A practitioner's view on zone models, conduit controls, and the gap between architecture diagrams and operational reality.
1. The "PowerPoint Firewall" vs. The Plant Floor
For years, enterprise security architects have sat in comfortable corporate offices drafting gorgeous network diagrams. These diagrams invariably showcase the pristine, layered structure of the Purdue Model, where information technology (IT) and operational technology (OT) are divided by a clear DMZ and a flawless firewall. In these PowerPoint presentations, no unauthorized packet ever crosses the boundary, and every industrial control system operates in serene, air-gapped isolation.
Then you walk onto the plant floor.
In the actual field, the "PowerPoint Firewall" quickly collapses under the weight of operational realities:
- Dual-homed workstations and engineering laptops: Technicians and vendors frequently dual-home workstations or plug their laptops directly into local switches to download configuration files, bridging the enterprise and control networks in a single turn.
- Rogue remote access and cellular backdoors: Frustrated by strict corporate IT policies or cabling costs, facility teams or third-party vendors often deploy unmanaged remote desktop tools or plug in rogue 3G/4G/5G cellular routers to establish direct paths to the internet.
- Third-party "black boxes": Building Management Systems (BMS) and HVAC networks are routinely outsourced to external integrators who demand unmonitored VPN access, treating the building's security as an unmanaged "black box."
This is not a hypothetical architecture flaw; it is a battle-tested initial access pipeline for adversaries. The classic historical precedent is the 2013 Target retail breach, where attackers stole credentials from an HVAC vendor, bypassed the perimeter, compromised the corporate Active Directory, and ultimately exfiltrated data from over 110 million customer accounts through the point-of-sale (POS) network.
Nearly a decade and a half later, the threat has escalated from data theft to physical sabotage. In December 2025, threat actors (attributed to Berserk Bear/Sandworm) targeted the energy sector in Poland, exploiting vulnerable, internet-facing edge routers that retained default passwords. The attackers moved laterally across flat networks directly onto Human-Machine Interfaces (HMIs) and Remote Terminal Units (RTUs), deploying destructive wiper malware, corrupting device firmware, and causing a catastrophic loss of view and physical control for distribution system operators.
Even when an attack is contained strictly to the IT layer, the operational dependency between IT and OT in modern automated environments can force a precautionary production shutdown. For example, during the May 2025 Nucor Steel incident, IT-layer violations forced a complete halt in production processes simply because the organization lacked the granular segmentation and visibility to verify that the OT network was safe.
2. Zones in the Wild: Pragmatic IEC 62443 Segmentation
To bridge the gap between elegant theory and messy plant floor realities, practitioners anchor their defense programs to the international standard ISA/IEC 62443. Rather than chasing a generic "security program" or trying to segment an entire plant at once, IEC 62443 provides a blueprint for grouping assets into functional Zones based on their operational consequence and communication needs.
The Three-Layer Architecture
A functional, defensible smart site or industrial facility is structured hierarchically:
- The Field Zone (Level 1 / 0): This is the lowest tier, housing physical sensors, actuators, and Direct Digital Controllers (DDCs) or Programmable Logic Controllers (PLCs) that interact directly with physical processes.
- The Control Zone (Level 2): This houses the supervisory control logic, local operator engineering workstations, and HMI dashboards used to monitor Level 1 devices.
- The Supervisory/Operations Zone (Level 3): This layer coordinates operations across multiple control areas and interfaces with enterprise boundaries through an Industrial DMZ.
The Vulnerability of Legacy Protocols
The primary challenge in Level 1 and Level 2 zones is that legacy automation protocols - such as BACnet, Modbus, LonWorks, and FOX - were engineered decades ago for physically isolated networks. They possess zero native authentication, encryption, or cryptographic integrity checks.
If an attacker gains access to a flat, unsegmented BACnet/IP network, they can easily sniff, spoof, or manipulate control packets to change temperature setpoints, unlock secure doors, or disable physical safety alarms. Security researcher Bertin Bervis demonstrated at DEF CON that BACnet web interfaces allow attackers to exploit read/write protocol properties to inject malicious JavaScript (Cross-Site Scripting or XSS) directly into the controller's configuration database, achieving persistent execution on browser devices used by operators.
This is a widespread industry vulnerability. On May 19, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued Advisory ICSA-26-139-05, documenting critical XSS vulnerabilities affecting multiple widely deployed Kieback & Peter DDC building controllers. This advisory was published alongside six other disclosures from major players like ABB, Siemens, and ScadaBR, proving that the web layers bolted on top of legacy protocols continue to inherit the fundamental insecurity of the protocols beneath them.
A pragmatic segmentation strategy does not expect these unauthenticated controllers to defend themselves. Instead, it isolates field devices on their own dedicated subnets, restricting configuration access and ensuring their web-based portals are never exposed directly to corporate networks or the public internet.
3. Conduit Controls: Defending the Paths In-Between
Under IEC 62443, a Conduit is a defined, logical communication pathway between different security zones. If zones represent the secured "towns" of your architecture, conduits are the guarded "roads" that connect them.
In the field, standard network segmentation often stops at flat Virtual Local Area Networks (VLANs) and basic Layer 4 (port-blocking) firewalls. However, blocking ports is no longer sufficient when modern threats run over allowed, legitimate channels.
Deep Packet Inspection (DPI)
A robust conduit design implements Deep Packet Inspection (DPI) firewalls that understand the industrial protocols themselves. A standard firewall sees Modbus traffic over TCP port 502 and permits it. A protocol-aware DPI firewall, by contrast, can read the Modbus payload in real time. It can be configured to permit read commands (e.g., Modbus Function Code 03) from a Level 2 HMI while blocking write commands (e.g., Modbus Function Code 06 or 16) unless they originate from a verified engineering workstation during an approved maintenance window.
Transitioning to Secure Protocols: BACnet/SC
To harden the conduits themselves, many organizations are transitioning from legacy BACnet/IP to BACnet/SC (Secure Connect). BACnet/SC encapsulates standard BACnet packets within secure TLS tunnels, bringing modern encryption, digital certificates, and strong mutual authentication (mTLS) directly down to the automation level.
However, practitioners must weigh the operational lifecycle burden of BACnet/SC. Because BACnet/SC requires every individual field controller to manage its own unique digital certificate, a mid-sized facility with 200 controllers translates to 200 certificates that must be manually deployed, tracked, and renewed before their 1-to-2-year expiry dates. This "certificate burden" frequently leads to misconfigurations or lapsed certificates that can bring down building systems, prompting many operators to seek alternative edge-gateway architectures.
4. Cloud-to-Edge: How SaaS Hijacked the Purdue Model
The traditional Purdue Model was designed for an era when OT networks could remain entirely offline. Today, the rise of cloud-hosted analytics, predictive maintenance, and Software-as-a-Service (SaaS) building management platforms has fundamentally shattered this offline assumption. Modern sites must connect to the cloud to achieve efficiency goals, but this cloud integration introduces severe supply-chain and edge gateway risks.
The Edge Router Attack Vector
To link local on-premises controllers to cloud platforms, facilities deploy 3G/4G/5G cellular edge routers and gateways. Because these devices bridge local OT networks with the public internet, they are highly valuable targets for threat actors.
In a landmark research project, Claroty’s Team82 uncovered critical vulnerabilities in ConnectedIO ER2000 4G edge routers and their cloud-based management platform. The exploitation chain revealed severe systemic flaws:
- Cryptographically insecure identifiers: The cloud platform relied on easily guessable hardware identifiers (sequential IMEI and MAC addresses) to authenticate and claim ownership of devices.
- Hardcoded clear-text credentials: The router firmware contained hardcoded, clear-text MQTT broker credentials shared across all deployed units.
-
Broker misconfiguration:
Because all devices shared the same credentials, the MQTT broker allowed any connected device to subscribe to the global
cio/device/statustopic. Attackers could sniff thousands of messages, leaking other routers' private Wi-Fi SSIDs, passwords, and IMEI numbers. -
Command execution over-privilege:
The router's communication protocol supported an unauthenticated, highly over-privileged command (Opcode
1116/CVE-2023-33374) that executed arbitrary shell commands directly under root privileges.
By chaining these vulnerabilities (tracked from CVE-2023-33372 to CVE-2023-33379), an attacker could remotely execute code on any connected edge gateway, compromise the underlying cloud infrastructure, and gain a root-level foothold inside thousands of industrial facilities worldwide.
What Actually Works: Secure Gateway Architecture
To secure the edge-to-cloud conduit without inducing certificate management fatigue, practitioners utilize a hardened Edge Gateway architecture:
- Outbound-only tunnels: The edge gateway must be configured to establish outbound-only connections to the cloud (typically using MQTT over TLS on TCP Port 8883). By initiating the connection from inside the OT network, the site requires zero inbound firewall holes and no port-forwarding, completely hiding the internal controllers from public internet scans.
- Centralized TLS termination: Instead of managing 200 certificates on 200 separate Level 1 controllers (the BACnet/SC headache), standard unencrypted BACnet/IP traffic is isolated on a local, non-routable OT subnet. The dual-homed edge gateway acts as the single security checkpoint: it ingests the local BACnet data, translates it to standardized, timestamped JSON schemas (such as Google UDMI), terminates a single secure X.509 certificate, and handles the secure mTLS transit to the cloud broker.
- Publish-by-exception: To conserve bandwidth and prevent network flooding, the gateway only publishes data packets when a value actually changes, eliminating continuous, noisy polling across the internet.
5. A Consequence-Led Implementation Playbook
As the Europe OT/ICS market transitions from voluntary compliance to strict, legally binding frameworks under the EU Cyber Resilience Act (CRA) and the NIS-2 Directive (which introduces personal liability for management boards and mandatory 24-hour incident reporting), security leaders must act swiftly.
However, according to Fortinet’s 2026 State of Operational Technology and Cybersecurity Report, OT environments are facing a severe "visibility crisis": OT professionals report having visibility over only half of their active OT environments. At the same time, the Dragos 2026 report warns that threat groups have progressed to Stage 2 of the ICS Cyber Kill Chain, moving past simple network reconnaissance to actively mapping physical control loops (HVAC, power grids, and water systems) to execute targeted physical disruptions. Compounding this, ransomware groups targeting industrial organizations have risen by 49% to 109 active groups, and average eCrime breakout times have plummeted to just 29 minutes (with the fastest observed breakout at a mere 27 seconds).
Faced with these statistics, a generic, all-at-once security program is doomed to fail. Security leaders must deploy a consequence-led, 3-step implementation playbook designed for industrial reality:
Step 1: Establish the Baseline via Passive Discovery
- Action: Deploy non-intrusive, passive network monitoring tools at the IT/OT boundary and core switches. Passive scanning analyzes network traffic mirrors without sending active ping packets that could crash fragile, legacy controllers.
- Deliverable: A compliance-grade asset inventory detailing device functions, physical locations, firmware supportability, and zone placements. Identify and eliminate immediately apparent vulnerabilities like exposed, unmonitored remote access sessions or default factory passwords.
Step 2: Micro-Segment High-Consequence Zones
- Action: Sequence your segmentation based on operational consequence, not convenience. Do not attempt to segment the entire plant in a single maintenance window.
- Deliverable: Isolate the highest-consequence control zones first. In a smart building or enterprise campus, this means separating data center cooling loops (HVAC), hospital operating theater controls, pharmaceutical cleanrooms, and physical access control networks from standard building operations. Enforce explicit firewall and conduit rules at these critical boundaries.
Step 3: Implement Identity Hardening & "Learning Mode" Monitoring
- Action: Mandate phishing-resistant Multi-Factor Authentication (MFA) and role-based access controls for all remote vendor technicians.
- Deliverable: Deploy protocol-aware intrusion detection systems. Run the monitoring tools in "learning mode" for the first 30 to 60 days to map normal communication baselines and protocol usage before enforcing block rules. This prevents accidental production shutdowns from false-positive rule triggers while providing the SOC with the actionable, real-time alert data required to meet modern regulatory timelines.
By focusing on scope clarity, zone and conduit discipline, outbound-only edge gateway transit, and consequence-led prioritization, industrial operators can build an OT security program that successfully holds up to both rigorous audits and real-world cyber incidents.