Back to Field Notes
Cloud & SASE/Field Note

OT Network Design — Defensible Segmentation Without Disrupting Production

Purdue is older than most engineers in the field. It is also the right answer for the substantial majority of OT environments.

Author

Hiroshi Tanaka

OT Security Lead

Published

April 24, 2026

Read

9 min

Share
AI-generated illustration of a power plant facility
AI-generated illustration of a power plant facility
Key Takeaways
  • 01The Purdue Enterprise Reference Architecture is sometimes dismissed as outdated. In practice, its zone model remains the right answer for the substantial majority of OT environments — and it maps cleanly to IEC 62443's zones and conduits.
  • 02The zones, in current vocabulary: Level 0/1 (process and basic control — sensors, actuators, PLCs), Level 2 (area supervisory — HMIs, local SCADA), Level 3 (site operations — historians, MES, batch management), Level 3.5 (industrial DMZ — jump hosts, AV updates, patch staging), Level 4/5 (enterprise — corporate IT, cloud).
  • 03Where to invest first: the IDMZ (Level 3.5). Done well it eliminates direct corporate-to-control traffic, provides a controlled patch and update path, and gives you the place to monitor lateral movement attempts. Done poorly it becomes a jump-host of last resort with weak controls. The control quality is the project.
  • 04Modern overlays: software-defined networking, virtual zones, and OT-aware firewalls let you implement Purdue without rewiring the plant. The model survives modernization; the implementation has many forms.

The Purdue Enterprise Reference Architecture is sometimes dismissed as outdated. In practice, its zone model remains the right answer for the substantial majority of OT environments — and it maps cleanly to IEC 62443's zones and conduits.

The zones, in current vocabulary

  • 01Level 0/1 — Process and basic control (sensors, actuators, PLCs)
  • 02Level 2 — Area supervisory control (HMIs, SCADA local)
  • 03Level 3 — Site operations (historians, MES, batch management)
  • 04Level 3.5 — Industrial DMZ (jump hosts, AV update servers, patch staging)
  • 05Level 4/5 — Enterprise (corporate IT, cloud)

Where to invest first

The IDMZ (Level 3.5) is the highest-leverage investment. Done well it eliminates direct corporate-to-control traffic, provides a controlled patch and update path, and gives you the place to monitor lateral movement attempts. Done poorly it becomes a jump-host of last resort with weak controls. The control quality is the project.

Modern overlays

Software-defined networking, virtual zones, and OT-aware firewalls let you implement Purdue without rewiring the plant. The model survives modernization; the implementation has many forms.

#OT#Purdue#Segmentation

/WRITTEN_BY

Hiroshi Tanaka

OT Security Lead · Alexa Cybersecurity