Skip to content
CONFIGLANE

OT Security / IT/OT segmentation

IT/OT segmentation.Permitted paths instead of flat networks.

A new VLAN list is not yet OT segmentation. We connect plant function, observed communication, the zone model and technical boundaries in a plan that remains workable for production, maintenance and IT.

Scope of service

What you receive.

This service fits flat production networks, new lines, site changes, regulatory requirements and overly broad access between IT and OT. We do not begin with blocking rules; we begin with functions and dependencies. That exposes which communications support production and maintenance and which persist only through historical convenience.

Zones with an operational rationale

Plant, lines, supporting services, management and boundaries are grouped by function and risk. The model stays readable for plant owners rather than being derived from IP subnets alone.

A dependable communication matrix

Source, destination, service, direction, business purpose and owner are recorded where possible. Observed traffic is an input, but it does not automatically become a permanently permitted rule.

Technical control points

Routing, firewalls, industrial components, access services and monitoring are placed where policy can actually be enforced and operated. Existing platform limitations remain visible.

Migration without a big bang

Pilot zones, temporary rules, logging, fallback and application tests provide a phased path. Every restriction has an operational contact and a testable success criterion.

The delivery path

Three controlled steps.

  1. 01

    Map functions and flows

    Validate plant roles, supporting systems, remote access and observed communication with production and IT stakeholders.

  2. 02

    Design zones and boundaries

    Review the target model, communication matrix, control points and operating processes. Unclear relationships remain explicit decisions.

  3. 03

    Pilot and expand

    Implement one representative zone, verify operational impact and supportability, and extend rules only after acceptance.

What we agree before starting

Segmentation limits the spread of attacks and faults, but it does not replace secure plant configuration, identities, patching or recovery planning. Production approvals and active tests remain with the operator. Hardware, firewall policy, application changes and continuous monitoring are scoped explicitly in the proposal.

Good to know

Your questions. Clear answers.

Is VLAN separation sufficient segmentation?

Not automatically. VLANs create logical areas, but the security effect depends on controlled boundaries, traceable rules and operations that manage change and exceptions. The appropriate control follows the architecture and risk.

How do we handle unknown communication?

We combine observation and operational knowledge, mark unclear flows and prioritise them before blocking. Logging, a pilot and time-limited exceptions can make the transition safer for critical areas.

Can segmentation be introduced during production?

Often in phases, but not without coordination. Control points, changes and tests have to fit the plant. Impact, fallback and approval are agreed with the responsible operational roles for every step.

Let’s discuss your requirements

A few details are enough to begin.

You do not need a finished design. We establish the need, boundaries and a dependable next step.

Plan IT/OT segmentation

Helpful for the first conversation

  • Plant and zone overview with responsible owners
  • Available traffic data and known exceptions
  • IT/OT boundaries, remote access and shared services
  • Permitted tests, windows and fallback requirements

Please do not submit passwords, API keys or confidential network plans through the form.

Explore the technical detail

IEC 62443 and the CRA as an operator capacity issue

Technical background: Cisco Cyber Vision Data Sheet

More OT Security services