Glossary
/
OT Security Concepts

Network Segmentation

Also known as:
Zones and conduits · network separation · micro-segmentation

Network segmentation divides a network into security zones grouping assets with shared security requirements, with controlled conduits between them. In IEC 62443 terms, segmentation limits how far an intrusion can spread; a policy violation is traffic crossing zones in a way the operator has not permitted.

How it works

Assets are grouped into zones by function and criticality, for example an interlocking zone, a maintenance zone and a corporate zone. Communication between zones is only allowed through defined conduits, enforced by firewalls, VLANs, data diodes or physical separation, with rules specifying which protocols and endpoints may traverse each conduit.

Because operational reality drifts from design, segmentation must be continuously validated: observing actual traffic between zones and flagging flows that violate the intended policy.

Why it matters for security

Segmentation is the primary control that keeps an IT-side compromise from reaching signaling, and it is explicitly required by IEC 62443, TSA directives and NIS2-derived regulation. Validating that segmentation works in practice, not just on paper, is a core function of rail OT monitoring.

Related solution

Aligning rail OT security with IEC 62443-3-3

Validating zones and conduits against the traffic that actually flows between them.

See the solution →

Related terms

Ready to protect your rail?

Our specialists will help you back on track

Talk with an Expert