT engineers
·
Free account
Why it matters

What segmentation actually prevents

Most OT incidents that reach the physical process — from Triton/TRISIS to Colonial Pipeline — involved an attacker moving laterally from an IT-connected system into the OT environment. Segmentation limits how far that movement can go.

Threat
Ransomware spreading from IT
How segmentation helps
A properly enforced DMZ stops ransomware that enters via IT email or VPN from reaching OT systems. Without segmentation, a single infected laptop can pivot to your DCS.
Threat
Unauthorised remote access
How segmentation helps
Segmentation forces all remote access through a controlled jump server in the DMZ — every session is logged, authenticated, and limited to specific systems.
Threat
Lateral movement after initial compromise
How segmentation helps
Zone boundaries limit how far an attacker can move. Compromising one HMI doesn't automatically give access to PLCs in a different zone if conduit rules are enforced.
Threat
Unpatched devices exposed to broad network
How segmentation helps
OT devices that can't be patched — end-of-life PLCs, legacy HMIs — can be placed in a more isolated zone with tighter conduit rules, reducing their exposure without replacing them.
Free account required
Keep reading with a free account

The rest of this guide is free — it just needs an account. Signing up also gets you the daily OT brief: curated OT security news, standards changes, and vendor advisories, every morning.

Create free accountSign in
Related guides
Guide
OT Cybersecurity for Controls Engineers
How functional safety concepts map directly to OT cyber
Guide
IEC 62443 Explained
The industrial cybersecurity standard — plain English