Promec Systems
Services Resources About Contact
Get in touch
Back to resources
IT/OT security

OT Network Segmentation — DMZ Design for Industrial Systems

IT/OT integration14 min readIEC 62443 · OT SecurityPROMEC Systems

Connecting an OT network to enterprise infrastructure without proper segmentation is one of the highest-risk things an industrial organisation can do. Not because connectivity is inherently dangerous — but because most teams design the firewall rules before they design the architecture, put the wrong servers in the wrong zones, and create paths between IT and OT that are never documented and therefore never reviewed.

Why OT Network Segmentation Is Different

IT network segmentation is about protecting data. OT network segmentation is about protecting physical processes — and the consequences of getting it wrong are not a data breach, they're a generation trip, a process upset, or physical damage to equipment. This changes the design priorities. In OT, patch windows are planned months in advance, system restarts may require controlled process rundown, and brief communication interruptions can cause spurious trips or missed events. The architecture must protect the OT network without affecting system availability or performance.

The Three-Zone Model

The defensible baseline architecture for industrial systems connecting to enterprise infrastructure is three zones separated by two firewalls:

ZoneContentsKey principle
CorporateWorkstations, AD, email, ERP, business intelligence, internet accessNo direct access to OT zone
DMZHistorian, jump server, file transfer, patch staging, AV update serverBuffer between IT and OT — neither side directly reaches the other
OT ZoneSCADA servers, HMIs, engineering workstations, PLCs, RTUs, IEDsOT-initiated traffic allowed out; enterprise-initiated traffic cannot come in

The key principle: OT-initiated traffic can flow from OT to DMZ. Enterprise-initiated traffic cannot reach the OT zone. The historian in the DMZ pulls data from the OPC server in the OT zone — not the other way around.

What Goes in the DMZ

Should be in the DMZ

  • Historian server — The plant historian and its database. Must live in the DMZ, not in the OT zone and not in the corporate network.
  • Jump server / bastion host — The only path for remote access into the OT zone. All vendor, support, and engineering remote sessions terminate here first. MFA required.
  • File transfer server — For moving files between enterprise and OT zones in a controlled, logged manner. Replaces USB drives and email attachments.
  • Patch staging server — Approved patches are copied here before being pushed to OT systems.
  • AV/endpoint update server — OT systems pull signature updates from here, not directly from the internet or corporate network.

Should NOT be in the DMZ

  • SCADA application servers — These belong in the OT zone. A SCADA server in the DMZ is exposed to enterprise.
  • Active SCADA HMI clients — An active HMI with write access to OT devices must be in the OT zone.
  • Safety systems — SIS requires physical separation, not just logical separation.
  • Domain controllers with write access — Creates a path for lateral movement from corporate to OT via domain trust.

The most dangerous DMZ mistake: putting a SCADA server in the DMZ because "it doesn't have write access." Write access is not the only risk. A compromised DMZ server can be used as a pivot point or to manipulate the data operators see. SCADA servers belong in the OT zone.

Firewall Rules — The Minimum Viable Ruleset

Every rule in your firewall ruleset should be justified by a specific operational requirement. "Allow any" rules in either firewall are both a compliance failure and a security failure. Each rule needs a named source, named destination, specific protocol and port, and a business justification. Rules without justifications don't survive an audit review.

Common Segmentation Mistakes

MistakeWhy it's a problemCorrect approach
Flat OT network with a single firewallNo DMZ — one compromised server reaches OT directlyDeploy two firewalls with a proper DMZ between them
Historian in the corporate networkRequires opening direct ports to/from OT — bypasses DMZ conceptHistorian lives in the DMZ
Vendor VPN terminating in the OT zoneVendor network gets direct access to OT devicesVPN terminates in DMZ — vendor uses jump server to reach OT
No session logging on the jump serverSecurity standards require logging of interactive remote accessConfigure session recording and retain logs per your retention policy

IT/OT Integration Planning Framework

Our free IT/OT Integration Planning Framework guides you through architecture decisions, DMZ design, security risk assessment, and testing in a structured five-phase sequence.

Download free framework Book an architecture review

Published by PROMEC Systems. Architecture recommendations align with IEC 62443 zone-and-conduit model principles. Review designs with your IT security team and validate against your regulatory requirements.

Promec Systems
Services Resources About Contact
(401) 830-2817 · © 2026 Promec Systems. All rights reserved.
0
Skip to Content
Promec systems
Home
About
Get a Free Quote
Promec systems
Home
About
Get a Free Quote
Home
About
Get a Free Quote

Customer Care

About

Contact

Contact

sales@promecsystems.com

© 2025 PROMEC SYSTEMS. All rights reserved.