A Primer for Securing Modern OT Environments
Where OT differs from IT security, and how to segment without stopping production.




Why it is worth reading
Operational technology used to be air gapped - isolated from the internet and from other devices, which kept the attack surface small. That era is over: OT devices in manufacturing, utilities, healthcare and transportation are now smart and networked, and 40% of organizations in those sectors run OT devices with known exploited vulnerabilities that are insecurely connected to the internet.
This white paper is a primer on closing that gap. It explains how OT security differs from IT security, walks through the Purdue Model and where smart devices break it, and lays out three concrete steps: deploy a dedicated OT firewall, segment the OT network into zones, and replace VPN with ZTNA for remote access.
What is inside
- From air gap to attack surfaceWhy smart, networked OT and IIoT devices in manufacturing, utilities and healthcare can no longer rely on isolation.
- OT security vs. IT securityIT protects confidentiality, integrity and availability of data - OT puts system availability and physical safety first.
- The Purdue ModelHow segmenting industrial control systems into levels, with a buffer zone at level 3.5, keeps traffic predictable and defensible.
- Where smart devices break the modelDirect internet connections and wireless IIoT links bypass the air gap and open the door to lateral movement.
- Three best practicesA dedicated OT firewall for visibility, segmentation into five OT zones, and ZTNA instead of VPN for remote access.
The security of the Purdue Model is broken, for example, if a level-0 device connects to level 4 directly.Who it is for
- OT managers whose plants are no longer air gapped
- Security architects extending SASE into production environments
- CISOs in manufacturing, utilities, healthcare and transportation
Founded in Switzerland. Backed by Swiss Post.
Founded in Switzerland in 1990, Open Systems generates more than USD 100 million in annual revenue and supports global enterprise customers operating in more than 180 countries. Since 2024, the company has been part of Swiss Post, combining Swiss trust and stability with global reach. As a European alternative to US- and Israel-based cybersecurity providers, Open Systems is guided by strong principles around sovereignty requirements, regulatory alignment, transparency and shared responsibility - taking clear ownership for security, performance and operational outcomes, helping organizations maintain control in an increasingly complex digital landscape.
Autonomous SASE. AI-powered. Human-backed.
You might also like.
What to Consider in Your OT Security Provider Choice
The questions that separate real OT coverage from rebadged IT security.
Read more →ZTNA vs. VPN: Access Security for a Cloud-First World
Why identity-based access replaces the VPN, and how to get there without breaking daily work.
Read more →
Secure Access Done Right
How SSE and ZTNA work together on the way to a zero-trust setup.
Read more →