Control need · Segmentation that holds

Your network diagram shows a boundary. Your cabling may not.

Segmentation is usually described as a set of zones and enforced as a set of rules. The two are not the same thing. If a credential, a misconfiguration or a forgotten route can carry traffic across a boundary, that boundary exists on the diagram rather than in the estate.

  • For operations and engineering leaders
  • IT and OT context
  • Leads to Blueprint CP-04
  • Enforced in hardware
The connection state today

Zones defined in configuration, tested rarely

Boundary enforcementFirewall rules
Rule reviewPeriodic at best
Engineering accessPersistent
Proof the zone holdsA diagram

Need → Control → Blueprint → Modules

Corridor of offline storage racks inside a Firevault bunker
01What is exposed

A boundary you cannot demonstrate is a boundary you cannot rely on.

Where operational systems sit behind logical separation only, the exposure is easy to describe and uncomfortable to look at.

01

Systems that cannot defend themselves

Controllers and instruments running unpatchable software were designed for isolation, then connected for visibility and reporting.

Legacy exposure
02

Shared administrative tooling

When identity, monitoring or jump servers span both sides of the boundary, a compromise on one side inherits the other.

Shared control plane
03

Routes nobody documented

Engineering laptops, temporary links and supplier connections create crossings that never appear in the architecture record.

Undocumented paths
04

Consequences measured physically

In operational environments, the outcome of a crossing is not data loss. It is production stoppage, safety risk and service failure.

Physical consequence
02Why the exposure exists

Convergence delivered real benefits and quietly removed the gap.

Operational networks were connected for good commercial reasons. The problem is that the protection they previously relied on was physical, and what replaced it was configuration.

The honest position

You cannot configure your way back to an air gap.

Firewalls, VLANs and rule sets are valuable, and they are still configuration. Configuration is changed by people, inherited from previous teams and occasionally wrong. A boundary that matters to safety and continuity deserves an enforcement mechanism that does not depend on a rule being correct on the day.

Control the path, protect the asset.
Reason 01

Reporting needed a route

Production data had to reach the business, and the simplest way to deliver it was a permanent connection.

Reason 02

Remote support became standard

Equipment vendors expect to reach their kit, and that expectation was met with standing access.

Reason 03

Rule sets accumulate

Firewall policies grow over years until no one is confident about what any individual rule still permits.

Reason 04

Operational systems cannot be patched freely

Availability requirements mean known vulnerabilities remain in place far longer than in corporate IT.

Reason 05

Two teams, two languages

IT and operations measure risk differently, so boundary decisions fall between the two.

Reason 06

The gap was never replaced

When the air gap was removed, nothing physical was put in its place. Only policy was.

03Which path needs controlling

Segmentation becomes real when each crossing has an owner.

Rather than debating zone models, start by naming the crossings that exist today and deciding how each one should behave.

The path or relationshipWho uses itHow it behaves todayWhat Control governs
Corporate IT to operational networkReporting, planning and business systemsPermanent route governed by rulesPhysically closed by default, opened only for defined exchange
Engineering and maintenance accessInternal engineers and equipment vendorsStanding access through shared jump hostsScheduled window, named person, closed automatically
Operational data to the businessHistorians, dashboards and analyticsContinuous two-way connectivityOne directional, defined route for the data that must flow
Shared identity and management toolingIT administration and monitoringSpans both environmentsSeparated, so a compromise on one side does not inherit the other
Zone models, level mapping and conduit design belong in the Blueprint. This page is about agreeing which crossings exist and which of them should stop being permanent.
04What physical Control changes

The boundary stops being a rule and starts being a fact.

Control puts a physical enforcement point on the crossings you have named, so the boundary holds regardless of what happens in configuration.

Connection state today

Logical segmentation

Zones exist in policy and are enforced by devices that can be reconfigured, misconfigured or traversed with valid credentials.

  • The boundary depends on rules being correct today and tomorrow
  • Valid credentials can cross a boundary that policy says is closed
  • Undocumented routes accumulate without being noticed
  • Assurance is an architecture document rather than a state
  • Operational risk is carried by a configuration change process
Connection state with Control

Physically enforced segmentation

Crossings exist only when they have been opened for a purpose, and the closed state is a property of the hardware rather than of a rule.

  • No permanent path between corporate IT and operational systems
  • Data flows on a defined route, in the direction it is meant to travel
  • Engineering and vendor access opened on schedule and closed automatically
  • A boundary that survives a misconfiguration or a stolen credential
  • Segmentation you can demonstrate to a regulator or an auditor
In operational environments, the consequence of a crossing is measured in downtime and safety, not in records.Connected when approved. Disconnected by default.
05The Control philosophy

Control the path, protect the asset.

Control restores the discipline that operational environments used to get from physical separation, without giving up the visibility that convergence delivered.

01

Start with the path, not the tool

Every incident that spreads does so along a connection that was already there. Control begins by naming that connection in plain language, before anyone talks about products.

02

Make the default state disconnected

A path that exists only when it is needed cannot be used at three in the morning by someone who should not have it. Disconnection is the resting state, not the emergency response.

03

Open on approval, close on schedule

When work genuinely needs a connection, Control opens it for a named person, a stated purpose and a fixed period, then closes it again without anyone having to remember.

04

Prove it physically, not on paper

A policy says the path should be closed. Physical control shows that it is. That difference is what auditors, insurers and boards are actually asking about.

How this fits together

Your need sets the direction. Control sets the rule. The Blueprint sets the architecture.

NeedControlBlueprintModules and Firebreak
06Where this goes next

The Blueprint for this need is CP-04 Enforce Physical Segmentation

With the crossings agreed, the Blueprint sets out the zone architecture, the enforcement points and the phased deployment that gets there without interrupting production.

CP-04 · Lead layer FIRE

Enforce Physical Segmentation

Segmentation should not just be logical. It should be physically enforceable.

Modules the Blueprint leads with

Applied to trust boundary enforcement between zones. The Blueprint page carries the architecture, the zone detail and the deployment sequence.

Why it is worth exploring

What you get from the Blueprint that this page does not cover

  • The zone and conduit architecture behind physically enforced segmentation
  • Where enforcement sits on each crossing and what it governs
  • How scheduled maintenance and vendor windows are handled
  • A phased deployment designed around production constraints
  • Evidence aligned to sector expectations and recognised frameworks
A different job

This page is about the crossings between IT and OT. Protecting the engineering records, configurations and gold copies behind that boundary is a different job: Offline Secure Storage keeps them physically disconnected.

Hold engineering records offline
Questions

What operations leaders ask.

The questions that decide whether physical segmentation is practical in a live environment.

Deployment is phased and designed around operational constraints. Control sits at boundaries rather than inside control systems, so programs, logic and protocols are not modified.
Need → Control → Blueprint

Name the crossings. Then design the boundary.

CP-04 Enforce Physical Segmentation shows how zones are separated in hardware and how approved crossings are governed.

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy