Resource
OT/IT Network Segmentation for Manufacturers
OT/IT network segmentation is an enforced boundary between your office network and your production systems, so a compromise on one side can't reach the other. It's how a manufacturer keeps an email-borne ransomware infection from stopping the production floor.
Many smaller plants run on a flat network, where office computers and production equipment share the same network with no real boundary. That's rarely a deliberate choice. It's how the network grew: a connection added here, a remote access tool there, without anyone asking what happens if one side is compromised.
Why the boundary matters
The Colonial Pipeline attack in 2021 is the example most people know. Ransomware hit the company's business systems, not the pipeline controls, yet the company shut the pipeline down as a precaution. When there's no clear boundary between business and operational systems, it's hard to say with confidence that production is safe, and shutting down becomes the cautious choice.
A segmented network gives you a third option beyond "shut everything down" or "keep running and hope": contain the incident on the office side while production keeps running.
What segmentation does (and doesn't) require
It doesn't require replacing your equipment. Segmentation works at the network level, so older PLCs, HMIs, and machine controllers keep running exactly as they do today. Only the network paths around them change. That matters for plants running equipment that would be expensive or impossible to replace.
It isn't a cure-all either. Segmentation limits how far an attack can spread, and it works best alongside the foundational controls: MFA, patching, tested backups, and monitoring.
How a segmentation project works
- Map what's connected. Most flat networks have grown enough that nobody has a complete picture. This step alone usually turns up surprises.
- Define zones. Office, production, and anything in between, such as engineering workstations or a quality system that needs data from the floor.
- Control the paths between them. Firewalls and managed switches allow only the traffic that needs to cross, and nothing else.
- Lock down remote access. Vendor and technician access to production equipment goes through a controlled, logged path with MFA, not an always-on remote tool.
- Monitor and test. Confirm the boundary holds, and keep watching the traffic that crosses it.
Cost and timeline depend on the size of the facility, the state of the existing network, and how much production equipment is connected. The mapping step is what makes both predictable.
What insurers and customers are asking
Cyber insurance applications for manufacturers increasingly ask whether office and production networks are separated, and larger customers are starting to ask their suppliers the same question. Having segmentation in place, and documented, gives you a clear answer.
Common questions
Questions leadership usually asks first.
Continue reading
Related work and reading.
IT for Manufacturers
How we manage office and plant floor IT as one environment.
Read more: IT for ManufacturersCyber Insurance for Manufacturers
What carriers ask manufacturers about segmentation and vendor access.
Read more: Cyber Insurance for Manufacturers2027 Readiness for Manufacturing
Planning ahead for the plant and the office.
Read more: 2027 Readiness for ManufacturingCIS Controls vs NIST CSF
The foundational controls segmentation works alongside.
Read more: CIS Controls vs NIST CSFNext step
Not sure how your plant network is set up today?
Schedule an IT Environment Review.
