---
title: "OT Network Segmentation Explained: Zones, Conduits and the…"
description: "An independent explainer on OT network segmentation: VLANs versus routed separation versus firewalled zones versus physical separation, IEC 62443 zones and…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/ot-network-segmentation#webpage",
      "url": "https://fire-vault.com/learn/ot-network-segmentation",
      "name": "OT Network Segmentation Explained: Zones, Conduits and the…",
      "description": "An independent explainer on OT network segmentation: VLANs versus routed separation versus firewalled zones versus physical separation, IEC 62443 zones and…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-learn.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/ot-network-segmentation#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/ot-network-segmentation#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Home",
          "item": "https://fire-vault.com/"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "OT Network Segmentation: Zones, Conduits and the Industrial DMZ Explained",
          "item": "https://fire-vault.com/learn/ot-network-segmentation"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "OT Network Segmentation Explained: Zones, Conduits and the…",
      "description": "An independent explainer on OT network segmentation: VLANs versus routed separation versus firewalled zones versus physical separation, IEC 62443 zones and…",
      "image": "https://fire-vault.com/images/og/og-base-learn.jpg",
      "author": {
        "@type": "Organization",
        "name": "Firevault"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Firevault",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png"
        }
      },
      "datePublished": "2025-11-18",
      "dateModified": "2026-08-27",
      "mainEntityOfPage": "https://fire-vault.com/learn/ot-network-segmentation"
    },
    {
      "@context": "https://schema.org",
      "@type": "TechArticle",
      "@id": "https://fire-vault.com/learn/ot-network-segmentation#article",
      "headline": "OT Network Segmentation: Zones, Conduits and the Industrial DMZ Explained",
      "description": "An independent explainer on OT network segmentation: VLANs versus routed separation versus firewalled zones versus physical separation, IEC 62443 zones and conduits, the industrial DMZ, data diodes, remote access and how segmentation is verified.",
      "about": [
        {
          "@type": "Thing",
          "name": "OT network segmentation"
        },
        {
          "@type": "Thing",
          "name": "IEC 62443"
        },
        {
          "@type": "Thing",
          "name": "Industrial DMZ"
        },
        {
          "@type": "Thing",
          "name": "Data diode"
        },
        {
          "@type": "Thing",
          "name": "Purdue Model"
        }
      ],
      "keywords": "OT network segmentation, network segmentation OT, IEC 62443 zones and conduits, industrial DMZ, data diode, protocol break, Purdue Model segmentation, OT remote access, management plane segmentation",
      "articleSection": "OT and ICS security",
      "inLanguage": "en-GB",
      "isAccessibleForFree": true,
      "wordCount": 2400,
      "image": [
        "https://fire-vault.com/assets/explainer-ot-network-segmentation-i7cd_hco.jpg"
      ],
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "url": "https://fire-vault.com/about",
        "jobTitle": "Director and Co-Founder, Firevault"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Firevault",
        "url": "https://fire-vault.com"
      },
      "datePublished": "2025-11-18",
      "dateModified": "2026-08-27",
      "url": "https://fire-vault.com/learn/ot-network-segmentation",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/ot-network-segmentation"
      },
      "citation": [
        {
          "@type": "CreativeWork",
          "name": "NIST SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security",
          "url": "https://csrc.nist.gov/pubs/sp/800/82/r3/final"
        },
        {
          "@type": "CreativeWork",
          "name": "ISA/IEC 62443 series",
          "url": "https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards"
        },
        {
          "@type": "CreativeWork",
          "name": "NCSC, Secure Connectivity Principles for Operational Technology",
          "url": "https://www.ncsc.gov.uk/collection/operational-technology"
        },
        {
          "@type": "CreativeWork",
          "name": "CISA, Layering Network Security Through Segmentation",
          "url": "https://www.cisa.gov/resources-tools/resources/layering-network-security-through-segmentation"
        },
        {
          "@type": "CreativeWork",
          "name": "NCSC, Recovering from a Cyber Incident",
          "url": "https://www.ncsc.gov.uk/collection/incident-management"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is OT network segmentation?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "OT network segmentation is the practice of dividing an operational technology estate into groups of assets, then controlling and monitoring every connection allowed between those groups. The goal is to stop a compromise in one part of the estate from spreading to the rest, and to make unusual traffic visible."
          }
        },
        {
          "@type": "Question",
          "name": "Is a VLAN the same as network segmentation?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "A VLAN is one way of implementing logical separation, but it is a weak form of segmentation on its own. VLANs share the same physical switching fabric and can be reconfigured or bridged by a single administrative mistake or a compromised management interface. Routed separation with access control lists, or a firewalled zone boundary, provides stronger enforcement than VLANs alone."
          }
        },
        {
          "@type": "Question",
          "name": "What is the difference between a zone and a conduit in IEC 62443?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "A zone is a group of assets that share a common set of security requirements. A conduit is the explicitly defined and controlled connection between two zones. IEC 62443-3-2 requires organisations to define zones and conduits with a target security level for each, rather than allowing implicit connectivity between systems."
          }
        },
        {
          "@type": "Question",
          "name": "What is the industrial DMZ?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The industrial DMZ, often referred to as Level 3.5 of the Purdue Model, is a dedicated zone that sits between site operations and enterprise IT. It hosts services such as jump hosts, replicated data stores and patch mirrors, so that enterprise systems and OT systems never communicate directly."
          }
        },
        {
          "@type": "Question",
          "name": "Is the industrial DMZ an air gap?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. A DMZ is a mediated, connected architecture with approved network paths, even where those paths are heavily restricted. An air gap is the absence of a network path. The two solve different problems and are not interchangeable terms."
          }
        },
        {
          "@type": "Question",
          "name": "What is a data diode and when is it used?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "A data diode, or unidirectional gateway, is a hardware device that physically allows data to flow in one direction only. It is typically used to publish OT data such as historian readings to an IT system without opening any path back into the OT environment, because the hardware itself cannot pass traffic the other way."
          }
        },
        {
          "@type": "Question",
          "name": "What is a protocol break?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "A protocol break is a point where a connection is terminated on one side and a new connection is established on the other, usually inside a DMZ host, rather than allowing a single session to pass straight through the boundary. It stops attacks that rely on tunnelling or exploiting a protocol across the entire path, because the boundary device fully terminates and re-originates the communication."
          }
        },
        {
          "@type": "Question",
          "name": "How should remote and vendor access be segmented?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Remote and vendor access should terminate in the industrial DMZ, through a jump host or a broker that enforces multi-factor authentication, session recording and time-limited access. Vendors should never be given a direct route into Level 2 or Level 1 systems, and access should be requested, approved and closed for each specific work item."
          }
        },
        {
          "@type": "Question",
          "name": "What is the management plane in OT segmentation?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The management plane is the set of systems used to configure and administer the segmentation controls themselves, such as firewall managers, switch consoles and identity providers. If the management plane is reachable from the same network it is meant to protect, or shares identity with corporate IT, an attacker who reaches it can reconfigure or disable the segmentation without touching a single controller."
          }
        },
        {
          "@type": "Question",
          "name": "How is segmentation verified rather than assumed?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Segmentation is verified through independent testing: reviewing firewall rule sets against the intended zone and conduit design, running authorised traffic tests between zones, checking that monitoring actually captures cross-zone traffic, and confirming that the architecture diagram matches the live configuration. A diagram that has not been checked against the real network is a description, not evidence."
          }
        },
        {
          "@type": "Question",
          "name": "What are the most common OT segmentation failures?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The most common failures are a single flat VLAN behind one perimeter firewall, a shared identity domain between corporate IT and the industrial DMZ, undocumented or forgotten conduits added during a project, and a backup or management platform that is reachable from both sides of a boundary it is supposed to respect."
          }
        },
        {
          "@type": "Question",
          "name": "Does segmentation replace the need for monitoring?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. Segmentation reduces the paths an attacker can use, but every legitimate conduit is still a route that needs monitoring. Effective OT security programmes pair segmentation with monitoring at each boundary, so that unexpected traffic across an approved conduit is detected rather than assumed to be normal."
          }
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

[Knowledge Vault](/learn/knowledge)

Explainer OT and ICS security 

# OT Network Segmentation: Zones, Conduits and the Industrial DMZ Explained

An independent explainer covering how operational technology networks are actually segmented, from VLANs to physical separation, how IEC 62443 zones and conduits work, and why segmentation has to be verified rather than assumed.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

18 November 2025 16 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fot-network-segmentation)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fot-network-segmentation&text=OT%20Network%20Segmentation%3A%20Zones%2C%20Conduits%20and%20the%20Industrial%20DMZ%20Explained%0A%0AAn%20independent%20explainer%20covering%20how%20operational%20technology%20networks%20are%20actually%20segmented%2C%20from%20VLANs%20to%20physical%20separation%2C%20how%20IEC%2062443%20zones%20and%20conduits%20work%2C%20and%20why%20segmentation%20has%20to%20be%20verified%20rather%20than%20assumed.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fot-network-segmentation)[](mailto:?subject=OT%20Network%20Segmentation%3A%20Zones%2C%20Conduits%20and%20the%20Industrial%20DMZ%20Explained&body=An%20independent%20explainer%20covering%20how%20operational%20technology%20networks%20are%20actually%20segmented%2C%20from%20VLANs%20to%20physical%20separation%2C%20how%20IEC%2062443%20zones%20and%20conduits%20work%2C%20and%20why%20segmentation%20has%20to%20be%20verified%20rather%20than%20assumed.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fot-network-segmentation)

![Network switches and patch panels in an industrial control room, representing OT network segmentation](/assets/explainer-ot-network-segmentation-i7cd_hco.jpg)

Segmentation is a set of enforced boundaries between groups of assets, not a single control or a diagram.

Written by

Mark Fermor, Co-Founder, Firevault

Technical review

Firevault architecture team

First published

18 November 2025

Last reviewed

27 August 2026

Review cycle

At least annually, or following material changes to NIST, NCSC or ISO guidance.

How we built this explainer:  This explainer draws on NIST SP 800-82 Rev. 3, the ISA/IEC 62443 series, NCSC UK guidance on operational technology, and CISA advisories on segmentation failures. It describes segmentation patterns neutrally, before a short closing section on how Firevault applies these principles to backup and recovery infrastructure.

**On this page**[What is OT network segmentation?](#what-is)[VLANs, routed separation, firewalled zones and physical separation](#separation-methods)[IEC 62443 zones and conduits](#zones-conduits)[The industrial DMZ](#industrial-dmz)[Data diodes and protocol breaks](#diodes)[Remote and vendor access](#remote-access)[The management plane](#management-plane)[Monitoring across boundaries](#monitoring)[Verified, not assumed](#verification)[Common segmentation failures](#failures)[A practical segmentation checklist](#checklist)[How Firevault applies these principles](#firevault)

On this page

1.  [What is OT network segmentation?](#what-is)
2.  [VLANs, routed separation, firewalled zones and physical separation](#separation-methods)
3.  [IEC 62443 zones and conduits](#zones-conduits)
4.  [The industrial DMZ](#industrial-dmz)
5.  [Data diodes and protocol breaks](#diodes)
6.  [Remote and vendor access](#remote-access)
7.  [The management plane](#management-plane)
8.  [Monitoring across boundaries](#monitoring)
9.  [Verified, not assumed](#verification)
10.  [Common segmentation failures](#failures)
11.  [A practical segmentation checklist](#checklist)
12.  [How Firevault applies these principles](#firevault)

Most operational technology estates already have some form of network segmentation. Very few have verified that it works. Segmentation is often described as a single feature, when it is actually a layered set of design decisions about which assets share a trust boundary, how that boundary is enforced, and how the enforcement itself is protected from tampering.

This explainer sets out how OT network segmentation is actually built, from the weakest and most common pattern to the strongest, how IEC 62443 formalises the idea through zones and conduits, where the industrial DMZ fits, and why segmentation has to be tested rather than assumed to be working.

## What is OT network segmentation?

OT network segmentation is the practice of dividing an operational technology environment into groups of assets, so that a compromise or fault in one group cannot freely reach the rest. Each group is given a defined set of allowed connections to every other group, and everything outside that allowed set is blocked and, ideally, logged.

The purpose in OT is slightly different from IT. In enterprise IT, segmentation is largely about confidentiality and least privilege. In OT, the primary drivers are safety and availability: a compromise that reaches a controller can stop production or, in the worst case, create a physical hazard. Segmentation exists to keep that outcome contained to the smallest possible part of the plant.

## VLANs, routed separation, firewalled zones and physical separation

Not all separation is equal. The four patterns below are commonly used together at different points in an OT architecture, and it matters which one is applied to which boundary.

Weakest

VLANs

-   Logical separation on shared switching fabric
-   Depends on correct trunk and tagging configuration
-   A misconfigured switch port can bridge VLANs

Useful for organising traffic, insufficient alone at a high-value boundary.

Stronger

Routed separation

-   Traffic between zones passes through a router or Layer 3 switch
-   Access control lists restrict source, destination and protocol
-   Still software-defined and reconfigurable by an administrator

Stronger still

Firewalled zones

-   Stateful inspection and logging at the boundary
-   Rule sets can enforce specific protocols and directions
-   Requires the firewall's own management plane to be protected

Strongest

Physical separation

-   No live network interface between the two sides
-   Cannot be bridged by a configuration error
-   Data moves only through a controlled, out-of-band process

The pattern used for a resilience copy that must survive every other control failing.

Four separation patterns, ordered from weakest to strongest enforcement.

In practice, most OT estates use routed separation and firewalled zones for day-to-day boundaries between Purdue levels, and reserve physical separation for the small number of assets, such as a recovery copy, that need to survive a total compromise of the network.

## IEC 62443 zones and conduits

[ISA/IEC 62443](https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards) formalises segmentation through zones and conduits. A zone is a group of assets that share a common set of security requirements and a target security level. A conduit is an explicitly defined and controlled connection between two zones, with a documented source, destination, protocol and enforcement mechanism.

Zone

A group of assets with common security requirements and a shared target security level.

Conduit

An explicitly defined, controlled connection between two zones.

Security level target

The level of protection a zone or conduit is designed to achieve, from SL-1 to SL-4.

Zone boundary

The physical or logical point where a zone's enforcement is applied.

IEC 62443-3-2 covers the risk assessment used to define zones and conduits. IEC 62443-3-3 then sets the technical requirements each zone must meet at its target security level. Purdue levels are the usual starting point for the zone boundaries, but the standard does not require every zone to map one-to-one onto a Purdue level; some estates split a single Purdue level into several zones based on process risk.

A zone without a documented conduit list is not a zone:  If nobody can produce a current list of every conduit into and out of a zone, with its purpose and enforcement, the zone exists on paper only. The list is the control.

## The industrial DMZ

The industrial DMZ, commonly called Level 3.5, is a dedicated zone that sits between site operations and enterprise IT. It is not simply a firewall rule between two VLANs. A properly built industrial DMZ has its own hosts, such as jump servers, patch mirrors and replicated historians, and, critically, its own identity domain rather than sharing the corporate Active Directory forest.

ENTERPRISE

Corporate IT

Identity, applications, email, enterprise services

INDUSTRIAL DMZ

Level 3.5

Jump hosts, patch mirrors, replicated historian, controlled transfer, separate identity domain

SITE OPERATIONS

Levels 0 to 3

Historian, engineering workstations, controllers, the physical process

A typical industrial DMZ separates enterprise IT from site operations with mediated services, not a direct path.

Nothing at Level 3 or below should have a direct route to Level 4 or above. Every legitimate interaction is brokered through a service that lives in the DMZ, which creates a point where authentication, inspection and logging can all happen before traffic reaches either side.

## Data diodes and protocol breaks

Where OT data genuinely needs to reach IT, such as historian data feeding an analytics platform, a unidirectional gateway, often called a data diode, enforces one-way flow at the hardware level. The receiving side gets the data; there is no physical path for anything to travel back into the OT environment. This is standard practice in regulated utilities for specific, well-defined data flows.

A protocol break serves a related but distinct purpose. Instead of a single session tunnelling straight through a boundary, the connection is terminated on one side, inspected or transformed, and a new connection is originated on the other side, usually by a host inside the DMZ. This stops techniques that rely on carrying malicious traffic inside an otherwise permitted protocol across the whole path.

OT side

Historian publishes data

Session terminates at the DMZ host

DMZ

Data inspected and re-packaged

New session originated from the DMZ host

IT side

Analytics platform receives data

No session ever spans the full path

A protocol break terminates and re-originates the connection inside the DMZ, rather than passing a single session straight through.

## Remote and vendor access

Remote and vendor access is one of the most common ways segmentation is quietly undone. Access for maintenance vendors, system integrators and remote engineers should terminate inside the industrial DMZ, through a jump host or access broker, never with a direct route into Level 2 or Level 1 systems.

1.  Request.  Access is requested for a specific piece of work, with a defined scope and time window.
2.  Authenticate.  Multi-factor authentication is required before the session is established.
3.  Broker.  The session is brokered through a jump host in the industrial DMZ, not a direct VPN into the OT LAN.
4.  Record.  The session is recorded and logged, with the identity, duration and systems touched.
5.  Close.  Access is closed at the end of the work item rather than left standing for future convenience.

## The management plane

The management plane is the set of systems used to configure the segmentation controls themselves: firewall managers, switch and router consoles, identity providers and the tools used to administer them. If the management plane sits on the same network it protects, or shares identity with corporate IT, an attacker who compromises it can reconfigure or disable segmentation without touching a single controller.

A common weakness is running the industrial DMZ inside the same Active Directory forest as corporate IT. Once that is the case, a phished domain administrator has authority on both sides of the boundary, and the firewall between them stops being the real security boundary; the identity domain is.

## Monitoring across boundaries

Segmentation reduces the number of paths available to an attacker, but every conduit that remains is still a route, and needs to be watched. Monitoring at each zone boundary is what turns an approved conduit from an assumption into evidence. Unexpected protocols, unexpected volumes or unexpected destinations on an approved conduit are early indicators that the conduit is being misused.

NCSC guidance on OT connectivity treats monitoring and boundary protection as companion controls, not alternatives: the boundary limits what can happen, and the monitoring confirms what actually did.

## Verified, not assumed

A segmentation design is a set of intentions until it has been checked against the live network. Verification means comparing the documented zones and conduits against the actual firewall rule sets and switch configurations, running authorised test traffic between zones to confirm that only the intended paths work, and confirming that monitoring actually captures traffic crossing each boundary.

Assumed segmentation

Network Data 

-   Diagram exists but has not been checked for a year
-   Firewall rule set has drifted from the design
-   No record of when the conduit was last tested

Verified segmentation

Network Data 

-   Rule set reviewed against the documented conduit list
-   Authorised traffic test confirms only intended paths work
-   Monitoring confirmed to capture cross-zone traffic

A conduit that has been tested and logged is evidence. A conduit that only exists on a diagram is an assumption.

An outdated segmentation diagram can be worse than no diagram at all, because it creates false confidence during an incident response, when responders assume a boundary holds that no longer exists in the live configuration.

## Common segmentation failures

### Flat VLANs behind a single firewall

Many industrial estates still run a single flat VLAN for the plant behind one perimeter firewall. Once an attacker gets past that firewall, every controller and historian on the flat network is reachable.

### Shared identity across the DMZ and enterprise IT

Placing the industrial DMZ inside the same identity domain as corporate IT means a compromised domain administrator has authority on both sides, regardless of what the firewall rules say.

### Undocumented conduits added during a project

A temporary rule added to support a commissioning project or a vendor visit is frequently never removed, and rarely appears on the architecture diagram that the security team relies on.

### A backup or management platform reachable from both sides

Running a backup platform as virtual machines on the corporate hypervisor, or as an appliance dual-homed into the corporate LAN, undoes segmentation regardless of how the backup data itself is protected, because the management plane that controls it is reachable from the side the boundary was meant to hold back.

Failure

Why it happens

What closes it

Flat VLAN estate

Segmentation added as an afterthought to an existing flat network

Zone and conduit redesign against Purdue levels

Shared identity domain

Convenience of a single Active Directory forest

Separate identity plane for the industrial DMZ

Undocumented conduits

Temporary rules never reviewed or removed

Scheduled conduit review tied to change management

Dual-homed management systems

Cost or convenience of shared infrastructure

Dedicated infrastructure, physically separated where the asset is critical

Common segmentation failures and the pattern that closes each one.

## A practical segmentation checklist

-   Zones defined against Purdue levels, with a written security level target per zone
-   Every conduit documented with source, destination, protocol and enforcement mechanism
-   Industrial DMZ hosts sit in a dedicated identity domain, not the corporate forest
-   No system at Level 3 or below has a route to Level 4 or above except through the DMZ
-   Unidirectional gateways used for OT to IT flows that only need to publish data
-   Remote and vendor access brokered through a jump host, never a direct route
-   Management plane for segmentation controls kept separate from the networks it protects
-   Cross-zone traffic monitored, not just blocked or allowed
-   Rule sets reviewed against the documented conduit list on a defined cycle
-   Segmentation re-verified after any change to the corporate identity domain

## How Firevault applies these principles

Firevault's role in an OT architecture is deliberately narrow. Offline Secure Storage® provides the copy of recovery data that is expected to survive a total compromise of the network, including a compromise of the segmentation controls described above. It typically sits in or near the industrial DMZ, or in a dedicated bunker, with no live network interface while it is offline.

Firevault Control governs the connection windows used to update or verify that copy, on a management plane that is kept separate from both the corporate identity domain and the OT production network, so that a compromise of either side does not automatically extend to the recovery copy. Every connection, disconnection and access is logged with identity, timestamp and reason, giving segmentation designs the kind of evidence described in the verification section above, for the one asset a segmentation failure elsewhere is not allowed to reach.

Key takeaway 

## Segmentation is a set of enforced boundaries, checked regularly

OT network segmentation is not a single control and it is not a diagram. It is a stack of decisions: which assets belong together in a zone, what is allowed to cross each conduit, how strongly that conduit is enforced, and who can change the enforcement. VLANs, routed separation, firewalled zones and physical separation each provide a different strength of guarantee, and the industrial DMZ only works if it has its own identity plane and its own management.

The organisations that get this right treat their segmentation design as something to test, not something to trust. They verify conduits against the live network, monitor traffic that crosses each boundary, and keep the systems that manage the boundary separate from the systems it is meant to protect.

Questions 

## Frequently Asked Questions

Straight answers on how Offline Secure Storage® behaves in practice.

### What is OT network segmentation?

### Is a VLAN the same as network segmentation?

### What is the difference between a zone and a conduit in IEC 62443?

### What is the industrial DMZ?

### Is the industrial DMZ an air gap?

### What is a data diode and when is it used?

### What is a protocol break?

### How should remote and vendor access be segmented?

### What is the management plane in OT segmentation?

### How is segmentation verified rather than assumed?

### What are the most common OT segmentation failures?

### Does segmentation replace the need for monitoring?

## Sources and further reading

-   [NIST SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security](https://csrc.nist.gov/pubs/sp/800/82/r3/final)
    
    Segmentation architectures for OT, including a Purdue-style DMZ and IEC 62443 zones and conduits as an alternative model.
    
-   [ISA/IEC 62443 series](https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards)
    
    The zones and conduits model, security level targets, and technical requirements for each zone.
    
-   [NCSC, Secure Connectivity Principles for Operational Technology](https://www.ncsc.gov.uk/collection/operational-technology)
    
    UK guidance on OT exposure, centralised connectivity, boundary protection, segmentation and monitoring.
    
-   [CISA, Layering Network Security Through Segmentation](https://www.cisa.gov/resources-tools/resources/layering-network-security-through-segmentation)
    
    US guidance on segmentation architecture and common implementation weaknesses.
    
-   [NCSC, Recovering from a Cyber Incident](https://www.ncsc.gov.uk/collection/incident-management)
    
    The relationship between segmentation, isolation and recovery during an incident.
    

Related Firevault guides

[The Purdue Model for OT/ICS security](/news/the-purdue-model-everything-you-need-to-know) [Purdue Model diagram](/learn/purdue-model-diagram) [Physical air gap for ransomware protection](/learn/physical-air-gap-ransomware-protection) [OT and ICS security air gap storage](/learn/ot-ics-security-air-gap-storage)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

Share this explainer 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fot-network-segmentation)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fot-network-segmentation&text=OT%20Network%20Segmentation%3A%20Zones%2C%20Conduits%20and%20the%20Industrial%20DMZ%20Explained%0A%0AAn%20independent%20explainer%20covering%20how%20operational%20technology%20networks%20are%20actually%20segmented%2C%20from%20VLANs%20to%20physical%20separation%2C%20how%20IEC%2062443%20zones%20and%20conduits%20work%2C%20and%20why%20segmentation%20has%20to%20be%20verified%20rather%20than%20assumed.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fot-network-segmentation)[](mailto:?subject=OT%20Network%20Segmentation%3A%20Zones%2C%20Conduits%20and%20the%20Industrial%20DMZ%20Explained&body=An%20independent%20explainer%20covering%20how%20operational%20technology%20networks%20are%20actually%20segmented%2C%20from%20VLANs%20to%20physical%20separation%2C%20how%20IEC%2062443%20zones%20and%20conduits%20work%2C%20and%20why%20segmentation%20has%20to%20be%20verified%20rather%20than%20assumed.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fot-network-segmentation)

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)