Glossary · Industrial communication
Network segmentation
Also known as: Network zoning, Segmentation
German: Netzwerksegmentierung
In OT security, network segmentation is the division of a network into separate segments or zones with controlled communication between them, so that traffic and the spread of attacks or faults are limited. IEC 62443-3-2 describes it as partitioning a system into zones and conduits.
- Industrial communication
- OT security
In one sentence
Network segmentation divides a network into zones with controlled links, limiting traffic and the spread of attacks or faults.
Example
Each production cell gets its own VLAN and subnet; an industrial firewall only lets the MES reach the cell controllers on OPC UA.
How it applies
- Engineering: Segments are formed from a risk assessment: assets with similar security requirements share a Security zone; communication between zones passes through defined Conduits such as firewalls. VLANs separate traffic logically; firewalls enforce rules between segments.
- Operation: Segmentation also contains non-malicious problems such as broadcast storms or misconfigured devices, which improves availability.
- Maintenance: New connections (for example for Remote access or a new cloud service) must be added through the change process, not by bypassing the segmentation.
- Documentation: The documentation team maintains the zone and conduit model, the Communication matrix and the firewall rule justification, and documents for each product which network interfaces it has and which ports and protocols it needs.
Network segmentation vs. air gap
An air gap means no network connection at all. Segmentation allows controlled connections. Pure air gaps are rare in modern plants because updates, data and service need a path; segmentation is the practical alternative.