Fortinet Engage Partner Specialization — ot
All insights
ITBUILDERS INTELLIGENCEFortinet

Securing Critical Infrastructure: Implementing the Purdue Model Without Production Downtime

OT networks can't tolerate downtime or unpatchable-system surprises. Here's how to segment industrial environments with the Purdue model, level by level, without stopping production.

By ITBuilders3 min read

In IT, a security change that causes a five-minute outage is an inconvenience. In OT, it can halt a production line, spoil a batch, or trip a safety system.

That single difference shapes everything about securing industrial networks. The same firewall rule that works fine in an office can stop a plant if someone applies it the IT way.

Why OT Breaks the IT Playbook

Industrial environments run on different assumptions.

Availability comes first. Plants measure uptime in years. Maintenance windows are rare, scheduled months ahead, and too short for trial and error.

Systems can't be patched on demand. Many PLCs, HMIs, and engineering workstations run operating systems or firmware that the vendor no longer updates. Others can be patched only with vendor approval, because an unapproved change can void the support contract or the safety certification.

Protocols trust everything. Modbus, DNP3, and many other industrial protocols were designed for isolated networks. Most carry no authentication. Any device that can reach a controller can usually send it commands.

Conditions are harsh. Equipment sits in substations, pump stations, and factory floors with heat, dust, vibration, and electrical noise that would kill standard rack hardware.

The networks are no longer isolated. Remote maintenance, production reporting, and ERP integration have connected many OT networks to corporate IT, and through it, to the internet. The air gap that once protected them is usually gone, whether anyone documented it or not.

The Purdue Model, Level by Level

The Purdue model gives OT networks a structure to segment against. It organizes the environment into levels, with security controls at the boundaries between them. IEC 62443 builds on the same idea with its zones and conduits approach, and the NCA's Operational Technology Cybersecurity Controls (OTCC) set specific expectations for OT environments in Saudi Arabia.

Here's how each level works in practice, from the plant floor up.

Levels 0 and 1: Physical process and basic control. Sensors, actuators, and the PLCs that control them. This is where the physical process runs. Security at this level focuses on protecting controllers from unauthorized commands.

Level 2: Supervisory control. HMIs and SCADA systems that operators use to monitor and control the process. A compromise here gives an attacker the operator's view and the operator's controls.

Level 3: Site operations. Historians, engineering workstations, and site-wide production management. This level collects data from below and hands it to business systems above.

Level 3.5: The industrial DMZ. The most important boundary in the model. No traffic should pass directly between the enterprise network and the control network. Instead, both sides talk to brokered services in the DMZ, such as a replicated historian, a patch server, or a jump host for remote access.

Levels 4 and 5: Enterprise IT. Business systems, ERP, email, and the internet. From the OT perspective, this is untrusted territory.

The goal is simple to state: an attacker who compromises an office laptop should hit wall after wall before getting anywhere near a controller.

IT Builders delivers OT cybersecurity work aligned with NCA regulations. In our experience, the hardest part of these projects is rarely the firewall configuration. It's discovering what's actually on the network and how it communicates, because the documentation almost never matches reality.

Starting an OT Segmentation Project?
Safe segmentation starts with a passive assessment of your OT assets and communication flows, completed without touching production systems.

Rules of Engagement for OT Inspection

Segmenting a live plant safely takes discipline. These principles keep production running.

Watch before you touch. Start with passive monitoring through a SPAN port or network TAP. Map every asset and every conversation between them before writing a single blocking rule. This baseline becomes the foundation of the policy.

Deploy without re-addressing. Changing IP schemes in an OT network can mean reprogramming controllers. FortiGate can run in transparent mode, sitting inline as a bridge so it inspects and filters traffic without any change to device addressing.

Understand the protocols, not just the ports. A port-based rule can allow Modbus or block it. It can't tell a routine read from a command that changes a setpoint. FortiGate's industrial protocol inspection, backed by FortiGuard's OT threat intelligence service, reads commands inside protocols such as Modbus and DNP3, so policy can allow monitoring traffic while blocking unauthorized writes.

Patch virtually where you can't patch physically. For controllers that will never receive another update, IPS signatures for known vulnerabilities block exploit attempts on the network before they reach the device.

Alert first, block later. Run new policies in monitor mode through at least one full production cycle. Move to enforcement only after operations and engineering have reviewed what the policy would have blocked.

Use hardware built for the environment. FortiGate Rugged models handle the temperature, vibration, and power conditions of substations and factory floors, and carry industrial certifications that standard firewalls don't.

The Bottom Line

OT security fails when it treats a plant like an office. It works when it respects the constraints of the environment: segmenting along the Purdue levels, observing before enforcing, inspecting industrial protocols at the command level, and protecting systems that can't protect themselves.

IT Builders is an authorized Fortinet Engage Partner holding the Operational Technology specialization. Our engineers run passive OT assessments, design segmentation around your production realities and NCA OTCC requirements, and deploy controls in stages that keep the plant running.

Planning OT segmentation or preparing for an OTCC assessment?

Fortinet Engage Partner Specialization — firewallFortinet Engage Partner Specialization — lanFortinet Engage Partner Specialization — sdwanFortinet Engage Partner Specialization — saseFortinet Engage Partner Specialization — secopsFortinet Engage Partner Specialization — cloudFortinet Engage Partner Specialization — ot
TALK TO A SPECIALIST

Turn this insight into a practical next step.

Discuss your environment with our team and get a clear recommendation grounded in your operational reality.

Start a conversation
CONTINUE READING

Related intelligence