Blackbird Cyber
Menu

Home / Capabilities / OT Network Architecting

OT Network Architecting

Purdue-aligned segmentation, industrial DMZ design and secure remote access, engineered around the process instead of on top of it.

ENGAGEMENT6–16 weeks
DELIVERYOn-site build
MAPPED TOIEC 62443-3-2 · Purdue

Scope

From the industrial DMZ to the controller.

We design the zones, build the conduits, write the rule sets and cut over during the windows you already have.

■Zone and conduit architecture per IEC 62443-3-2
■Industrial DMZ with brokered data flows only
■Firewall, ACL and industrial switch configuration
■Secure vendor and remote access with session recording
■Redundant ring topologies and cutover plans
Levels in scope
L5 / L4Enterprise
ERPEmailCorporate AD
Out of scope
L3.5Industrial DMZ
Jump hostPatch relayHistorian mirror
In scope
L3Site operations
HistorianEng. workstationDomain ctrl
In scope
L2Supervisory
SCADA serverHMIAlarm server
In scope
L1Control
PLCRTUSafety PLC
In scope
L0Process
SensorsActuatorsDrives
Out of scope

Engagement timeline

Design, build, cut over.

PH 1WK 1–3
DiscoverPassive capture and drawings. Every conversation on the wire, mapped.
PH 2WK 4–7
DesignTarget architecture, rule sets and a cutover plan reviewed with operations.
PH 3WK 8–14
BuildStaged in parallel, tested against live traffic, cut over inside outage windows.
PH 4WK 15–16
Hand overAs-builts, runbooks and a change process your team can hold.
You receiveTarget architecture, as-built drawings, configured hardware, rule sets, cutover runbooks and a change-control process.
We need from youNetwork drawings, outage windows, integrator contacts and access to the switch closets.

Get in touch

Talk to an OT security engineer.

Engineer at a membrane skid control panel