A practical guide to OT network segmentation—using security zones, controlled communications and industrial DMZs to reduce unnecessary exposure in operational environments.
Published: 17 August 2026 | Last reviewed: 9 September 2026 | 10 min read
OT network segmentation separates systems with different security needs and controls the communications between them.
Rather than allowing broad access across an operational environment, segmentation creates defined boundaries between corporate IT, OT operations, engineering systems, safety systems, remote access and external connections.
Done well, segmentation reduces unnecessary exposure while preserving the communications needed to operate and maintain the environment safely.
Industrial environments often develop over time. New systems, vendor connections, remote-access arrangements and data integrations are added as operational needs change.
Without clear boundaries, these connections can create broad pathways between corporate IT, operational systems and external parties. A cyber incident affecting one part of the environment may then be able to move further than intended.
This does not mean every connection is unsafe. Industrial systems need to exchange information, support engineering work and allow approved maintenance. The challenge is to ensure each connection has a clear purpose, appropriate controls and documented ownership.
OT network segmentation is the process of grouping systems into distinct security zones and controlling the communications between those zones.
The aim is not simply to add more firewalls. It is to create boundaries that reflect operational function, criticality and risk. A control network, engineering workstation, historian, remote-access environment and safety system may each need different levels of protection.
Segmentation helps organisations move away from flat networks and overly broad access. It makes it easier to understand what is connected, why it is connected and what controls are needed to protect the connection.
A zone is a group of systems with similar security requirements. A conduit is the controlled communication path between zones.
Zones are not defined only by where equipment is located. They should reflect operational function, consequence of compromise, system dependencies and the level of protection required. For example, engineering workstations, control systems, remote-access services and safety-related systems may need to sit in separate zones because they carry different operational and cyber risks.
A conduit defines how those zones are allowed to communicate. It should identify which systems can connect, which protocols and services are permitted, and what controls protect the connection. This may include firewall rules, authentication, network monitoring, approval processes and documented access responsibilities.
The goal is not to prevent every connection. It is to allow the communications needed for safe, reliable operations while limiting unnecessary access and reducing the opportunity for an incident to move between environments.
IEC 62443 provides the zones and conduits model commonly used to structure OT network segmentation.
An industrial DMZ provides a controlled boundary between corporate IT, external services and operational technology.
It can support approved data exchange, remote-access gateways, jump hosts, security monitoring and other services that need to operate across IT and OT boundaries.
A DMZ is not simply another network segment. Its value comes from defining what is allowed to pass through it, how that communication is protected and who is responsible for managing it.
Every OT environment is different. Segmentation should reflect operational function, consequence of compromise, system dependencies and the protocols in use.
This simplified example shows how common systems can be separated into distinct security zones, with controlled pathways between them.
Business systems, enterprise users and corporate services
Approved, time-bound access with MFA and logging
Approved data exchange, jump host and access gateway
Engineering workstations, SCADA and control services
Safety-related systems with the highest protection requirements
Each connection should have a clear purpose, appropriate controls and documented ownership. In practice, this includes defining the permitted protocols and services between zones.
A practical segmentation program starts by understanding the operational environment before making changes to it.
There is no single segmentation design that suits every industrial environment. The objective is to make deliberate, risk-based decisions that reduce unnecessary exposure without disrupting safe and reliable operations.
Effective segmentation is about deliberate design and ongoing management. These common issues can weaken otherwise well-intended security architecture.
Broad access can allow an incident to move further than it should.
Third parties should use approved, controlled access paths rather than connect directly into control environments.
A DMZ only adds value when permitted services, access paths and ownership are clear.
Security controls must support maintenance, engineering workflows and safe recovery.
Implicit OT helps organisations understand their operational networks, define practical security boundaries and strengthen OT architecture without losing sight of safe, reliable delivery.