---
title: "The Purdue Model for OT and ICS Security"
description: "A working guide to the Purdue Model (PERA) for OT and ICS security: the six levels, the industrial DMZ at Level 3.5, and where a physical air gap belongs."
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": "GB"
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/purdue-model-ot-ics-security#webpage",
      "url": "https://fire-vault.com/learn/purdue-model-ot-ics-security",
      "name": "The Purdue Model for OT and ICS Security",
      "description": "A working guide to the Purdue Model (PERA) for OT and ICS security: the six levels, the industrial DMZ at Level 3.5, and where a physical air gap belongs.",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-learn.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/purdue-model-ot-ics-security#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/purdue-model-ot-ics-security#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "The Purdue Model for OT and ICS Security",
          "item": "https://fire-vault.com/learn/purdue-model-ot-ics-security"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "The Purdue Model for OT and ICS Security",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Firevault"
      },
      "mainEntityOfPage": "/learn/purdue-model-ot-ics-security"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is the Purdue Model in OT security?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The Purdue Model, formally the Purdue Enterprise Reference Architecture (PERA), is a reference architecture that divides an industrial estate into six levels, from Level 0 field devices up to Level 5 enterprise, with an industrial DMZ at Level 3.5. It is the shared vocabulary that OT engineers, IT teams, IEC 62443 assessors and cyber underwriters use to describe where a system sits and what it may talk to."
          }
        },
        {
          "@type": "Question",
          "name": "What are the levels of the Purdue Model?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The levels are Level 0 (field devices, sensors, actuators), Level 1 (PLCs, RTUs, safety instrumented systems), Level 2 (HMI, engineering workstations, local historians), Level 3 (site operations, MES, batch, asset management), Level 3.5 (industrial DMZ), Level 4 (site business systems) and Level 5 (corporate IT, cloud, SaaS). Some diagrams collapse L4 and L5, but the boundary between the plant and the enterprise always sits at Level 3.5."
          }
        },
        {
          "@type": "Question",
          "name": "Is the Purdue Model still relevant in 2026?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. It is regularly declared obsolete by cloud vendors and IIoT platforms, then quietly reused by every serious OT security programme. IEC 62443, NIST SP 800-82 and the NCSC CAF still reference Purdue levels, and insurers still expect Level 3.5 to be a real boundary. The model is not a security control on its own, but it remains the standard vocabulary for zones and conduits."
          }
        },
        {
          "@type": "Question",
          "name": "Where does a physical air gap fit in the Purdue Model?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The physical air gap sits at Level 3.5 or in a dedicated bunker adjacent to the OT estate, isolated from Level 4 and Level 5. That placement means the gold copy remains disconnected when the corporate identity domain is compromised, which is the entry point for the majority of destructive OT ransomware incidents."
          }
        },
        {
          "@type": "Question",
          "name": "What is the difference between the Purdue Model and IEC 62443 zones?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The Purdue Model is a reference architecture that names the layers. IEC 62443 uses those layers as a starting point but requires you to define zones (groups of assets with common security requirements) and conduits (the connections between them) with formal security level targets. In practice most IEC 62443 assessments map zones on to Purdue levels then tighten from there."
          }
        },
        {
          "@type": "Question",
          "name": "What is Level 3.5 in the Purdue Model?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Level 3.5 is the industrial DMZ, an intermediate zone between site operations (Level 3) and enterprise IT (Level 4 and above). It hosts jump servers, patch mirrors, published historians and the boundary services that let OT and IT exchange data without direct connectivity. It is the recommended home for a Firevault gold copy so that isolation from the corporate domain is enforceable."
          }
        },
        {
          "@type": "Question",
          "name": "How is OT network segmentation related to the Purdue Model?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The Purdue Model provides the boundaries. OT network segmentation is the enforcement: firewalls, unidirectional gateways, protocol breaks and, for the gold copy, a physical air gap. Segmentation without an underlying reference architecture drifts. The Purdue Model without segmentation is just a diagram."
          }
        },
        {
          "@type": "Question",
          "name": "Do we need a Purdue Model diagram for our IEC 62443 assessment?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "An assessor will not usually mandate a Purdue diagram by name, but they will ask for a zone and conduit diagram that shows where the plant ends and where the enterprise begins. A properly labelled Purdue diagram with the industrial DMZ, the identity boundaries and the gold copy location is the fastest way to answer that request."
          }
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Why OSS 

# The Purdue Model for OT and ICS Security 

The Purdue Enterprise Reference Architecture is still the vocabulary IEC 62443 assessors, cyber underwriters and OT engineers use to describe an industrial estate. This is where every level sits, and where a physical air gap belongs.

Book a demo

![Corridor of offline storage racks inside a Firevault bunker](/assets/hero-square-bunker-BC9Flanh.jpg)

R6 

What the Purdue Model actually is 

## A Reference Architecture, Not a Product 

The Purdue Model is a shared vocabulary for OT and IT. It is not a security control on its own, but every serious OT programme still uses it.

01 

Purdue Enterprise Reference Architecture (PERA) 

### A reference architecture, not a product

The Purdue Model is a reference architecture for industrial control systems, originally published as PERA by Theodore Williams at Purdue University in the 1990s. It splits an industrial estate into levels so that engineers, IT and security can agree on where a system sits and what may talk to it.

-   Published as PERA, 1990s
-   Shared vocabulary for OT and IT
-   Not a product or a standard

02 

Levels 0 to 5 plus an industrial DMZ 

### Six zones from field to cloud

The model runs from Level 0 (field devices) up to Level 5 (enterprise). Between the plant and the enterprise sits Level 3.5, the industrial DMZ, where OT talks to IT under strict rules. Modern OT security programmes treat those level boundaries as the primary segmentation policy.

-   L0 field devices, sensors, actuators
-   L3.5 industrial DMZ boundary
-   L5 enterprise, cloud, SaaS

03 

IEC 62443 and NIST SP 800-82 both use it 

### Still the reference in 2026

The model is regularly declared obsolete, then quietly reused. IEC 62443, NIST SP 800-82 and the NCSC CAF for essential services all reference Purdue levels when they describe zones and conduits. It is the shorthand assessors, insurers and auditors expect in scoping documents.

-   Referenced by IEC 62443
-   Referenced by NIST SP 800-82
-   Assumed by cyber underwriters

The six levels, from field to cloud 

## Level by Level, What Sits Where 

Level 0 field devices up to Level 5 enterprise, with the industrial DMZ at Level 3.5. The boundary between the plant and the enterprise always sits at 3.5.

01 

Field devices, controllers and supervision 

### Level 0 to 2, the plant

Level 0 is the physical process: valves, motors, sensors, actuators. Level 1 is the controllers that drive them: PLCs, RTUs, safety instrumented systems. Level 2 is the local supervision: HMI, engineering workstations and site historians. This is where uptime is measured in years and where ransomware translates directly into a stopped plant.

-   L0 sensors and actuators
-   L1 PLC, RTU, SIS
-   L2 HMI, engineering workstations

02 

Where OT meets IT under strict rules 

### Level 3 and 3.5, operations and DMZ

Level 3 hosts site operations: MES, batch, site historians and asset management. Level 3.5 is the industrial DMZ where OT publishes data to IT and receives updates back. Almost every OT ransomware incident enters at this boundary, which is why the Firevault gold copy sits at Level 3.5, isolated from Levels 4 and 5.

-   L3 MES, batch, site historian
-   L3.5 industrial DMZ
-   Highest attacker footfall

03 

Corporate estate, cloud and SaaS 

### Level 4 and 5, IT and enterprise

Level 4 is site-level IT: business systems that live in the same building as the plant. Level 5 is the wider enterprise: corporate identity, cloud, SaaS. These layers carry the majority of the attack surface and the majority of destructive incidents originate here, which is why a physical air gap between L4/L5 and the OT gold copy is the boundary of last resort.

-   L4 site business systems
-   L5 corporate cloud and SaaS
-   Origin of most OT incidents

Where a physical air gap belongs 

## Firevault at Level 3.5 or a Dedicated Bunker 

Ransomware enters at Level 5, moves through Level 4, then pivots at Level 3.5. A Layer 1 physical air gap breaks that chain for the gold copy.

01 

L5 to L3.5, then downward 

### Where ransomware enters the model

The dominant attack pattern is compromise at Level 5 (phished corporate identity, exposed VPN, exploited SaaS), lateral movement to Level 4, then a pivot through Level 3.5 into the plant. Every published post-incident report on a large OT ransomware event follows this shape. The mitigation is not more segmentation rules, it is a copy the attacker cannot reach at all.

-   Entry at L5, corporate identity
-   Lateral to L4 and Level 3.5
-   Air gap breaks the chain

02 

Layer 1 isolation, not VLAN separation 

### Firevault at Level 3.5 or a dedicated bunker

The Firevault gold copy sits at Level 3.5, or in a dedicated bunker adjacent to the OT estate. It has no network interface enabled while offline. Connection windows are switched out of band, logged on a separate management plane, and closed the moment the sync ends. That is a Layer 1 boundary, not a firewall rule.

-   No live network interface
-   Out-of-band switching
-   Tamper evident connection log

03 

Not a replacement, an addition 

### Layered with existing ICS backup

The Firevault pattern does not replace Veeam, Rubrik, Commvault or native ICS backup platforms. Those handle fast operational recovery for the ordinary failure modes. Firevault provides the one offline copy the 3-2-1-1-0 rule requires, and the tamper evident evidence the insurer requires.

-   Layers over existing tools
-   Handles the one offline copy
-   Provides audit evidence

Common mistakes

## Eight Ways a Purdue Diagram Is Misused

A Purdue diagram on the wall is not a security control. These are the failure modes we see most often in OT assessments.

-   Treating Purdue as a security control on its own, it is a reference architecture and needs enforcement 
-   Placing the industrial DMZ (Level 3.5) inside the same identity domain as Levels 4 and 5 
-   Running the OT backup platform on a VM in the corporate hypervisor, reachable from Level 5 
-   Assuming a firewall between levels is equivalent to physical isolation for the gold copy 
-   Skipping Level 3.5 entirely and letting Level 3 talk directly to Level 5 for reporting 
-   Buying an immutable appliance and describing it as an air gap in insurer paperwork 
-   Not testing a restore from the offline copy across a Level 3.5 boundary at least annually 
-   Losing chain of custody by moving the offline copy through an ordinary courier rather than an escorted collection 

Continue with the diagram reference, the segmentation guide and the wider OT pillar.

[Purdue Model diagram](/learn/purdue-model-diagram) [OT network segmentation](/learn/ot-network-segmentation) [OT and ICS security pillar](/learn/ot-ics-security-air-gap-storage) [Module deployment maps](/control)

Questions 

## The Purdue Model, Common Questions

Straight answers on how Offline Secure Storage® behaves in practice.

### What is the Purdue Model in OT security?

### What are the levels of the Purdue Model?

### Is the Purdue Model still relevant in 2026?

### Where does a physical air gap fit in the Purdue Model?

### What is the difference between the Purdue Model and IEC 62443 zones?

### What is Level 3.5 in the Purdue Model?

### How is OT network segmentation related to the Purdue Model?

### Do we need a Purdue Model diagram for our IEC 62443 assessment?

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

![David Bailey](/assets/david-bailey-CnLw95Ao.jpg)

![Kenny Phipps](/assets/kenny-phipps-DxIqwaIL.jpg)

Online Now 

Concierge 

## Put the gold copy at Level 3.5, not on the corporate domain

Talk to the Firevault team about a Layer 1 air-gapped copy that sits at the industrial DMZ, isolated from the enterprise identity ransomware targets first.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up