Diagram

IT/OT Segmentation Reference Architecture

A zone-and-conduit reference architecture for a pipeline OT environment: five zones, and the specific conduits between them worth naming individually rather than treating the boundary as a single firewall.

This diagram lays out five zones, from Corporate/IT through OT Supervisory and OT Control to Safety, and the conduits between them, built around the two failure patterns that show up most often in real segmentation reviews: a historian export that should be a narrow one-way conduit, and vendor remote access that should stop at the supervisory zone rather than reaching Control or Safety directly. It's a generic reference model, not a specific network's as-built diagram, useful as a starting point for describing where a real environment's segmentation matches this shape and where it doesn't.

IT/OT segmentation reference architectureCorporate/IT and DMZ zones connect via general business traffic. The DMZ and OT Supervisory zone connect via two separate conduits: a one-way historian export flowing from OT Supervisory to the DMZ, and a time-boxed, monitored vendor remote-access path flowing from the DMZ into OT Supervisory only. OT Supervisory and OT Control connect via a controlled, logged engineering-access conduit. OT Control and the Safety zone have no routine traffic between them.Corporate / ITERP & emailReporting dashboards1DMZHistorian relayVendor jump host23OT SupervisoryHMI & eng. workstationsPrimary historian4OT ControlPLCs / RTUsSafetySIS

Diagram scrolls horizontally on narrow screens.

What the numbered conduits mean

1 — Corporate / IT ↔ DMZ
General business traffic, stopping at the DMZ boundary rather than reaching further into the OT side directly.
2 — OT Supervisory → DMZ (one-way)
The historian's process-data export. Built correctly, it's a narrow, one-directional conduit: data flows out, nothing flows back in. This is the most common finding in a real segmentation review, built the way time pressure usually produces it: a dual-homed server with broader access than the export function needs.
3 — DMZ → OT Supervisory (vendor remote access)
A jump host or VPN path for vendor and integrator support, time-boxed and monitored, and reaching no further than the supervisory zone. The gap opens when this access stays broader or longer-lived than the commissioning project that originally justified it.
4 — OT Supervisory ↔ OT Control
Engineering access to controllers, controlled and logged rather than left open the way a flat network would leave it.
OT Control ↔ Safety: no routine traffic
The Safety Instrumented System is isolated by design. There's no numbered conduit here because the point is the absence of one, not a restricted version of one.

Where a real network usually diverges

Two gaps against this model show up more than any others: a historian built as a broad dual-homed bridge instead of conduit 2's narrow one-way path, and vendor remote access left reaching further, or staying open longer, than conduit 3's time-boxed design calls for. Both are covered in more detail in IT/OT segmentation for pipeline environments, and both are what a segmentation design and review engagement checks first.

This is a generic reference model built around IEC 62443's zone-and-conduit concept, not a specific operator's as-built network. Last verified 2026-09-23.

Check a design against this model