Recent Breaches
Breaches
View All →
Network Evolution & Rapid Protection

Physical Network Governance for Operational Technology

Industrial control systems, SCADA networks, and manufacturing processes were built for reliability, not cybersecurity. As IT/OT convergence accelerates, these systems face threats they were never designed to withstand.

Back to Control
Control

Network Evolution & Rapid Protection

If your IT network can reach your OT network, so can an attacker. The only real air gap is a physical one, not a firewall rule, not a VLAN, not a DMZ. Firevault Control enforces physical IT/OT separation at the hardware level.

Zero

IT-to-OT crossover pathways

24/7

Operational continuity maintained

9

Governance modules for OT isolation

Full

IEC 62443 compliance evidence

The Challenge

OT environments are increasingly exposed.

IT/OT Convergence

Shared connectivity between IT and OT networks exposes industrial systems to IT-borne threats.

Legacy Systems

Legacy OT systems lack authentication and encryption, and patching requires downtime.

Configuration Tampering

Attackers alter PLC programs and SCADA configurations with changes that go undetected for weeks.

The Scenario

Scenario: Ransomware Crosses IT into OT

A manufacturing plant's IT network is compromised through a phishing email targeting the finance team. The ransomware spreads laterally across the corporate network within 4 hours. Because the historian server bridges IT and OT, sharing a network path for reporting, the ransomware reaches the OT network by hour 6. PLC configurations are encrypted, SCADA displays go dark, and the plant loses supervisory control of three production lines. Recovery takes 18 days because backup PLC configurations were stored on a network-attached share, also encrypted. With Firevault Control, the Isolate module physically disconnects OT backup data from IT networks. The Transfer module governs any data movement between zones through policy-controlled windows. The ransomware reaches IT but cannot cross a connection that physically does not exist.

"We had a firewall between IT and OT. We thought that was an air gap. When the ransomware jumped across, we realised a firewall rule is just software, and software can be bypassed. We needed physical disconnection."

Module deployment · OT estate

Where each Control module is deployed across the Purdue layers.

Most OT estates still look like a stack: enterprise on top, an industrial DMZ in the middle, process control and supervisory layers below it, and safety at the bottom. Control puts a physical boundary at every step so a problem at one layer does not propagate to the next.

Grounded in ISA-95 / Purdue, IEC 62443-3-3 and NIST SP 800-82 Rev. 3.

L5

Internet / Cloud

External

Cloud services
FirebreakValidate

External traffic terminates in the perimeter.

L4

Enterprise

IT

ERP
Email
SOC / SIEM

Business systems. Not part of the process.

Business systems. Not part of the process.

IsolateFirebreak

Enterprise cannot reach the DMZ on its own terms.

L3.5

Industrial DMZ

DMZ · trust boundary

Jump server
Patch & AV
Data broker

All IT/OT traffic terminates here.

All IT/OT traffic terminates here.

RelayValidateTransfer

Data moves through the DMZ on controlled routes only.

L3

Operations

OT

Historian
MES
Engineering
Isolate

Engineering and SCADA on separate fabrics.

L2

Supervisory

OT

SCADA
HMI
Execute

Control actions need approval.

L1

Basic control

Field

PLCs
DCS
RTUs
IsolateLock

Safety is reachable by named operators only.

SIS

Safety systems

Field

Safety PLC
ESD

Safety integrity. Last line.

Safety integrity. Last line.

Lock

Field assets named.

L0

Physical

Field

Sensors
Actuators
OSS

Crown jewels

Off-network

Detail callout · A

Offline Secure Storage

PLC programs, DCS baselines, SIS logic, recipes and the records to rebuild from after an incident.

Offline by design · secure by default

Modules & symbols

FirebreakPhysical sever
ValidateIntegrity check
IsolateZone boundary
RelayTime-bound path
TransferControlled move
ExecuteApproved action
LockNamed access
DMZ boundaryTrust transition
OSS calloutOff-network detail

Where each module is deployed, and what it does there.

One row per module. Placement on the network, then plain-English purpose at that point.

  1. Isolate

    At every Purdue boundary

    Each layer sits on its own physical fabric. A compromise in enterprise cannot walk into process control or safety on the strength of a misconfigured rule.

  2. Firebreak

    On the L5 to L4 link and the L4 to L3.5 link

    Firebreak gives the OT team a real hardware off switch on the IT boundary, so a compromise in enterprise cannot ride a live cable into process control.

  3. Relay

    Inside the L3.5 DMZ

    Data moves from enterprise into OT through scheduled, defined routes. Nothing streams unattended.

  4. Validate

    Inside the L3.5 DMZ

    Before anything reaches process control, Validate checks its origin, integrity and authority.

  5. Transfer

    Inside the L3.5 DMZ

    When data has to move across the boundary, Transfer governs how it crosses and where it lands.

  6. Execute

    On the L2 to L1 link

    Pushing a change to a controller holds until the right approval is in place.

  7. Lock

    On the L1 to SIS link and the SIS to L0 link

    Safety is the last layer anything reaches. Lock ties that boundary to named operators with the right engineering authority.

Featured In

TechRadar ProSecurity BuyerYahoo FinanceSecurityBriefChannel Insider

Key Capabilities

PLC & SCADA Config Protection

Golden copies of PLC programs, SCADA configurations, and HMI settings stored in hardware-encrypted offline vaults, immune to network-based attacks.

Historian Backup

Process historian data protected in physically disconnected storage, ensuring operational records survive ransomware and are available for safety investigations.

Controlled Maintenance Windows

Time-bound access windows for firmware updates and configuration changes, physical paths open only during authorised periods with full audit trails.

IEC 62443 Evidence

Automated compliance logging maps to IEC 62443 zone and conduit requirements, demonstrable physical separation, not just logical segmentation.

Zero-Downtime Deployment

Deploys alongside existing OT infrastructure without requiring changes to PLCs, SCADA systems, or network architecture, no production disruption.

Demo to Live

Adoption Guide

Step 1

OT Environment Audit

Map all IT/OT boundaries, shared network paths, historian connections, and remote access points to identify where physical separation is required.

Step 2

Zone and Conduit Design

Align Control modules to IEC 62443 security zones and conduits, designing physical separation that maps directly to your compliance requirements.

Step 3

Non-Disruptive Pilot

Deploy alongside existing PLCs, SCADA systems, and RTUs without any changes to operational equipment, zero production downtime during validation.

Step 4

Production Go-Live

Activate controlled maintenance windows, historian backup replication, and immutable audit trails across your entire OT environment.

Step 1

OT Environment Audit

Map all IT/OT boundaries, shared network paths, historian connections, and remote access points to identify where physical separation is required.

Step 2

Zone and Conduit Design

Align Control modules to IEC 62443 security zones and conduits, designing physical separation that maps directly to your compliance requirements.

Step 3

Non-Disruptive Pilot

Deploy alongside existing PLCs, SCADA systems, and RTUs without any changes to operational equipment, zero production downtime during validation.

Step 4

Production Go-Live

Activate controlled maintenance windows, historian backup replication, and immutable audit trails across your entire OT environment.

Questions

Frequently Asked

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy

    Ot Environments

    Control platform capabilities for operational technology environments. Physical isolation protecting SCADA, ICS, and industrial systems.

    © 2026 Firevault Limited. Disconnect to Protect®