EnterpriseConfigSchedule a Consultation
Back to services

Operational resilience

OT / ICS Security

OT security requires careful change control, visibility, and segmentation. The goal is to protect operations while respecting vendor support, safety, latency, and uptime requirements.

OT asset discovery and network mapping

Purdue-aligned segmentation and controlled IT/OT access

Secure remote vendor access with MFA and logging

Firewall policy, monitoring, and incident readiness for production networks

Fortinet Purdue model concept

IT/OT segmentation from enterprise to field devices.

A practical Purdue model view for separating enterprise IT, industrial DMZ services, site operations, supervisory control, basic control, and process networks.

Fortinet OT Purdue model reference architectureFORTINETSECURING THEPURDUE MODELA FortiGate OT Reference ArchitectureDEFEND EVERY LEVELComprehensive protectionacross IT and OT environmentsSEGMENT & CONTROLEnforce secure segmentationand access policiesVISIBILITY & THREAT DETECTIONEnd-to-end visibility from ITto industrial assetsBUILT FOR AVAILABILITYHigh availability, redundancyand industrial resilienceINTERNETISP AINTERNETISP BCLOUD SERVICESM365 / AWS / AzureBUSINESS APPSSaaS / CRM / ERPLEVEL 4-5ENTERPRISEBusiness systemsInternet accessPERIMETERIPS / SSL InspectionWeb FilteringDLP / Anti-MalwareLEVEL 3.5Industrial DMZPatch / AV / Jump hostHistorian / Data BrokerINDUSTRIAL DMZSecure ProxyJump ServerHistorianData Diode (Optional)LEVEL 3OperationsOperations systemsICS DMZICS DMZRemote Access VPNApplication ProxyData CollectionLEVEL 2Supervisory ControlSCADA / HMI / View / ControlOT SEGMENT PROTECTIONApplication ControlIPS for OT ProtocolsAllowlist / DenylistLEVEL 1Basic ControlPLCs / RTUs / IEDsINDUSTRIAL SWITCHINGRuggedized SwitchingVLAN / QoS / ACLRedundant TopologyLEVEL 0ProcessSensors / ActuatorsPhysical ProcessFortiGate 1800F(HA Primary)FortiGate 1800F(HA Secondary)HA HEARTBEATPLCHMII/OROBOT / ACTUATORCENTRALIZED MANAGEMENT& ANALYTICSFortiManagerCentralized ManagementFortiAnalyzerLogging & AnalyticsFortiSIEMEvent CorrelationFortiDeceptorThreat DetectionFortiNACNetwork Access ControlSecurity FabricIntegrated ProtectionMANAGEMENT NETWORKOut-of-Band MgmtDedicated admin pathMonitoringAvailability alertsRADIUS / ADAuthenticationSyslog / NTP / DNSShared servicesBackup ReportingRecovery recordsTRAFFIC FLOWSInternet / Cloud AccessIT / Enterprise TrafficOT / ICS TrafficManagement / MonitoringHA / HeartbeatKEY BENEFITSSECURE BY DESIGNDefense-in-depth across IT and OTHIGH AVAILABILITYRedundant firewalls and linksVISIBILITYClear view across the OT stackCOMPLIANCE READYSupports IEC 62443 and ISO 27001SCALABLE ARCHITECTUREGrowth-ready segmented designOPERATIONAL EFFICIENCYCentralized policy and reporting
Fortinet-style OT Purdue reference architecture with enterprise access, industrial DMZ, operations, supervisory control, basic control, process assets, centralized management, traffic-flow legend, and key benefits.

Segmentation and visibility

Industrial environments benefit from simple, documented boundaries that separate enterprise IT from production systems while preserving required flows.

  • Purdue model zoning for enterprise, DMZ, supervisory, control, and device networks.
  • Fortinet or Cisco firewall enforcement between IT, OT DMZ, engineering workstations, and PLC networks.
  • Passive discovery, switch monitoring, and traffic baselining before policy tightening.

Remote access and operations

Vendor and engineer access needs to be deliberate, temporary where possible, and fully logged.

  • VPN access with MFA, approval workflows, named users, and restricted destination policies.
  • Jump hosts, session recording options, and separate administrative credentials.
  • Maintenance windows, rollback planning, and documentation for operational teams.

Technology stack

FortiGateCisco Industrial EthernetOT DMZJump HostsMFAMonitoring

Next step

Discuss a design for your environment.

Share your current topology, pain points, cloud plans, and security goals. EnterpriseConfig can turn that into a practical design and implementation path.

Contact EnterpriseConfig