OT vs IT Security

Understand OT environments and manufacturing cyber risks against industry best practice guidelines

The Purdue Model and network segmentation

The Purdue Enterprise Reference Architecture (PERA), commonly called the Purdue Model, is the standard framework for segmenting industrial networks into security zones. It defines six levels, from physical processes at the bottom to the enterprise network at the top:

Level 0 – Physical process: Sensors, actuators, and the physical equipment being controlled. Temperature probes, pressure valves, motors.

Level 1 – Basic control: Programmable logic controllers (PLCs), remote terminal units (RTUs), and safety instrumented systems (SIS) that directly control Level 0 devices.

Level 2 – Area supervisory control: SCADA systems, human-machine interfaces (HMIs), and engineering workstations that monitor and manage Level 1 controllers.

Level 3 – Site operations: Production management, historian servers, and site-level systems that coordinate operations across the facility.

DMZ (Demilitarised zone): A buffer zone between OT (Levels 0-3) and IT (Levels 4-5). All traffic between OT and IT must pass through the DMZ. No direct connections.

Levels 4-5 – Enterprise IT: Corporate network, email, ERP, business applications, and internet connectivity.

The principle is straightforward: each level should only communicate with the levels immediately adjacent to it. Level 0 devices should never be directly reachable from the enterprise network. In practice, this architecture is routinely violated by IT/OT convergence, remote access tools, cloud-connected sensors, and business systems that reach into OT networks for operational data.

The air-gap myth

Historically, OT environments were assumed to be ‘air-gapped’ (physically isolated from IT networks and the internet). This assumption is now largely false. Modern industrial operations depend on data flowing between OT and IT for production reporting, predictive maintenance, supply chain integration, and remote monitoring. Cloud-connected IoT sensors, vendor remote access, and enterprise resource planning (ERP) systems have created connections that dissolve the air gap.

The 2017 Triton/TRISIS attack on a Saudi petrochemical facility targeted safety instrumented systems through a compromised IT network, demonstrating that even safety-critical OT systems can be reached when the air gap does not exist. The 2021 Colonial Pipeline ransomware attack shut down fuel distribution across the US eastern seaboard, not because the OT systems were directly compromised, but because the operator could not confirm the integrity of the OT network after the IT breach.

These incidents illustrate a consistent pattern: attackers enter through IT and pivot into OT. The convergence of IT and OT networks has made OT security an IT problem, whether OT teams acknowledge it or not.

IT/OT convergence risks

The convergence of IT and OT creates specific security challenges that neither discipline is equipped to handle alone:

Patching constraints – IT systems can be patched regularly with scheduled maintenance windows. OT systems often run continuously for months or years. Shutting down a production line or power plant to apply a Windows patch is rarely acceptable. Many OT systems run legacy operating systems (Windows XP, Windows 7) that no longer receive security updates.

Protocol differences – IT uses TCP/IP, HTTPS, and standard enterprise protocols. OT uses industrial protocols (Modbus, DNP3, OPC UA, PROFINET) that were designed for reliability, not security. Many OT protocols transmit data in cleartext with no authentication.

Asset visibility – IT environments are inventoried by endpoint management tools. OT environments often contain devices that were installed decades ago, have no documentation, and cannot be scanned without risk of disruption. You cannot secure what you cannot see.

Incident response – IT incident response can involve isolating systems, reimaging machines, and restoring from backups. In OT environments, isolating a compromised PLC might shut down a physical process, and there may be no backup configuration to restore. The response must balance cyber containment with operational safety.

The IEC 62443 standard addresses these challenges directly, providing a framework for securing industrial control systems that account for the operational constraints of OT environments.

Cyberfort and OT security

We deliver OT security assessments through our OT/IoT security review service. Our assessment covers OT asset discovery and inventory, network architecture review against the Purdue Model, vulnerability assessment of industrial control systems, IT/OT boundary analysis, and recommendations aligned to IEC 62443 and the NCSC CAF. We work with organisations across manufacturing, energy, utilities, and defence where OT security failures have operational and safety consequences. Our penetration testing service includes OT-specific testing for organisations that need to validate the security of their industrial environments under controlled conditions. Discuss your OT security requirements →

Related glossary terms

  • IEC 62443 – the international standard for industrial control system cyber security, built around zones and conduits
  • NCSC CAF – the UK Cyber Assessment Framework applied to critical national infrastructure, including OT environments
  • NIS2 Directive – EU regulation covering essential services sectors that rely on operational technology
  • MITRE ATT&CK – includes an ICS-specific matrix for mapping threats to industrial control systems
  • Zero Trust – the security architecture principle increasingly applied to OT network segmentation

External references

Frequently asked questions

What is the difference between OT security and IT security?

IT security protects data. It prioritises confidentiality, then integrity, then availability. OT security protects physical processes. It prioritises availability and safety, then integrity, then confidentiality. In an OT environment, a system going offline can cause equipment damage, environmental harm, or risk to human life. This fundamentally different risk profile means that OT environments require specialist security approaches, not just IT controls applied to industrial systems.

Is the air gap still effective for OT security?

In most environments, no. Modern industrial operations depend on data flowing between OT and IT for reporting, remote monitoring, predictive maintenance, and supply chain integration. Cloud-connected sensors, vendor remote access, and ERP integrations have dissolved the physical isolation that air-gapping relies on. Organisations should assume that their OT environments are reachable from IT and design their security controls accordingly, using the Purdue Model’s zone-based segmentation.

What framework should we use for OT security?

IEC 62443 is the primary international standard for industrial control system security. It provides a comprehensive framework covering asset owners, system integrators, and component suppliers. In the UK, the NCSC Cyber Assessment Framework (CAF) applies to organisations designated as operators of essential services under the NIS Regulations. Most organisations benefit from using IEC 62443 for technical controls and the NCSC CAF for governance and compliance reporting.

Awards and Accreditations

blue light commercial logo

Contact Us

Cyberfort Ltd
Venture West,
Greenham Business Park, Thatcham,
Berkshire,
RG19 6HX

+44 (0)1304 814800

[email protected]


Cyberfort
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.