TroutTrout

Beyond Purdue. Micro-DMZs for Modern OT.

The Purdue Model defined OT security for decades. But remote access, IIoT, and cloud analytics have eroded every layer. It's time for a new boundary, one per asset.

Zuletzt aktualisiert:

Forces of Change

Why the Purdue Model and Its DMZ No Longer Hold.

Three forces erode the hierarchy while the Industrial DMZ concentrates risk instead of distributing defense.

Single Point of Failure

A single DMZ breach exposes every asset on both sides of the boundary. Adding new connections requires firewall rule changes that lag weeks behind operations.

Everything Funnels Through One Bottleneck

Vendor access, IIoT telemetry, and cloud sync all share the same DMZ chokepoint. One overloaded boundary trying to broker all IT/OT traffic.

Visibility Ends at the DMZ

Lateral movement inside OT goes completely undetected. Once past the DMZ, attackers move freely across flat plant networks.

The Solution

Micro-DMZs. One Per Asset.

Replace the Shared DMZ with Per-Asset Boundaries.

Statt einer gemeinsamen DMZ für die gesamte Anlage erhält jedes OT-Asset seine eigene Grenze. Jede Micro-DMZ vermittelt den Nord-Süd-Zugriffspfad zum Asset und authentifiziert, prüft und protokolliert jede Sitzung. Der zyklische Verkehr zwischen Controller und I/O bleibt im Underlay; nur routbare Sitzungen aus Leitwarte, Engineering und von Dienstleistern laufen über das Overlay, sodass die Echtzeit-Regelschleife nie im Durchsetzungspfad liegt.

MICRO-DMZ ARCHITECTURE — ONE BOUNDARY PER ASSETMICRO-DMZPLC-1TAG-01MICRO-DMZHMI-2TAG-02MICRO-DMZRTU-3TAG-03MICRO-DMZSIS-4TAG-04MICRO-DMZSCADATAG-05MICRO-DMZHISTTAG-06VENDOROPERCLOUDXXXXMICRO-DMZ STATUS6 ASSETS PROTECTED0 LATERAL PATHSPROXIES: ACTIVEISOLATION: 100%
Why Micro-DMZs

Five Reasons to Move Beyond Purdue.

Zero Lateral Movement

MICRO-DMZPLC-1ISOLATEDMICRO-DMZHMI-2ISOLATEDMICRO-DMZRTU-3ISOLATEDMICRO-DMZSIS-4ISOLATEDMICRO-DMZSCADAISOLATEDMICRO-DMZHISTISOLATEDXXXXXXXLATERAL PATHS: 0ALL ASSETS ISOLATED
Whitepaper

Download the Full Whitepaper.

Get the complete analysis: why the Purdue Model breaks, how Industrial DMZs fail to scale, and the technical architecture behind Micro-DMZs.

Fertig

What You'll Learn

Why the five-level Purdue hierarchy fails against modern threats. How remote access, IIoT, and cloud analytics erode every security boundary.

12 pages

The Micro-DMZ Architecture

Technical deep-dive into asset-level proxy boundaries. How to deploy Micro-DMZs incrementally without network redesign.

Request a Demo
FAQ

Common Questions About Micro-DMZs.

1

boundary per asset. Micro-DMZs replace the shared Industrial DMZ with dedicated, identity-aware proxies at every OT endpoint.

No. The Purdue Model remains a useful reference architecture for understanding OT network layers. Micro-DMZs evolve its security intent, isolation and controlled access, by enforcing boundaries at the asset level instead of relying on a single shared DMZ at Level 3.5.

Micro-segmentation typically means adding VLANs or firewall rules to limit lateral movement within a flat network. Micro-DMZs go further: each asset gets a dedicated proxy that authenticates, inspects, and logs every connection. It's not just network isolation, it's identity-aware, protocol-aware access control per device.

Ja. Die Platzierung ist eine bewusste, standortspezifische Entscheidung. Standardmäßig läuft Access Gate als Overlay neben dem Asset und vermittelt die Sitzungen, die es erreichen; wo eine stärkere, nicht umgehbare Durchsetzung erforderlich ist, kann es inline als transparenter Punkt im Datenpfad eingesetzt werden. In beiden Fällen wird nichts auf dem Asset installiert, sodass ältere PLCs, HMIs und SCADA-Systeme, die keine moderne Sicherheitssoftware ausführen können, ohne Änderung geschützt werden. Der Proxy vermittelt die Sitzung und führt die Authentifizierung durch; der Controller sieht die Authentifizierung nie und wird nie verändert.

Each vendor session is authenticated and scoped to a specific asset. No shared VPN tunnel, no broad network access. The vendor connects through the asset's Micro-DMZ proxy, which enforces time-limited, audited, protocol-level access, then closes the session automatically.

IIoT devices connect through their own Micro-DMZ proxy, which controls and inspects outbound telemetry. Cloud connectivity is allowed per policy, specific endpoints, specific protocols, specific schedules, without exposing the broader OT network to internet-facing attack surfaces.