OT security

Industrial DMZ architecture

An industrial DMZ creates a controlled zone between the OT network and enterprise systems so direct unrestricted connectivity is avoided.

Placement

In the Purdue model it is commonly described as Level 3.5, between manufacturing operations and the enterprise network.

Common services

MQTT broker

Controlled publish/subscribe exchange across zones.

API gateway

Authentication, authorization, routing, limits and logging.

Jump server

Controlled and auditable administrative access.

Replication

Controlled transfer of historian, file or other approved data.

Design rule

Allow only the required source, destination, protocol, port and operation. Avoid broad unrestricted paths between OT and IT.

Explore visually

See the DMZ inside the complete OT/IT architecture.

Open Concept Board