TroutTrout
Solutions / OT Segmentation

OT network segmentation. Without rewiring.

OT network segmentation puts each machine in its own zone and decides what may talk to it. Trout Access Gate does that from one on-premise appliance that plugs into the network you already have. Nothing is re-addressed, no switch is reconfigured, and production keeps running while the zones go in.

Last updated:

Trusted by leading companies

John CockerillOrange CyberdefenseElna MagneticsThales
OT NETWORK — ZERO-TRUST WITH ACCESS GATELIVEMPLS, APN, TUNNELSINTERNET / WANSITE BFIREWALL / ROUTERphysical wireLANZERO-TRUST OVERLAYVLANTagged & TrunkSECURITYAuth, Encryption, ACLOT SERVICESDNS, NTP, Protocol Gateway,Remote AccessACCESS GATEIT CLIENTIT SERVERZONE A OTZONE B OTDesktopDesktopDesktopDesktopIT SERVICESApps, SIEM, etcHMISensorDesktopPLCHMISensorPLCDesktop
Defense in Depth Limits

Why segmentation stalls on a live plant.

Most sites can describe the segmentation they want. The obstacle is that retrofitting it onto a running network means re-addressing equipment that cannot be taken offline. For the levels themselves and where the hierarchy stops matching real traffic, see <a href="/resources/purdue-model">the Purdue Model guide</a>.

The IT/OT boundary is the junction attackers aim for. It is also becoming more brittle with increased digitalization. Remote maintenance and cloud-bound data flows are prime examples of challenges to Purdue and segmentation efforts.

The result is that most sites stay flat or only partly segmented, not because operators do not know the model, but because retrofitting it onto a live network is too disruptive.

IEC alignment

IEC 62443 Zones and Conduits.

In IEC 62443: a zone is a grouping of assets that share the same security requirements and a common Security Level. The standard defines four, from SL1 (protection against casual or coincidental violation) to SL4 (protection against a state-level actor with extended resources). A conduit is the controlled communication path between two zones.

The hard part is implementing conduits on a network that is already running, which traditionally means a VLAN redesign: re-addressing equipment, reconfiguring switches, and taking production down for the cutover. For most operators, that downtime is the blocker that keeps a flat network flat for another year.

How the approaches compare

Flat, VLAN, firewall zones, or an overlay.

OT segmentation approach
Flat network
Enforcement point
None
Rewiring / downtime
None
Lateral movement
Unrestricted
Audit trail
None
OT segmentation approach
VLAN only
Enforcement point
Layer 2 isolation
Rewiring / downtime
Switch reconfig
Lateral movement
Inter-VLAN routing open
Audit trail
None
OT segmentation approach
Firewall zones / iDMZ
Enforcement point
Zone firewalls
Rewiring / downtime
Re-addressing, downtime
Lateral movement
Blocked at the zone edge
Audit trail
At the boundary
OT segmentation approach
Access Gate overlay
Enforcement point
Per-asset, identity-based
Rewiring / downtime
None (adjacent overlay)
Lateral movement
Blocked per asset
Audit trail
Every session recorded
How Access Gate deploys

OT Cybersecurity without a network redesign.

PHASE 1

Connect Access Gate to the Network

Access Gate deploys alongside the existing network in an aggregation or lollipop architecture. No VLAN changes. No agents on PLCs or OT endpoints.

PHASE 2

Zero Trust consolidation.

The overlay becomes the new Zero Trust fabric. Migration runs at about 10 systems per hour through the Access Gate proxy, so a 100-system site is done in a single day. IT admins and OT operators manage policy through role-based access in a shared UI.

Deployment

Access Gate adapts to your network

Pick your environment to see where the Access Gate sits, how much Zero-Trust coverage you get, and the migration path, from full coverage to partial coverage.

Access Gate: deploy Zero-TrustSelect an option to highlight its path
See the full deployment guide

Trusted by industrial and critical infrastructure operators.

Saint-Gervais Domaine Skiable
55

distributed sites protected across harsh operational environments, securing critical infrastructure without agents or downtime.

Read the case study

Trusted by leading companies

Thales
Orange Cyberdefense
Carahsoft
John Cockerill
NeverHack
Kyron
Eden Cluster
Airicom
Skynopy
Frequently asked questions

OT network security, answered.

6

Purdue, IEC 62443 zones, multi-site policy, and the two-phase Access Gate deployment

The Purdue model is the reference layout for an industrial network: the process at the bottom, control above it, supervision above that, then site operations and the enterprise. Segmentation follows those layers. The full walkthrough, level by level, is in our guide to the Purdue model at /resources/purdue-model.

IEC 62443 formalises Purdue-style segmentation into two constructs. A zone is a grouping of assets that share the same security requirements and a common Security Level (SL1 to SL4). A conduit is the controlled communication path between zones. It sets and enforces exactly which traffic may cross a zone boundary, and under what conditions. Without conduits, a zone diagram is theoretical: any device can still reach any other.

Access Gate deploys in two phases. In Phase 1 it sits adjacent to the existing network at the Level 3 / DMZ boundary and creates a Zero Trust overlay across the Purdue zones. No VLAN reconfiguration, no agents on PLCs or OT endpoints, no production downtime. Visibility and identity-based access control are immediate. In Phase 2 that overlay becomes the new Zero Trust fabric as systems migrate behind the gate, with no forklift replacement of switches.

Phase 1, the adjacent overlay, is live in hours, not months. Phase 2 migration runs at about 10 systems per hour through the Access Gate proxy, so a 100-system OT environment is done in roughly a single working day. Compare that with the months a traditional VLAN redesign and consolidation project takes, most of which is change-control and validation, not the cutover itself.

NIS2 Article 21 does not name IEC 62443 explicitly, but its technical measures (network segmentation, access control, logging) map directly onto the zone-and-conduit model. National guidance for OT operators, including ANSSI guidance in France, treats IEC 62443 as the recognised technical implementation standard for those obligations, so building to IEC 62443 zones is the practical route to demonstrating Article 21 segmentation.

Access Gate provides central policy management across every site from a single role-based UI. Each site deploys independently in Phase 1, with no cross-site interdependency and no big-bang cutover. From day one of Phase 2, the sites roll up into one unified Zero Trust fabric. IT admins set enterprise-wide policy while OT operators keep site-level control, so a 50-site group runs a consistent IEC 62443 zone posture without sending a network team to every plant.

OT (operational technology) security protects the industrial systems that run physical processes: PLCs, HMIs, SCADA, and the legacy servers behind them. Unlike IT security it cannot rely on endpoint agents or frequent patching, so Access Gate enforces identity, segmentation, and monitoring at the network layer with a Zero Trust proxy in front of each asset, no agents and no downtime.

IT security defends data and user devices, where agents, patches, and reboots are routine. OT security defends availability and safety on equipment that often cannot be patched, agented, or taken offline. Access Gate adds Zero Trust access, microsegmentation, and audit at the network layer instead of on the device, so protection does not disrupt production.