If your shop floor and your front office share one flat network, you are not alone. Plenty of small and mid-sized manufacturers across Chicagoland grew that way: a few PLCs and HMIs got plugged into the same switches as the accounting PCs, a machine vendor asked for a network drop, and over the years everything ended up on one big subnet. It works until it doesn’t. The fix is network segmentation, and it is one of the highest-value, lowest-drama upgrades a manufacturer can make.
This guide explains what OT/IT segmentation actually means, why it matters for a smaller plant, and how a project like this typically comes together without shutting down the line.
OT vs. IT: two networks with very different jobs
IT (information technology) is the world most people picture: email, file servers, accounting software, Wi-Fi for laptops and phones, printers. These devices get patched often, get replaced every few years, and expect fast internet access.
OT (operational technology) is the plant floor: PLCs, HMIs, CNC machines, robotic cells, sensors, drives, and the SCADA or line-control systems that tie them together. OT gear has a completely different personality. It runs for a decade or more, often on old operating systems that can’t be patched without vendor sign-off, and it cares far more about uptime and timing than about talking to the internet.
When you put both worlds on one flat network, the weakest device sets the security level for everything. A single infected laptop or a compromised email attachment can reach a control system that was never designed to defend itself. Manufacturing has been the most-targeted industry for ransomware and intrusions for several years running, precisely because downtime is so expensive that operators are tempted to pay. Flat networks are a big part of why those attacks spread so fast.
What segmentation actually does
Segmentation means splitting one network into separate zones so that traffic only crosses between them through a controlled checkpoint. Instead of every device seeing every other device, the plant floor and the office become distinct neighborhoods with a guarded gate in between. The benefits stack up quickly:
- Contain problems. A malware outbreak on the office side can’t jump straight onto the production VLAN.
- Protect uptime. A backup job or a big file transfer on IT won’t flood the network that your machines rely on for real-time control.
- Simplify troubleshooting. When the office and the floor are separate, it’s far easier to see where a problem lives.
- Support compliance. Customer audits, cyber-insurance questionnaires and frameworks like IEC 62443 increasingly expect OT/IT separation.
The Purdue model, in plain English
The industry reference for OT segmentation is the Purdue model. You don’t need to memorize it, but the core idea is worth borrowing: organize the network into layers, and let traffic flow only between adjacent layers rather than freely across all of them. At the bottom are the sensors and controllers; above them the line-control and supervisory systems; then a buffer zone; and at the top the business IT network and the internet.
The most important piece for a smaller manufacturer is that buffer zone in the middle, often called a DMZ. It sits between the plant floor and the office. When the office needs production data, or a machine needs a file, it goes through the DMZ rather than opening a direct path from the internet down to a controller. Controllers, as one rule of thumb goes, simply don’t need to talk to the internet.
You don’t have to boil the ocean
For a small plant, a full six-layer Purdue build can be overkill. A practical starting point is three zones: office/IT, a DMZ for shared services and remote access, and the OT network for the floor. That alone eliminates the most dangerous flat-network risks and gives you room to tighten things further later.
How a segmentation project comes together
Manufacturers worry that a network project means stopping the line. Done right, most of the work happens in parallel with production and cuts over in short, planned windows. Here’s the typical arc:
- Discovery. Walk the floor and inventory what’s actually connected, how devices talk to each other, and which machine vendors need remote access. On older lines this step alone often surfaces surprises.
- Zone design. Decide which devices belong in which zone and write the firewall rules that define what’s allowed to cross between them.
- Cabling and hardware. Many plants need cleaner structured cabling and managed switches before segmentation is even possible. Industrial-rated switches and proper cable pathways matter on a floor full of vibration, dust and EMI.
- Staged cutover. Move devices onto their new VLANs in planned windows, often over a weekend or between shifts, verifying each machine comes back clean.
- Documentation. Label the ports, map the VLANs, and record the firewall rules so the next person isn’t guessing.
Common mistakes to avoid
- Leaving remote access wide open. Machine vendors love permanent VPN tunnels straight into their equipment. Route that access through the DMZ and turn it on only when needed.
- Segmenting on paper only. VLANs without firewall rules between them are just labels. The enforcement is what protects you.
- Forgetting the wireless. Handheld scanners, tablets and guest Wi-Fi belong nowhere near the control VLAN.
- Skipping documentation. An undocumented segmented network is almost as hard to support as a flat one.
Where to start
If you’re not sure whether your plant is flat or segmented, that uncertainty is itself the answer — start looking. A short assessment of your current switching, VLANs and remote-access setup will tell you how big the gap is and what it takes to close it. From there, a phased business network installation plan lets you improve security without a disruptive rip-and-replace. The goal isn’t a perfect textbook architecture on day one; it’s steady, documented progress toward a plant floor that keeps running even when something goes wrong on the office side.
Ready to separate your plant floor from your office network?
RG Fiber designs and installs segmented business networks, industrial cabling and structured cabling for manufacturers across Chicagoland and the Midwest — planned around your production schedule, tested and documented.
Get a Free Quote Call 847-388-0808