OT CybersecurityBy AzertyUI Team

Many industrial incidents start far from the machines: a phishing email, a compromised office workstation. If the plant network is “flat”, nothing stops the attack from reaching the PLCs. Segmentation is the measure that limits this risk.
The Purdue model as a map
The Purdue model describes a plant in levels: sensors and actuators (level 0), PLCs (1), SCADA (2), manufacturing operations (3), then business IT (4 and 5). It is not meant to be applied literally, but it gives a shared vocabulary to decide who is allowed to talk to whom.
The industrial DMZ
Between business IT and production sits an industrial demilitarised zone (often called level 3.5). Necessary exchanges go through relay servers: replicated historian, update server, remote access bastion. No flow crosses directly from IT to the PLCs.
Simple flow rules
- Everything is denied by default, then justified flows are allowed one by one.
- Outbound flows from production are preferred over inbound ones.
- Each rule is documented: source, destination, protocol, reason, owner.
- Maintenance access goes through a single, logged entry point (see our article on remote access).
Segmenting without stopping production
Segmentation is prepared: passive observation of existing flows, rules in “log only” mode before blocking, a planned switchover outside production. We include it in the roadmap of our OT assessment, consistent with the zones and conduits of IEC 62443.
Related Tags
- Cybersécurité OT
- DMZ industrielle
- Industrial DMZ
- Industrial firewall
- Modèle de Purdue
- OT Cybersecurity
- Pare-feu industriel
- Purdue model
- Segmentation


