October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
cybersecurity

OT and IoMT Network Segmentation: Where Security Breaks Down and How to Reduce Risk

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

OT and IoMT network segmentation reduces unnecessary communication between systems and can limit how far an attacker moves after compromising an endpoint. It works only when zones reflect operational needs and the traffic between them is defined, filtered, and monitored. A generic diagram or firewall alone is not a safe design for a live industrial or clinical environment.

What network segmentation does in OT and IoMT

Segmentation divides a network into separate physical or logical areas and restricts communication between them. In operational technology (OT), those boundaries can reduce paths from business IT systems to industrial control systems. In healthcare, they can separate IT and operational technology assets, including connected medical devices, while controlling traffic that must cross between segments.

The security value is not simply that systems occupy different network areas. The value comes from limiting which systems can communicate, over which paths, and for what operational purpose. If an endpoint is compromised, fewer permitted routes can make lateral movement more difficult; segmentation does not, by itself, prevent compromise or guarantee that an attacker cannot reach a critical system.

Where segmentation breaks down

IT and OT remain connected without a controlled boundary

CISA recommends separating IT and OT and using a demilitarized zone (DMZ) to avoid unregulated communication between them. CISA and NSA have warned that insufficient separation can put OT environments at risk and enable lateral movement. A connection that bypasses the intended boundary, or allows broad communication without a defined operational reason, weakens the separation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Zones exist, but allowed traffic is not defined

A zone boundary is not a policy by itself. If the organization has not specified which communications are necessary between zones, it cannot reliably distinguish expected traffic from unnecessary access. CISA guidance describes defining conduits between zones and filtering and monitoring traffic that crosses them.

Traffic crosses boundaries without effective filtering or monitoring

Firewalls, gateways, and proxies are among the approaches CISA identifies for controlling cross-zone communication. Their presence is not proof that a boundary is effective: the rules must match the intended conduits, and traffic needs appropriate monitoring. A control that permits broad, unreviewed communication can leave the network functionally porous.

Devices bridge segments or policy is not followed

CISA’s StopRansomware guidance identifies devices that bridge multiple segments and non-adherence to segmentation policy as ways controls can be undermined. A device with connections to more than one zone may provide a path around the intended boundary if its role and communications are not accounted for. Network diagrams and policies should therefore be checked against the connections that actually exist.

Plan zones and conduits around operational risk

CISA recommends assigning OT assets to logical zones based on criticality, consequence, and operational necessity. That makes segmentation a risk and engineering exercise, not a task of placing every device into an arbitrary set of network groups. CISA’s OT advisory describes proxies, gateways, firewalls, and multiple Purdue-style levels and zones as possible implementation approaches; it does not make one diagram suitable for every site.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Inventory assets. Build and maintain an inventory, recording each asset’s role, why it is exposed, and its support status. CISA’s OT guidance emphasizes understanding the assets before deciding how to protect them.
  2. Map dependencies and required communications. Identify which systems need to exchange traffic to support the process. Involve people responsible for operating and maintaining the environment so that necessary dependencies are not mistaken for unnecessary access.
  3. Set zones using risk and operational need. Group assets in a way that reflects their criticality, the consequences of disruption or compromise, and the communications their function requires. Treat the resulting zones as a planning model to validate, not a universal template.
  4. Separate IT and OT, and plan the DMZ. Use a controlled intermediary boundary for necessary communication rather than an unregulated IT/OT connection. Specify what the DMZ is meant to permit before implementing rules.
  5. Define and enforce conduits. For each permitted path between zones, document its operational purpose and the traffic that is acceptable. Use appropriately configured firewalls, gateways, proxies, or equivalent controls to filter it.
  6. Monitor boundary traffic. Review traffic crossing conduits so that unexpected communication can be identified. A boundary that filters but is not observed offers less ability to spot policy drift or suspicious use.
  7. Review remote access and exposed connections. Examine vendor and other remote pathways as part of the boundary plan. CISA’s OT advisory calls for device control lists when possible and regular inventory of internet-accessible devices.
  8. Validate changes with operational stakeholders. Check that the proposed controls preserve necessary process functions and are supportable before relying on them. CISA cautions that its segmentation infographic is not a production engineering diagram; its principles require site-specific engineering and validation.

Choose an enforcement approach the organization can manage

Physical and logical segmentation are both recognized approaches, and the guidance does not prescribe one universal winner. VLANs, access control lists (ACLs), DMZs, firewalls, and gateways appear among the identified mechanisms. The relevant choice depends on the boundary an organization needs to enforce and its ability to operate and validate the control.

Approach What distinguishes it Questions to resolve before relying on it
Physical segmentation Uses physical separation between network areas. Does the separation match required resilience and operational needs, and can the organization manage and validate it?
Logical segmentation Separates areas through logical controls; VLANs and ACLs are among the mechanisms identified in the guidance. Are boundaries and permitted communications clearly defined, enforced, and monitored?

Macro-segmentation establishes broader zone boundaries; microsegmentation applies boundaries to smaller groups of resources. CISA’s July 29, 2025 release on zero-trust microsegmentation is planning-oriented and aimed at federal zero-trust implementation, while stating that its principles can apply more broadly. It is not a site-specific OT or medical-device design.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Apply the principle carefully to healthcare and IoMT

CISA’s Healthcare and Public Health Sector Mitigation Guide recommends placing IT and OT devices on different segments and controlling communication between segments. That is a useful baseline for network segmentation involving connected medical devices, but it does not establish one universal VLAN pattern or architecture for every IoMT device.

Device-specific clinical workflows, manufacturer support, and safety constraints need to be considered when defining zones and allowed conduits. The available guidance does not settle those requirements for every device or care setting, so a blanket rule to isolate all medical devices in the same way is not justified. Healthcare teams should validate proposed boundaries and traffic rules with the people responsible for clinical operations and device support.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why segmentation must sit inside a wider security plan

CISA’s January 2022 infographic, “Layering Network Security Through Segmentation,” states: “Segmentation is not the only tool to secure a network.” It explains that multiple security layers increase the difficulty of reaching control systems and warns against treating the infographic as a production design. Segmentation should therefore complement—not replace—asset visibility, operational review, and other security controls.

Do not treat procurement of an industrial firewall or OT security gateway as completion of the work. CISA guidance identifies these categories as possible ways to filter or restrict cross-zone traffic, but selecting equipment requires attention to the specific process, protocols, performance, safety, and support needs. A product cannot decide which communications are operationally necessary or validate that a proposed boundary is safe.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.