Operational technology networks
Connect the machinery without disturbing the processAsset discovery, approved data paths, industrial switching, remote access, monitoring, backups, maintenance windows, testing, and rollback, all with process-owner approval.
What Operational technology networks includes
Operational technology includes programmable systems and devices that interact with the physical environment, such as industrial controls, building automation, transportation, utilities, physical access, and environmental monitoring. Their safety, timing, reliability, and availability needs can differ materially from office IT.
An OT project should begin with asset and data-flow discovery performed without disrupting production. Architecture, segmentation, monitoring, patching, remote access, backups, and incident response must be coordinated with process owners and equipment vendors.
Question to answer before designWhich physical process depends on each connection, when can it be changed, and how will operation be restored if the change causes a problem?
This service may fit when:
- Controls, building systems, cameras, vendors, and office devices share a flat undocumented network
- Remote vendor access uses permanent shared credentials or unmanaged consumer hardware
- No one can produce current asset, firmware, network, backup, or communication-path records
- Changes are made without a process owner, maintenance window, backup, test, or rollback
What the system includes
A complete scope covers each part below and the connections between them.
Process and assets
Controllers, sensors, actuators, HMIs, servers, building and physical systems
Zones and conduits
Criticality boundaries, industrial links, approved protocols and data paths
Controlled access
Identity, jump path, vendor session, least privilege, logging and approval
Operations and recovery
Monitoring, time, configuration backup, spares, change window, rollback and incident plan
How site information becomes a tested project
A complete project record connects the conditions found on site, the design decisions made from them, and the tests and closeout documents delivered afterward.
What we confirm before design
- Process, safety, availability, timing, environmental, regulatory, and maintenance-window constraints
- Assets, firmware, protocols, addresses, criticality, owners, vendors, and lifecycle status
- Current and required data flows, zones, remote access, identity, time, logging, and monitoring
What those findings determine
- Discovery: Use only methods the process and equipment owners approve for the operational risk.
- Segmentation: Architecture follows safety, process function, criticality, protocol, vendor, and recovery.
- Remote access: Define approver, device, user, time, destination, logging, revocation, and emergency exception.
What you should receive
- Approved OT asset, owner, version, criticality, and communication inventory
- Current and target zone/conduit architecture and policy matrix
- Remote-access, identity, monitoring, time, backup, change, and rollback design
The exact inputs, decisions, and acceptance records depend on the site and signed scope.
Project stagesSurvey through closeoutView details
How the work moves from survey to closeout
Each stage should produce the records and test results needed before the next stage begins.
- 01
Discover without disruption
Coordinate with process and safety owners; inventory assets, versions, protocols, dependencies, vendors, data flows, remote paths, network equipment, time, backups, and allowable methods.
EvidenceOwner-approved asset and communication inventory, current topology, criticality, maintenance constraints, and discovery limitations. - 02
Design zones and controlled paths
Define security zones, conduits, industrial switching, routing, firewall policy, remote access, identity, logging, time, redundancy, monitoring, configuration backup, and recovery.
EvidenceTarget architecture, approved communication matrix, access model, equipment and resilience schedule, backup plan, test plan, and rollback criteria. - 03
Change in approved windows
Back up configurations, stage equipment, pretest rules, label connections, implement an approved segment at a time, observe process state, and retain a working rollback path.
EvidencePre-change backup checks, labeled assets and links, change log, owner observations, configuration record, and rollback readiness. - 04
Validate process and recovery
Confirm approved communications, blocked paths, latency-sensitive functions, alarms, time, redundancy, monitoring, remote access, configuration restoration, and process-owner acceptance.
EvidenceCommunication and segmentation test results, process acceptance, monitoring events, remote-access audit sample, restoration test, and exceptions.
Design choicesCompare the available approachesView details
How to choose the right approach
The right choice depends on the site, application, operating risk, and acceptance requirements. More equipment does not automatically improve the system.
What we need to know
- Process, safety, availability, timing, environmental, regulatory, and maintenance-window constraints
- Assets, firmware, protocols, addresses, criticality, owners, vendors, and lifecycle status
- Current and required data flows, zones, remote access, identity, time, logging, and monitoring
- Industrial media, distances, redundancy, enclosures, power, grounding, spares, and support
- Configuration backups, restore method, test environment, change approval, validation, rollback, and incident response
What you should receive
- Approved OT asset, owner, version, criticality, and communication inventory
- Current and target zone/conduit architecture and policy matrix
- Remote-access, identity, monitoring, time, backup, change, and rollback design
- Communication, segmentation, process, monitoring, and restoration acceptance evidence
- Labeled as-builts, configuration archive, exception register, and operating runbook
Equipment examplesSee relevant hardwareView details
Hardware that may be part of the project
These examples are not a final bill of materials. We confirm compatibility, availability, and the exact model after the requirements are clear.

UCG-Ultra
Router, firewall & UniFi controller for 30+ devices / 300+ clients, 1 Gbps IPS routing
Equipment planning price $170 ↗
UCG-Max
2.5G gateway & controller, 30+ devices / 300+ clients, 2.3 Gbps IPS routing, built-in NVR bay
Equipment planning price $400 ↗
UDM-Pro
10G rackmount gateway & controller, 100+ devices / 1,000+ clients, 3.5 Gbps IPS routing
Equipment planning price $500 ↗
UDM-Pro-Max
10G gateway, 200+ devices / 2,000+ clients, 5 Gbps IPS routing, dual NVR-ready storage
Equipment planning price $800 ↗
USW-Lite-8-PoE
8-port PoE switch, fanless, 52W total PoE budget
Equipment planning price $150 ↗
USW-Lite-16-PoE
Wall-mountable 16-port PoE switch, fully passive fanless cooling
Equipment planning price $260 ↗When this service makes sense
- Manufacturing, utilities, buildings, transportation, warehouses, and critical facilities
- Sites with a named process owner and approved maintenance windows
- Organizations separating IT and OT responsibilities without isolating communication
- Programs that need asset inventory, network boundaries, remote access, and recovery evidence
What we verify first
- OT changes can affect safety, production, warranties, validated processes, and vendor support; process-owner approval is required
- Active discovery, vulnerability scanning, failover, patching, or restoration tests can disrupt fragile equipment and must be explicitly approved
- Legacy protocols and devices may lack modern authentication, encryption, logging, or patch paths
- Security improvements must preserve required deterministic behavior, local control, safe states, and recovery
Site contextSee where this work is usedView details
How site conditions change the design
Occupancy, operating hours, user activity, regulation, weather, construction, and access can change the design.
What people usually ask
Why not scan the OT network like office IT?
Some legacy or fragile devices can be affected by unexpected traffic. Discovery methods, timing, rate, credentials, targets, monitoring, and abort criteria require process-owner and vendor-aware approval.
Does segmentation mean physically isolated?
Not always. Physical separation is one option. Zones and conduits can also use switching, routing, firewalls, identity, and monitored policies, chosen around process and risk requirements.
How should vendors access OT?
Through a named, approved, time-limited path to specific assets with strong authentication, limited permissions, logging, rapid revocation, and a documented emergency exception, subject to platform capability.
Standards and referencesReview the source materialView details
Sources used for this guide
These references inform the guide. The adopted code, engineer of record, authority having jurisdiction, manufacturer instructions, and signed agreement control the project.
Defines OT and provides guidance that accounts for performance, reliability, safety, topology, threats, vulnerabilities, and controls.
Open reference ↗International Society of Automation · reviewed 2026-08-20ISA/IEC 62443 Series of StandardsDescribes consensus standards for secure industrial automation and control systems across asset owners, service providers, and product suppliers.
Open reference ↗Cybersecurity and Infrastructure Security Agency · reviewed 2026-08-20Cross-Sector Cybersecurity Performance GoalsProvides voluntary high-impact security outcomes for IT and OT, organized around Govern, Identify, Protect, Detect, Respond, and Recover.
Open reference ↗

