Segmenting an OT network helps limit communications between different industrial environments and reduces the potential spread of an attack.
On paper, the principle seems straightforward. In the field, it is a different story.
Existing industrial environments often include several generations of equipment, architectures that have evolved through successive projects, and communication flows whose purpose is no longer fully documented.
Before changing the network architecture, one question should therefore be asked: Do you really know what is happening on your OT network?
7 steps for OT network segmentation
1. Start by understanding your OT environment
It is impossible to segment a network properly if you do not know what it contains.
The first step is to create an inventory of the equipment present in the environment:
PLCs and control systems
SCADA and HMI systems
Industrial servers
Engineering and maintenance workstations
Network equipment
Monitoring and historian systems
Connections to the IT network
Remote access connections
This mapping must go beyond a simple list of assets. You also need to understand how these assets are connected to one another.
A network diagram can provide an initial overview of the architecture. However, it does not necessarily show which communications are actually taking place.
2. Identify the communication flows between assets
This is one of the most important steps before implementing segmentation.
For each communication, you should be able to answer a few questions:
Which asset is communicating with which other asset?
Which protocol is being used?
Why is this communication necessary?
How often does it occur?
Is it essential to production?
What would happen if it were blocked?
This analysis helps distinguish necessary communications from flows that no longer have a clear operational justification. It can also reveal dependencies that are not always visible in the theoretical network architecture.
3. Define consistent network zones
Once the assets and communication flows have been identified, you can start considering how to organise the network.
The aim is not necessarily to isolate every individual asset. Instead, systems with similar characteristics or security requirements should be grouped together.
For example, the architecture could distinguish between:
IT network → Industrial DMZ → Supervisory network → Production zones or cells
This approach can be structured around the principles of the ISA/IEC 62443 standard, particularly the concepts of zones and conduits. However, segmentation must always take the actual architecture of the installation and its operational constraints into account.
4. Determine which communications should be allowed
Once the zones have been defined, the next step is to determine what can be exchanged between them.
A communication should not automatically be considered legitimate simply because it already exists.
For each flow, you should be able to justify:
Its source
Its destination
Its protocol
Its purpose
Its level of criticality
Filtering rules can then be defined accordingly, particularly at the level of industrial firewalls.
This makes it possible to move from segmentation based on the network structure to segmentation based on actual communication requirements.
5. Consider IT/OT connections and remote access
Segmentation does not only concern equipment located on the shop floor.
Connections between IT and OT networks must also be analysed, as well as access used by maintenance teams, system integrators and suppliers.
For each access point, it is useful to determine:
Who can connect?
From which environment?
To which assets?
With which permissions?
Under which conditions?
A remote connection required for maintenance can represent a significant security weakness if it is not properly controlled.
6. Deploy segmentation progressively
In an industrial environment, changing the network architecture involves one essential constraint: Production must continue to operate.
A complete segmentation strategy does not necessarily have to be deployed all at once.
A progressive approach makes it possible to:
Map the environment
Analyse communication flows
Define network zones
Identify priorities
Test changes within a controlled scope
Gradually deploy segmentation rules
Check their impact on operations
This approach also allows you to start with the environments or flows presenting the most significant risks.
7. Keep your network view up to date
Segmentation is not a project that can be considered complete once the filtering rules have been implemented.
A new PLC, a production line modification, the installation of new software or the opening of a new remote access connection can change the communications that are required.
Documentation and network mapping must therefore evolve alongside the industrial environment.
Effective segmentation relies on regularly updated knowledge of assets, connections and communication flows.
Visibility as the starting point
Before deciding which communications to allow, block or isolate, you need a sufficiently accurate view of your OT environment.
This is where visibility becomes a genuine cybersecurity concern.
Octovision, the platform developed by our partner AMDT, helps centralise and contextualise information from the OT environment to provide a more complete view of assets, connections and available data.
This visibility can provide a basis for analysing the environment and identifying the security actions that should be prioritised.
Segmentation starts with a simple question: do you know what is really communicating on your OT network?
As an industrial systems integrator, B2C Engineering helps you secure your industrial systems by offering solutions tailored to your IT/OT environment.
Evaluate your needs with our experts
We support you in structuring, securing, and managing your industrial cybersecurity.
Together, we assess your needs and plan a demonstration of the solution.
