Industrial security education

Purdue Model and ISA/IEC 62443 zones and conduits explained

A practical guide for business, engineering, IT and OT stakeholders who need a clearer way to discuss industrial segmentation, trust boundaries, remote access and control system risk.

Public educational guide Updated June 2026 No vendor affiliation

Why this matters

Industrial networks often evolve over many years. New data flows, remote support paths, monitoring tools and corporate services can slowly weaken the intended separation between business IT and operational technology.

SegmentationRemote accessFirewall governanceOT resilience
Business risk

Cyber events can become operational events

In industrial environments, cyber risk is not only about data loss. It can affect production availability, operator confidence, safety-related processes, product quality and recovery capability.

Architecture risk

Connectivity must be justified

The issue is rarely whether two systems can communicate. The real question is whether the communication is required, governed, monitored and constrained to the minimum operational need.

Governance risk

Diagrams are not control evidence

A network diagram is useful, but it does not prove the environment is secure. Evidence is needed for actual routes, firewall rules, accounts, remote paths, ownership and change control.

Important context

The Purdue Model is a useful reference model, not a complete security architecture. ISA/IEC 62443 adds a risk-based way to think about zones, conduits, target security levels, lifecycle governance and control requirements. Neither should be applied as a generic template without site context.

Leadership

Frame risk clearly

Use the model to understand why industrial cyber risk needs operational context, defined ownership and a prioritised improvement roadmap.

Engineering and OT

Protect operations practically

Use the zones and conduits language to discuss required data flows, safe remote access, production constraints and change windows.

Cyber, IT and risk

Evidence control maturity

Use the review questions to test whether architecture, firewall rules, access pathways and governance evidence support defensible decisions.

Layered reference model, mapped to security intent

Select any Purdue layer to view a practical ISA/ISA/IEC 62443-aligned interpretation. The mapping is illustrative. A real environment should define zones and conduits based on risk, ownership, asset criticality, operational constraints and required data flows.

Purdue levelsSecurity zonesControlled conduitsRisk-based SL-T
Purdue reference stack with ISA/IEC 62443 overlay
Illustrative education model. Not a universal compliance mapping.
Interactive model
5External
External, vendor and cloud access

Internet services, supplier connectivity, remote support entry points, cloud platforms and externally managed services.

External connectivity zoneDo not treat as trusted OT access.
SL-T
Risk based
Conduit:Remote access, ZTNA, VPN, PAM, jump access, identity federation and logging.
4Enterprise
Enterprise IT and business systems

Corporate identity, email, ERP, service desk, SIEM, endpoint management, user workstations and standard IT operations.

Enterprise zoneBusiness IT risk domain.
SL-T
Risk based
Conduit:Brokered enterprise-to-industrial flows through controlled services. Avoid direct L4 to L2 or L1 paths.
3.5IDMZ
Industrial demilitarised zone

Segregated intermediary layer for replicated historians, jump hosts, update brokers, file transfer, proxies and monitored data exchange.

Industrial DMZ zonePrimary controlled boundary.
SL-T
Risk based
Conduit:Explicitly permitted application flows, monitored sessions, limited protocols and owned firewall rules.
3Operations
Site operations and manufacturing systems

MES, production scheduling, OT domain services, local historians, maintenance services, site applications and operational reporting.

Site operations zoneIndustrial operations support.
SL-T
Risk based
Conduit:Strictly required traffic between operations services and supervisory control assets.
2Supervisory
Supervisory control

SCADA servers, HMI stations, operator workstations, engineering workstations, alarm systems and control room services.

Supervisory control zoneHigh operational impact.
SL-T
Risk based
Conduit:Protocol-aware, least privilege and change-controlled pathways to controllers.
1Control
Basic control and intelligent devices

PLCs, RTUs, safety controllers, drives, relays, robotic controllers, process controllers and embedded control devices.

Basic control zoneIntegrity and availability critical.
SL-T
Risk based
Conduit:Controller to process interactions, engineering access and safety-sensitive communication paths.
0Process
Physical process

Sensors, actuators, valves, motors, pumps, conveyors, instrumentation, physical equipment and production process behaviour.

Physical process contextCyber controls apply through connected systems.
SL-T
Context led

Where ISA/IEC 62443 fits

ISA/IEC 62443 helps convert a high-level architecture conversation into a risk-based control model for industrial automation and control systems. The key concepts for this page are zones, conduits, target security levels and foundational requirements.

Zones

A zone is a grouping of systems with similar security requirements. In practice, zones should consider function, ownership, criticality, trust level, technology constraints and consequence of compromise.

Conduits

A conduit is a governed communication path between zones. A useful conduit should have a clear business purpose, permitted protocols, defined source and destination, ownership, monitoring and review cadence.

Target security levels

Security level targets should be set through risk assessment. Higher consequence zones and conduits may need stronger authentication, integrity, restricted data flow, monitoring and availability controls.

Lifecycle governance

Security design is not a one-off activity. Access rules, exceptions, vendor pathways, change records, monitoring coverage and resilience assumptions need ongoing governance and evidence.

IEC 62443 foundational requirement themes

Seven control themes to use when reviewing industrial architecture

These themes help explain why segmentation alone is not enough. They connect network design to identity, use control, integrity, confidentiality, restricted data flow, event response and resource availability.

FR1 IACIdentification and authentication control.
FR2 UCUse control and authorisation.
FR3 SISystem integrity.
FR4 DCData confidentiality.
FR5 RDFRestricted data flow.
FR6 TRETimely response to events.
FR7 RAResource availability.

Practical interpretation path

A useful review starts with operational consequence, then works back through architecture, data flows, access paths, ownership and evidence. This keeps the conversation grounded in risk reduction rather than diagram aesthetics.

Start with operationsIdentify critical processes, safety considerations, production dependency, recovery needs and business impact.
Use Purdue for contextMake enterprise, DMZ, operations, supervisory and control separation visible to mixed stakeholder groups.
Convert layers into zonesGroup assets by security requirements, ownership, criticality, trust and operational role.
Validate conduitsReview required flows, firewall rules, remote access, vendor pathways, monitoring and rule ownership.
Prioritise improvementTranslate gaps into risk-ranked actions aligned to operational constraints, change windows and governance ownership.
Key takeaway

A mature IT/OT architecture is not created by drawing the Purdue Model. It is created by proving that zones and conduits are understood, justified, monitored, governed and aligned to the risk profile of the industrial operation.

Common industrial segmentation risk patterns

These patterns are frequently seen in real industrial environments. They do not automatically mean a site is insecure, but they usually justify closer review.

Direct L4 to L2 accessCorporate workstations, service accounts or enterprise tools can communicate directly with HMI, SCADA or engineering assets.
Flat operational VLANsEngineering, HMI, PLC and vendor assets share excessive trust with limited internal control points.
Vendor VPN into OTRemote support lands too deep in the environment without privileged access governance, approval, recording or expiry.
Over-permissive firewall rulesConduits exist technically, but rules are not constrained to least privilege or operational need.
Dual-homed workstationsEngineering stations bridge networks and undermine intended segmentation boundaries.
Weak DMZ servicesPatch, AV, historian or file transfer services become uncontrolled paths into lower levels.
Unclear ownershipRules, exceptions, accounts and legacy paths remain active because no team owns the risk lifecycle.
No validated flowsArchitecture diagrams exist, but actual traffic, routes and required communications have not been evidenced.

Self-review questions

Use these questions to assess whether your organisation has enough evidence to support confident IT/OT segmentation and ISA/ISA/IEC 62443-aligned architecture discussions.

AreaPractical questionWhy it matters
ArchitectureCan you identify all trust boundaries between enterprise IT, industrial DMZ, operations, supervisory systems and controllers?Boundaries must be visible before they can be governed.
ConduitsCan every IT/OT firewall rule or remote access path be mapped to a justified operational requirement?Unjustified flows create unmanaged attack paths.
Remote accessCan vendors reach OT assets only through controlled, approved, monitored and time-bounded access?Third-party access is often one of the highest risk pathways into industrial environments.
Asset visibilityDo asset inventories and monitoring outputs reflect what is really connected, not just what is expected?Zones based on incomplete asset data can create false assurance.
GovernanceAre rule ownership, exception handling, review cadence and change control clearly defined?Segmentation degrades over time without operational governance.
ResilienceAre backup, recovery and incident response assumptions validated for critical industrial systems?Security architecture should support operational continuity, not just prevention.
Correct use

How to use this model

Use the Purdue Model as a common language for understanding separation. Use IEC 62443 to structure risk-based zones, controlled conduits, target security levels and governance expectations.

Avoid overclaiming

What this page does not prove

This page does not prove IEC 62443 compliance. Compliance, certification or assurance requires defined scope, formal criteria, evidence review and appropriate assessment activity.

Practical next step

Apply the model to a real environment

A site-specific review should validate actual assets, firewall rules, remote access paths, operational dependencies, resilience assumptions and governance ownership before using this model for risk decisions.

Aegis support

Independent IT/OT segmentation and architecture review

Aegis Industrial Security provides independent IT/OT architecture advisory, industrial network segmentation reviews, firewall risk reviews and cyber resilience support for industrial organisations.

Discuss a review Return to main site