Network Segmentation
Network segmentation divides a network into security zones grouping assets with shared security requirements, with controlled conduits between them. In IEC 62443 terms, segmentation limits how far an intrusion can spread; a policy violation is traffic crossing zones in a way the operator has not permitted.
How it works
Assets are grouped into zones by function and criticality, for example an interlocking zone, a maintenance zone and a corporate zone. Communication between zones is only allowed through defined conduits, enforced by firewalls, VLANs, data diodes or physical separation, with rules specifying which protocols and endpoints may traverse each conduit.
Because operational reality drifts from design, segmentation must be continuously validated: observing actual traffic between zones and flagging flows that violate the intended policy.
Why it matters for security
Segmentation is the primary control that keeps an IT-side compromise from reaching signaling, and it is explicitly required by IEC 62443, TSA directives and NIS2-derived regulation. Validating that segmentation works in practice, not just on paper, is a core function of rail OT monitoring.
Related solution
Aligning rail OT security with IEC 62443-3-3
Validating zones and conduits against the traffic that actually flows between them.
See the solution →

