OT Network Segmentation

How Can I Prevent Lateral Movement from IT to OT — and Between OT Systems?

Ransomware doesn't teleport into your plant floor. It walks there — through your IT network, across your historian server, and into your PLCs. Zero-trust microsegmentation closes every door in that path before an attacker can use it.

70%

of OT breaches involve lateral movement

200+ days

Average attacker dwell time in OT before detection

$4.4B

Colonial Pipeline attack economic impact

What is BlastShield?

BlastShield is a zero-trust network access solution that helps organizations implement a zero-trust architecture.

Instead of relying on enhanced identity governance (EIG), complex layers of micro-segmentation, or cloud-based gateways, BlastShield utilizes a software-defined perimeter (SDP) approach for more granular access controls and reduced risk from stolen credentials and complex management.

Start a free trial

How Attackers Move from IT into OT Environments

Lateral movement — the ability for an attacker who has compromised one system to reach others — is the defining technique of every major OT cyberattack. The Colonial Pipeline ransomware attack, the Oldsmar water treatment intrusion, and the JBS Foods ransomware incident all share the same pattern: initial access in IT, followed by systematic movement into operational technology systems.

Typical IT-to-OT Ransomware Attack Path

1
Initial access: Phishing email, compromised VPN credential, or exposed RDP reaches an IT workstation
2
Credential theft: Attacker harvests credentials using Mimikatz, pass-the-hash, or Kerberoasting on the IT network
3
IT lateral movement: Attacker pivots through IT systems using stolen credentials, mapping network topology
4
IT/OT boundary crossing: Engineer workstation, historian server, or jump server provides network adjacency to OT network
5
OT reconnaissance: Attacker maps OT network — identifying PLCs, HMIs, historians, safety systems
6
OT lateral movement: Flat OT network allows attacker to move freely between industrial devices
7
Detonation: Ransomware deployed, OT systems encrypted, operations halted
The critical observation: if lateral movement is blocked at any point in this chain, the attack fails. The goal of OT microsegmentation is to collapse this attack path — to make each step impossible rather than just difficult.
The Problem

Your OT Systems Are Visible to Every Attacker on the Internet

Most OT networks were designed for operational reliability, not security isolation. The result is a "flat" network architecture where PLCs, HMIs, historians, engineering workstations, and IT-adjacent systems share unrestricted IP connectivity. Once an attacker reaches any point on this network, every other device is reachable.

The flat network problem: In a flat OT network, a compromised historian server — which must communicate with both IT and OT — has direct network adjacency to every PLC on the plant floor. For an attacker, this means a single successful pivot from IT delivers access to the entire OT environment.
Why Traditional IT Segmentation Tools Don't Work in OT
VLAN-based segmentation and perimeter firewalls solve parts of this problem — but not all of it. Their limitations in OT environments include:
  • VLANs are bypassed by shared services: Historian servers, engineering workstations, and remote access gateways often span VLANs by design — creating paths attackers can use.
  • Firewall rules expand over time: OT firewall rulesets become complex and difficult to audit. Overly permissive rules accumulate. The rule that was "temporary" in 2019 is still in production in 2026.
  • OT devices don't support 802.1X authentication: Most PLCs and RTUs cannot authenticate to a network access control system, making identity-based segmentation via traditional NAC impossible.
  • East-west traffic is invisible: Traditional segmentation tools focus on north-south (in/out of the network) traffic. Lateral movement is east-west — between devices on the same network — and often bypasses perimeter controls entirely.

Major OT Ransomware Attacks That Exploited Lateral Movement

Case Study

Colonial Pipeline (2021)

DarkSide ransomware entered via a compromised VPN account, moved laterally through IT systems, and forced Colonial to proactively shut down OT pipeline operations to prevent spread. 45% of East Coast fuel supply disrupted for 6 days.

Case Study

JBS Foods (2021)

REvil ransomware moved from IT into OT environments at the world's largest meat producer, forcing shutdowns of US, Australian, and Canadian processing plants. $11M ransom paid.

Case Study

Norsk Hydro (2019)

LockerGoga ransomware spread laterally through Hydro's global network into OT environments at aluminum smelting operations, forcing a switch to manual processes. $71M in damages.

Case Study

Oldsmar Water (2021)

Attacker accessed a water treatment plant's HMI via remote access software and attempted to increase sodium hydroxide to dangerous levels. The HMI had unrestricted network access to SCADA controls.

How to Prevent Lateral Movement from IT to OT: A Zero-Trust Approach

Stopping lateral movement requires removing the network paths that attackers travel. Zero-trust microsegmentation is the most effective current approach — it assumes that any IT system may be compromised, and denies it network access to OT assets unless explicitly and continuously authorized.
1

Eliminate Default Network Adjacency Between IT and OT

No IT endpoint should have network-layer access to OT devices by default. This includes engineering workstations, remote access solutions, historian servers, and any shared services. The IT/OT boundary should enforce a default-deny policy: no communication is permitted unless it is explicitly defined, authorized, and necessary. BlastShield enforces this without requiring VLANs or complex firewall rules.

2

Microsegment Within the OT Network Itself

Preventing IT-to-OT lateral movement is only half the solution. Once an attacker reaches any OT system — through a vendor laptop, a compromised remote access tool, or a breached historian — they must be prevented from moving between OT devices. Each OT zone (production line, utility systems, safety systems) should be isolated with explicit allow-rules for the communication it actually requires.

3

Protect the IT/OT Bridging Points: Historians and Jump Servers

Historian servers, engineering workstations, and jump servers are the natural crossing points between IT and OT. They must be treated as high-risk assets requiring the strictest access controls. No engineer's laptop should have direct RDP access to an engineering workstation with OT adjacency without going through explicit, logged, authenticated session controls.

4

Implement Zero-Trust for All OT Remote Access

Remote access — from engineers, vendors, and contractors — is one of the primary paths ransomware uses to enter OT environments. Replace VPN-based remote access (which grants broad network access upon connection) with zero-trust remote access that enforces least-privilege: each session grants access only to the specific OT device the user is authorized to reach, with no broader network visibility.

5

Monitor East-West Traffic Between OT Devices

Lateral movement traffic looks like normal IT activity — it uses legitimate protocols (SMB, RDP, WMI) and valid credentials. Detecting it requires understanding what "normal" east-west communication looks like in your OT environment and alerting on deviations. A PLC that suddenly initiates connections to other PLCs or to historian servers is exhibiting anomalous behavior that warrants immediate investigation.

The zero-trust principle for OT: Never trust a connection based on network location. An IP address inside the OT network is not a trusted identity. Zero-trust microsegmentation requires that every connection — even between adjacent OT devices on the same VLAN — be authorized based on verified identity and explicit policy.

How BlastWave Stops IT-to-OT Lateral Movement

BlastShield enforces zero-trust microsegmentation across the IT/OT boundary and within the OT network itself — without requiring network reconfiguration, device agents, or operational downtime. It works on every OT device, regardless of age, vendor, or operating system.
Identity-Based Access at Every OT Segment Boundary
BlastShield replaces implicit network trust with explicit identity-based access control. An engineer can only reach the OT assets their role explicitly permits. A historian server can only communicate with the PLCs that feed it. A vendor can only access the specific system they are contracted to maintain — and only during the authorized maintenance window. Every other connection is denied, logged, and alerted.
No Agents on OT Devices
BlastShield's microsegmentation does not require agents on OT endpoints. PLCs, RTUs, and HMIs are protected through network-layer policy enforcement — no firmware changes, no software installation, no device modification. Legacy devices with no ability to run modern software are fully included in the microsegmentation policy.
Instant Containment When an IT System Is Compromised
When an IT system is suspected of compromise, BlastShield can immediately revoke its network access to all OT segments — containing the threat before it can pivot into the industrial environment. This can be done in seconds, without changing firewall rules, modifying VLANs, or taking systems offline.

Frequently Asked Questions

How can I prevent lateral movement from IT to OT and between OT systems?

Deploy zero-trust microsegmentation that enforces identity-based access controls at every network boundary. Default-deny policies mean no IT endpoint has OT access unless explicitly authorized. Within the OT network, each zone is isolated so that a compromise in one area cannot automatically spread to adjacent systems. BlastShield implements this without requiring network reconfiguration or device agents.

What's the difference between IT-to-OT segmentation and OT microsegmentation?

IT-to-OT segmentation blocks traffic crossing the IT/OT boundary (typically enforced by DMZ, firewall, or jump server). OT microsegmentation goes further — it isolates individual devices and zones within the OT network itself. Even if an attacker bypasses the IT/OT boundary (via a compromised jump server, for example), microsegmentation prevents them from reaching adjacent OT devices. Both layers are necessary for comprehensive lateral movement prevention.

Can I prevent lateral movement without replacing my existing network infrastructure?

Yes. BlastShield's software-defined approach deploys as an overlay on your existing network — it does not require replacing switches, routers, or firewalls. Microsegmentation policy is enforced at the software layer, making it possible to deploy in days rather than the months or years a network hardware replacement would take.

How does ransomware spread between OT systems, and how do I stop it?

Ransomware spreads between OT systems using the same techniques as human attackers: credential reuse, SMB file shares, remote management protocols, and any other communication path available on the flat OT network. Stopping it requires removing those paths through microsegmentation — so that ransomware on one HMI cannot reach adjacent PLCs, historian servers, or other OT assets.

Does network segmentation satisfy NERC CIP and IEC 62443 requirements?

NERC CIP (Critical Infrastructure Protection) and IEC 62443 both require network segmentation and access control for OT environments. Specifically, NERC CIP-005 requires Electronic Security Perimeters for Cyber Assets, and IEC 62443 requires zone-and-conduit models with defined communication policies between zones. BlastShield's microsegmentation architecture aligns with and supports compliance with both frameworks.

How do I segment OT networks that include legacy devices that can't be updated?

No. BlastShield's Network Cloaking maintains full connectivity for authorized users while being invisible to unauthorized parties. Engineers, operators, and vendors retain the same remote access they depend on — the difference is that only authenticated users can see or reach the OT asset. Operational continuity is preserved; the attack surface is eliminated.

Related OT Security Problems

Preventing internet exposure is the first line of defense. These related pages address the additional layers of OT security BlastWave protects against:
Internet Exposure

How to Prevent OT Systems from Being Publicly Accessible

Make your ICS and SCADA systems invisible to internet scanners and attackers.

Legacy Systems

How to Protect Legacy OT Without Downtime

Shield vulnerable systems without requiring patches, firmware updates, or downtime.

Credential Security

How to Protect OT Devices from Weak Passwords

Eliminate default credentials that enable initial access and lateral movement.

Unknown Devices

How to Protect All OT Devices — Known and Unknown

Extend protection to every device on your network, including shadow OT.

Stop Ransomware at the IT/OT Boundary

See how BlastShield's zero-trust microsegmentation closes every lateral movement path between your IT and OT environments — with no network reconfiguration and no downtime.

Learn About OT Segmentation

Contact Us

Our Privacy Policy applies.