The problem
Many industrial networks are flat because that is how they grew: first a cable connected the ERP and SCADA to extract production data, then an integrator was given access, then another. Today, ransomware entering through corporate email may have a direct path to the HMIs. This is not hypothetical: it is the pattern repeated in most published industrial incidents.
Segmentation projects almost always fail for the same reason: someone buys a firewall and nobody knows which rules to write because nobody knows which flows are legitimate. Everything is then allowed “temporarily”, and the firewall becomes an expensive ornament.
Scope
- Target architecture design using zones and conduits in accordance with IEC 62443-3-2.
- An industrial DMZ for IT/OT exchanges: historians, files and remote maintenance.
- Vendor-neutral technology selection: industrial NGFW and, where appropriate, a data diode.
- Rules built from observed actual traffic, not assumptions.
- Controlled remote access: a single entry point, MFA, session recording and expiry.
- A phased migration plan, each phase with defined testing and rollback, within your existing windows.
Deliverables
- Documented architecture: target network diagrams and diagrams for each intermediate phase.
- A matrix of legitimate inter-zone flows, validated with operations.
- Implemented and verified rules, with written justification.
- A firewall operating procedure: how changes are requested and who approves them.
- Architecture evidence ready for NIS2, IEC 62443 or ENS audits.
Questions we are asked before engagement
How many production shutdowns does the project require?
The plan is designed around your existing maintenance windows. In most cases no dedicated shutdown is needed; if any phase requires one, you will know before signing, not halfway through the project.
Which firewall vendor do you work with?
We work with the leading industrial NGFWs on the market, without exclusivity. The choice is justified by technical requirements and operating cost, and the final decision is yours.
What happens to access for our integrators and manufacturers?
It is controlled, not cut off. Each third party uses a single entry point with MFA, permissions limited to its equipment, recorded sessions and expiring access. Integrators generally welcome this because it protects them too.