Network & Systems

IT/OT Segmentation Design and Review

Independent design and review of the zone-and-conduit architecture separating IT and OT networks, for operators planning a segmentation project or checking one a vendor has already proposed.

Most industrial networks accumulate flat connectivity over years of individually reasonable decisions: a vendor remote-access line here, a historian pulling data from the control network there, until the boundary between IT and OT exists mostly on the network diagram. This engagement treats that boundary as a design question rather than an assumed fact: review how the network is actually segmented today, close the gap against a defensible zone-and-conduit model, and, where a design already exists, give it an independent, vendor-neutral read before it gets built.

What this covers

Architecture review characterizes how IT and OT are actually separated today, using configuration audit and protocol capture rather than sending traffic to field devices that weren't built to receive it. Gap analysis maps that current state against IEC 62443's zone-and-conduit model, grouping assets by criticality and function into zones and treating everything that crosses between them as an explicit, monitored conduit instead of an assumed one. The output is a target architecture and a prioritized roadmap for closing the gap, or, where a systems integrator or vendor has already proposed a design, an independent review of that design before it's implemented. For what a target zone-and-conduit architecture looks like in a pipeline OT environment, see the segmentation reference architecture diagram.

Who this is for

Network and OT architects and VP Infrastructure at operators planning a segmentation project, or wanting a second, vendor-neutral look at one already on the table. If the question is broader than segmentation specifically, where the program stands overall, see the OT/ICS security assessment instead, which covers this same architecture question as one part of a wider review mapped to NIST CSF 2.0 and NIST SP 800-82r3. If TSA has notified your pipeline system, hazardous liquid line, or LNG facility that it's critical, see the TSA pipeline cybersecurity page instead: segmentation is one piece of what those directives require, not the whole picture.

What an engagement looks like

Engagements start with a scoping call to confirm the environment and whether there's an existing design to review or this starts from current-state discovery. From there, architecture review and protocol capture build a picture of how the network is actually segmented today, kept passive by design so the work never puts a live process at risk to prove a finding. The output is a target zone-and-conduit architecture and a prioritized roadmap; implementation stays with your network team or systems integrator. Windlass is based in Houston, on-site for Gulf Coast operators and remote-capable everywhere else.

Frequently asked questions

Do you design the segmentation, or just assess it?

Both: current-state architecture review, gap analysis against a zone-and-conduit target, and a design and roadmap for closing the gap. The implementation work itself, configuring the switches and firewalls, stays with your network team or systems integrator; Windlass designs and reviews, independent of any hardware or integration vendor.

We already have a systems integrator proposing a segmentation design. Can you review it before it's built?

Yes. An independent review before implementation catches gaps against the zone-and-conduit model while they're still a design change, not a rebuild.

How is this different from the OT/ICS security assessment?

The OT/ICS security assessment covers the program broadly, mapped to NIST CSF 2.0 and NIST SP 800-82r3. This engagement goes deep on one architecture question inside that same review: how IT and OT are segmented, and what closing the gap to a zone-and-conduit model actually takes.

What if TSA has designated our system critical?

See the TSA pipeline cybersecurity page instead: segmentation is one control among several those directives require, built around what they specifically require rather than segmentation alone.