The levels
- Level 0, the process: sensors, actuators, valves, drives. The physical plant.
- Level 1, basic control: PLCs, RTUs, safety controllers. The devices that read level 0 and act on it.
- Level 2, supervisory control: HMIs, SCADA servers, alarm servers. Where operators see and steer the process.
- Level 3, site operations: historians, engineering workstations, domain controllers for the OT, manufacturing execution. The systems that manage the site but do not touch the process directly.
- Level 3.5, the industrial DMZ: the buffer between plant and enterprise. Nothing crosses from level 4 to level 3 directly; it lands here first.
- Levels 4 and 5, the enterprise: business systems, email, the internet.
Where the boundary really is
The model says the boundary is the DMZ. In real plants it is wherever the last firewall rule allows. The corporate domain that authenticates OT users, the historian replicated to the cloud, the vendor VPN that terminates on an engineering workstation, the shared laptop that moves between office and switchroom: each one is a conduit that bypasses the diagram.
A segmentation assessment starts by finding those conduits. Passive monitoring shows which flows actually cross the boundary; a configuration review of the firewalls and switches shows which are permitted. The difference between the two is the work.
Segmenting a plant that was never designed for it
- Start with the zone model: group assets by function and consequence, and set a target security level for each zone. IEC 62443-3-2 is the method.
- Build the DMZ first if there is none. Historian replication, remote access and patch distribution all move into it. This single change removes most direct paths from the enterprise to the controllers.
- Fix remote access next: a jump host in the DMZ, named accounts, multi-factor authentication, session recording, and vendor access enabled only for the window it is needed.
- Then segment inside the plant, one conduit at a time, in outage windows, with the operations team confirming each change. Safety systems get their own zone and, where the consequence justifies it, a unidirectional gateway.
- Monitor the conduits. A segmentation that is not observed drifts back to flat within a year.
Regulators use the same picture
Australia's CIRMP frameworks and the Essential Eight expect network segmentation as a basic control. India's CEA power sector regulations require OT to be isolated from IT and the internet and segmented into trust levels, with IT-to-OT flows through a unidirectional gateway. IEC 62443's zones and conduits are the common vocabulary for all of them.
- IEC 62443-3-2
- NIST SP 800-82 Rev 3, section on network architecture
- CEA (Cyber Security in Power Sector) Regulations, 2026, Chapter IV





