OT network segmentation is the practice of dividing operational technology (OT) networks into isolated zones — separated from IT systems and the broader internet — to contain cyber threats before they reach industrial control systems. The most resilient segmentation strategies enforce that isolation at the hardware level, using data diodes or unidirectional gateways, rather than relying solely on firewall rules that can be misconfigured, exploited, or bypassed.
For organizations running SCADA systems, PLCs, or distributed control systems, segmentation isn’t a nice-to-have. It’s the primary control standing between a compromised IT network and a shutdown, safety incident, or environmental release on the plant floor.
Why OT Network Segmentation Matters Now
For decades, OT networks were segmented by default — they were physically isolated, running proprietary protocols with no path to the outside world. That isolation has eroded. Industry 4.0 initiatives, remote monitoring requirements, and the push to feed OT telemetry into cloud analytics and business intelligence platforms have connected environments that were never designed to be connected.
That convergence has consequences. Cybersecurity and Infrastructure Security Agency (CISA) reporting has repeatedly flagged rising attack activity against industrial control systems, and threat actors increasingly use IT-side compromises as a launching point into OT networks rather than attacking OT directly. Once inside, unsegmented networks give an attacker a straight path from a phished email account to a control system.
Regulatory pressure has followed the threat. NERC CIP requirements for the electric sector, the EU’s NIS2 directive, and sector-specific guidance from CISA all treat network segmentation as a foundational, often mandatory, control — not an optional hardening step.
The Purdue Model: Where Segmentation Actually Happens
Most OT segmentation strategy still traces back to the Purdue Enterprise Reference Architecture, which organizes industrial networks into hierarchical levels:
- Level 0-1: Field devices, sensors, and actuators
- Level 2: Supervisory control (HMIs, local controllers)
- Level 3: Site manufacturing operations and control
- Level 4-5: Business logistics, enterprise IT, and cloud
The two boundaries that matter most for segmentation are Level 2/3 (between supervisory control and site operations) and Level 3/4 (between the plant and the business network). These are the choke points where data legitimately needs to flow outward — for monitoring, reporting, and analytics — but where any inbound path represents unacceptable risk.
Segmentation Approaches Compared
Not all segmentation is equal. Here’s how the two dominant approaches stack up at the Level 3/4 boundary:
| Firewalls / DMZ Architecture | Hardware Data Diodes | |
|---|---|---|
| Enforcement mechanism | Software rules and policy configuration | Physical, one-way hardware path |
| Failure mode | Misconfiguration or vulnerability can open a path | No return path exists, regardless of configuration |
| Maintenance burden | Ongoing rule review, patching, tuning | Minimal — enforcement doesn’t depend on software state |
| Best fit | Bidirectional needs, general IT segmentation | One-way data flows: telemetry, historian data, monitoring feeds |
| Compliance weight | Accepted control, but audited for configuration drift | Treated as a high-assurance control in many frameworks |
Firewalls remain necessary for bidirectional traffic and general IT segmentation. But for the specific, common use case of getting OT data out to IT — historian replication, alerting, compliance reporting — a hardware-enforced one-way path removes an entire category of risk that no firewall rule can fully close.
Hardware-Enforced Segmentation in Practice
This is where data diode technology fits directly into a segmentation strategy. A hardware data diode contains a transmitting component on the OT side and a receiving component on the IT side, with no physical or electrical path for information to travel backward. Malware on the IT network cannot propagate into the OT environment through that path. Command-and-control traffic has nowhere to go. The isolation is a matter of physics, not policy.
Owl Cyber Defense’s Protocol Filtering Diodes (PFDs) extend this further by adding protocol-aware filtering on top of the one-way hardware path — so only well-formed, policy-approved data crosses the boundary, at throughput up to 100 Gbps depending on the appliance. That combination (hardware enforcement + protocol filtering) is what allows segmentation to hold up even as the volume and variety of OT data flowing outward keeps increasing.
Meeting Compliance Requirements
Segmentation decisions increasingly need to hold up to external scrutiny, not just internal risk tolerance. A few frameworks worth knowing:
- IEC 62443 defines Security Levels (SL1-SL4) for industrial automation and control systems. The higher tiers (SL3/SL4), associated with protection against sophisticated, resourced adversaries, are where hardware-enforced controls are most commonly specified.
- NERC CIP requires documented Electronic Security Perimeters for bulk electric system assets, with segmentation as a core control.
- CISA guidance consistently recommends unidirectional gateways and data diodes as a recognized control for critical infrastructure operators seeking defense-in-depth.
For organizations that already operate under U.S. government accreditation requirements, it’s also worth noting that Owl’s cross domain and data diode solutions are listed on the National Cross Domain Strategy and Management Office (NCDSMO) Baseline — the U.S. government’s own registry of accredited, hardware-enforced data transfer technology. That’s a materially different bar than a vendor simply claiming to be “government-grade.”
Real-World Deployment Considerations
A few practical notes for teams planning segmentation projects:
- Start at the boundary that carries the most risk, not the most convenient one. The Level 3/4 boundary is usually the highest priority because it’s the widest, most trafficked path between OT and the rest of the enterprise.
- Inventory what actually needs to leave the OT network. Historian data, alarms, and compliance logs are common candidates for one-way export — and rarely need a return path.
- Plan for growth in data volume. As predictive maintenance and AI-driven analytics programs mature, the volume of OT data feeding outward tends to grow quickly. Segmentation architecture should be sized for that trajectory, not just today’s traffic.
Frequently Asked Questions
What is OT network segmentation?
OT network segmentation is the practice of isolating operational technology networks — industrial control systems, SCADA, and similar environments — from IT networks and the internet, using controls that limit how and where data and commands can cross that boundary.
Why is OT network segmentation important?
It contains the blast radius of a cyberattack. Without segmentation, a compromise on the IT side of a business can potentially reach and disrupt physical industrial processes, with consequences ranging from downtime to safety incidents.
Is a firewall enough for OT network segmentation?
Firewalls are useful for bidirectional traffic and general segmentation, but they remain software that can be misconfigured or exploited. For one-way data flows out of OT environments, hardware-enforced data diodes remove the risk of a return path entirely, regardless of configuration.
What is the Purdue Model and how does it relate to segmentation?
The Purdue Model is a reference architecture that organizes industrial networks into hierarchical levels, from field devices up to enterprise IT. Segmentation is typically applied at the boundaries between these levels, most critically between site operations (Level 3) and the business network (Level 4).
Do data diodes support OT network segmentation?
Yes. Data diodes physically enforce one-way data flow between OT and IT networks, making them a common choice for the specific and frequent use case of exporting OT telemetry, historian data, or compliance logs without introducing any inbound risk.

