Skip to content
Client access

OT/ICS

IT/OT segmentation in mining: where to start

The convergence of corporate and industrial networks opens paths an attacker can exploit. A six-step roadmap to bring order with IEC 62443 without stopping operations.

Kamaya Secure team 4 min read

In a mining operation, the industrial network controls physical processes: crushing, grinding, flotation, conveyor belts, pumping, tailings. For years that network was isolated by design. It no longer is. Dispatch systems, the process historian, production reporting and vendor remote support all need real-time plant data, and each of those needs opened a connection between the corporate network (IT) and the operations network (OT).

The problem is not the connection itself, but that in many cases it grew without an explicit design. The result is a “flat” network where a compromised office computer can reach an engineering workstation or a plant controller in just a few hops.

Key takeaways

  • IT/OT segmentation does not start with a firewall, but with an inventory of assets and traffic flows built without disrupting operations.
  • The IEC 62443 zones and conduits model groups assets by criticality and controls every communication between them.
  • An industrial DMZ should be the only exchange point between IT and OT: nothing should cross directly.
  • Changes are rolled out in stages and in monitor mode before blocking, coordinated with operations and maintenance.

Why a flat network is an operational risk

Three paths come up again and again in industrial assessments:

  • Vendor remote access set up for an emergency and never removed, sometimes with shared credentials or no second factor.
  • Dual-homed machines: engineering workstations, historian or reporting servers with one network card in IT and another in OT, acting as a bridge.
  • Shared services —Active Directory, antivirus, updates— that cross the boundary without control and extend corporate network risks into the plant.

On top of this, OT has a characteristic of its own: many controllers and industrial protocols (Modbus TCP, EtherNet/IP, PROFINET, OPC) were designed without authentication or encryption. If an attacker reaches the control network, they can often send valid commands without exploiting any vulnerability at all.

In OT, the priorities are availability and people’s safety. That is why segmentation is designed with operations, not against them.

Step 1: know what you have

Without an inventory, segmentation is not possible. For each OT asset, the inventory should record its role in the process, location, vendor and model, firmware version, the protocols it uses and what it talks to.

In industrial environments the inventory is best built with passive monitoring: traffic is copied through mirror ports (SPAN) or network TAPs and analyzed without sending a single packet to the devices. Traditional active scans can overload or stop legacy controllers, so they are used only selectively, in coordination with operations and during maintenance windows.

Step 2: map the real traffic flows

The second deliverable is a communications map: which system talks to which, over what protocol and for what purpose. This map often reveals flows nobody remembered, such as a corporate server querying a controller directly or an outbound internet connection from an engineering workstation. Every flow should have an owner and a business justification; those that do not are candidates for removal.

Step 3: define zones and conduits

IEC 62443 groups assets into zones with common security requirements and controls every communication between zones through defined conduits. A reasonable starting split for mining, based on the Purdue reference model, could be:

ZoneExamplesCriticality
Corporate (IT)Email, ERP, office workstationsMedium
Industrial DMZHistorian replica, jump server, patch repositoryHigh
Plant operationsSCADA, HMI, primary historian, engineering workstationsVery high
Process controlCrushing, grinding, flotation and tailings controllersCritical
Functional safetySafety instrumented systems (SIS)Critical

IEC 62443-3-2 describes how to assess risk in order to define these zones, and IEC 62443-3-3 sets out the system security requirements and the security levels (SL) each zone should reach. NIST SP 800-82 Rev. 3 is a good practical companion.

Step 4: build the industrial DMZ

The core rule is that no flow crosses directly from IT to OT or the other way around. Every exchange terminates in the industrial DMZ:

  • The corporate network queries a replica of the historian, not the plant historian.
  • Patches and antimalware signatures are downloaded to a repository in the DMZ and distributed to OT from there, after validation.
  • Remote access lands on a jump server in the DMZ, with multi-factor authentication, recorded sessions and per-event approval.

Step 5: control third-party remote access

Vendor access deserves its own controls: named accounts (never shared), access enabled only during the approved work window, session logging and periodic review of who still has access. It is one of the changes with the best ratio of effort to risk reduction.

Step 6: roll out in stages and verify

To avoid stopping operations:

  1. Deploy the controls between zones first in monitor mode, logging what would be blocked without blocking it.
  2. Review the logs with operations and maintenance to confirm that every required flow is covered.
  3. Enable blocking zone by zone, during maintenance windows and with a rollback plan.
  4. Verify with a controlled OT penetration test that segmentation actually closes the paths it was meant to close.

Common mistakes

  • Buying an industrial firewall before building the inventory and the flow map.
  • Allowing “any traffic” between IT and OT temporarily and never revisiting it.
  • Treating the functional safety (SIS) network as part of the general control network.
  • Leaving segmentation to IT alone, without the operations and maintenance teams.
  • Not reassessing after a plant expansion or a change of vendor.

How we can help

At Kamaya Secure we support this process end to end: passive inventory, flow mapping, zone and conduit design aligned with IEC 62443, and controlled testing that validates the segmentation, always coordinated with your operations team. Learn more about our OT/ICS Security service and how we work with the Mining industry.

Insights

More insights

Kamaya Secure logo on an office wall

Want to apply this in your organization?

Tell us where you are today. Our team will help you define the right scope and next steps, with no commitment.

Chat on WhatsApp (opens in a new tab)