Purdue Model
The Purdue Model is a reference architecture for industrial control networks, arranging systems into levels from Level 0 (physical process and sensors) through Levels 1 to 3 (control, supervision and operations) to Levels 4 and 5 (enterprise IT). It is a common basis for segmenting OT from IT.
How it works
Level 0 holds the physical devices: sensors and actuators. Level 1 holds the controllers that operate them (PLCs, object controllers, interlockings). Level 2 holds supervisory systems such as HMIs and SCADA. Level 3 holds site-wide operations systems. Levels 4 and 5 are the business and enterprise networks. A demilitarized zone (Level 3.5) typically separates OT from IT.
In rail, the model is applied loosely: interlockings and object controllers sit at Levels 1 and 2, control-centre systems at Level 3, and corporate IT at Levels 4 and 5, with onboard systems forming their own hierarchy.
Why it matters for security
The Purdue Model provides a shared vocabulary for deciding where security boundaries belong and which traffic should never cross them. Traffic that skips levels, such as a corporate host talking directly to an interlocking, is a classic indicator of misconfiguration or compromise.
Related solution
Building a rail security operations center
Seeing traffic that crosses levels it should not, and acting on it rail-safely.
See the solution →

