Internet services, supplier connectivity, remote support entry points, cloud platforms and externally managed services.
Risk based
A practical guide for business, engineering, IT and OT stakeholders who need a clearer way to discuss industrial segmentation, trust boundaries, remote access and control system risk.
Industrial networks often evolve over many years. New data flows, remote support paths, monitoring tools and corporate services can slowly weaken the intended separation between business IT and operational technology.
In industrial environments, cyber risk is not only about data loss. It can affect production availability, operator confidence, safety-related processes, product quality and recovery capability.
The issue is rarely whether two systems can communicate. The real question is whether the communication is required, governed, monitored and constrained to the minimum operational need.
A network diagram is useful, but it does not prove the environment is secure. Evidence is needed for actual routes, firewall rules, accounts, remote paths, ownership and change control.
The Purdue Model is a useful reference model, not a complete security architecture. ISA/IEC 62443 adds a risk-based way to think about zones, conduits, target security levels, lifecycle governance and control requirements. Neither should be applied as a generic template without site context.
Use the model to understand why industrial cyber risk needs operational context, defined ownership and a prioritised improvement roadmap.
Use the zones and conduits language to discuss required data flows, safe remote access, production constraints and change windows.
Use the review questions to test whether architecture, firewall rules, access pathways and governance evidence support defensible decisions.
Select any Purdue layer to view a practical ISA/ISA/IEC 62443-aligned interpretation. The mapping is illustrative. A real environment should define zones and conduits based on risk, ownership, asset criticality, operational constraints and required data flows.
Internet services, supplier connectivity, remote support entry points, cloud platforms and externally managed services.
Corporate identity, email, ERP, service desk, SIEM, endpoint management, user workstations and standard IT operations.
Segregated intermediary layer for replicated historians, jump hosts, update brokers, file transfer, proxies and monitored data exchange.
MES, production scheduling, OT domain services, local historians, maintenance services, site applications and operational reporting.
SCADA servers, HMI stations, operator workstations, engineering workstations, alarm systems and control room services.
PLCs, RTUs, safety controllers, drives, relays, robotic controllers, process controllers and embedded control devices.
Sensors, actuators, valves, motors, pumps, conveyors, instrumentation, physical equipment and production process behaviour.
ISA/IEC 62443 helps convert a high-level architecture conversation into a risk-based control model for industrial automation and control systems. The key concepts for this page are zones, conduits, target security levels and foundational requirements.
These themes help explain why segmentation alone is not enough. They connect network design to identity, use control, integrity, confidentiality, restricted data flow, event response and resource availability.
A useful review starts with operational consequence, then works back through architecture, data flows, access paths, ownership and evidence. This keeps the conversation grounded in risk reduction rather than diagram aesthetics.
A mature IT/OT architecture is not created by drawing the Purdue Model. It is created by proving that zones and conduits are understood, justified, monitored, governed and aligned to the risk profile of the industrial operation.
These patterns are frequently seen in real industrial environments. They do not automatically mean a site is insecure, but they usually justify closer review.
Use these questions to assess whether your organisation has enough evidence to support confident IT/OT segmentation and ISA/ISA/IEC 62443-aligned architecture discussions.
| Area | Practical question | Why it matters |
|---|---|---|
| Architecture | Can you identify all trust boundaries between enterprise IT, industrial DMZ, operations, supervisory systems and controllers? | Boundaries must be visible before they can be governed. |
| Conduits | Can every IT/OT firewall rule or remote access path be mapped to a justified operational requirement? | Unjustified flows create unmanaged attack paths. |
| Remote access | Can vendors reach OT assets only through controlled, approved, monitored and time-bounded access? | Third-party access is often one of the highest risk pathways into industrial environments. |
| Asset visibility | Do asset inventories and monitoring outputs reflect what is really connected, not just what is expected? | Zones based on incomplete asset data can create false assurance. |
| Governance | Are rule ownership, exception handling, review cadence and change control clearly defined? | Segmentation degrades over time without operational governance. |
| Resilience | Are backup, recovery and incident response assumptions validated for critical industrial systems? | Security architecture should support operational continuity, not just prevention. |
Use the Purdue Model as a common language for understanding separation. Use IEC 62443 to structure risk-based zones, controlled conduits, target security levels and governance expectations.
This page does not prove IEC 62443 compliance. Compliance, certification or assurance requires defined scope, formal criteria, evidence review and appropriate assessment activity.
A site-specific review should validate actual assets, firewall rules, remote access paths, operational dependencies, resilience assumptions and governance ownership before using this model for risk decisions.
Aegis Industrial Security provides independent IT/OT architecture advisory, industrial network segmentation reviews, firewall risk reviews and cyber resilience support for industrial organisations.