Systems that cannot defend themselves
Controllers and instruments running unpatchable software were designed for isolation, then connected for visibility and reporting.
Legacy exposureSegmentation is usually described as a set of zones and enforced as a set of rules. The two are not the same thing. If a credential, a misconfiguration or a forgotten route can carry traffic across a boundary, that boundary exists on the diagram rather than in the estate.
Need → Control → Blueprint → Modules

Where operational systems sit behind logical separation only, the exposure is easy to describe and uncomfortable to look at.
Controllers and instruments running unpatchable software were designed for isolation, then connected for visibility and reporting.
Legacy exposureWhen identity, monitoring or jump servers span both sides of the boundary, a compromise on one side inherits the other.
Shared control planeEngineering laptops, temporary links and supplier connections create crossings that never appear in the architecture record.
Undocumented pathsIn operational environments, the outcome of a crossing is not data loss. It is production stoppage, safety risk and service failure.
Physical consequenceOperational networks were connected for good commercial reasons. The problem is that the protection they previously relied on was physical, and what replaced it was configuration.
Firewalls, VLANs and rule sets are valuable, and they are still configuration. Configuration is changed by people, inherited from previous teams and occasionally wrong. A boundary that matters to safety and continuity deserves an enforcement mechanism that does not depend on a rule being correct on the day.
Control the path, protect the asset.Production data had to reach the business, and the simplest way to deliver it was a permanent connection.
Equipment vendors expect to reach their kit, and that expectation was met with standing access.
Firewall policies grow over years until no one is confident about what any individual rule still permits.
Availability requirements mean known vulnerabilities remain in place far longer than in corporate IT.
IT and operations measure risk differently, so boundary decisions fall between the two.
When the air gap was removed, nothing physical was put in its place. Only policy was.
Rather than debating zone models, start by naming the crossings that exist today and deciding how each one should behave.
Control puts a physical enforcement point on the crossings you have named, so the boundary holds regardless of what happens in configuration.
Zones exist in policy and are enforced by devices that can be reconfigured, misconfigured or traversed with valid credentials.
Crossings exist only when they have been opened for a purpose, and the closed state is a property of the hardware rather than of a rule.
Control restores the discipline that operational environments used to get from physical separation, without giving up the visibility that convergence delivered.
Every incident that spreads does so along a connection that was already there. Control begins by naming that connection in plain language, before anyone talks about products.
A path that exists only when it is needed cannot be used at three in the morning by someone who should not have it. Disconnection is the resting state, not the emergency response.
When work genuinely needs a connection, Control opens it for a named person, a stated purpose and a fixed period, then closes it again without anyone having to remember.
A policy says the path should be closed. Physical control shows that it is. That difference is what auditors, insurers and boards are actually asking about.
With the crossings agreed, the Blueprint sets out the zone architecture, the enforcement points and the phased deployment that gets there without interrupting production.
Segmentation should not just be logical. It should be physically enforceable.
Applied to trust boundary enforcement between zones. The Blueprint page carries the architecture, the zone detail and the deployment sequence.
This page is about the crossings between IT and OT. Protecting the engineering records, configurations and gold copies behind that boundary is a different job: Offline Secure Storage keeps them physically disconnected.
Hold engineering records offlineThe questions that decide whether physical segmentation is practical in a live environment.
CP-04 Enforce Physical Segmentation shows how zones are separated in hardware and how approved crossings are governed.
We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy