Industrial Segmentation Use Cases¶
Remote vendor microsegment¶
A vendor receives a dedicated access domain and may monitor only the assigned package unit. Control, configuration, unrelated assets, and peer sessions remain unavailable. Every permitted and blocked industrial operation is linked to the vendor session.
The domain is carried over an authenticated encrypted tunnel, allowing isolation to be introduced without extending one shared remote-access segment to every vendor.
Protection-engineering access¶
A protection engineer may reach designated relays and perform reviewed maintenance operations during an approved window. General browsing of the field network and control of unrelated bays are restricted.
Production-cell containment¶
Each production cell remains a separate communication domain. Required supervisory and inter-cell flows cross managed enforcement points; unexpected controller-to-controller communication or prohibited industrial operations are recorded or blocked.
Substation bay or feeder enclave¶
Equipment associated with one bay or feeder is grouped as a protected industrial enclave. Access can differ for SCADA operations, protection engineering, field service, and commissioning while retaining one evidence model.
Commissioning microsegment¶
A temporary, time-bounded domain provides access to test equipment and the systems under commissioning. Policies permit the required test sequence, record deviations, and allow the domain or sessions to be removed after acceptance.
Quarantine and recovery¶
A suspicious or recovering user, site, or device is moved into a restricted domain with limited diagnostic communication. Recovery operations are recorded and broader industrial authority is restored only after review.
Site-to-site least privilege¶
Only approved communication between designated systems is carried across the site connection. L2Proxy policies distinguish ordinary monitoring from consequential control, configuration, and recovery activity.
Lateral-movement investigation¶
Operations and OT security review new destinations, unknown assets, unexpected protocol use, session-to-session communication, denied operations, and stateful deviations to identify activity outside the approved industrial purpose.