Join our Newsletter — 33% off our NHI Course

How should manufacturers use zero trust segmentation to keep production running during a ransomware attack?

Manufacturers should use zero trust segmentation to contain the blast radius of an attack, rather than relying on perimeter defenses alone. By restricting east west communication to only required protocols and assets, security teams can stop ransomware from reaching critical production systems. This supports operational resilience, keeps essential services available, and buys time for investigation, remediation, and safe recovery.

Why Zero Trust Segmentation Keeps Plant Floors Running During Ransomware

In manufacturing, the goal is not to assume the environment can be fully protected at the perimeter, it is to stop compromise from spreading into the systems that keep machines, lines, and safety functions operating. zero trust segmentation is most useful when it is designed around production dependencies, not broad network zones, so that a ransomware event can be contained without forcing an unnecessary shutdown.

The practical value is blast-radius control. If a ransomware operator lands on a workstation, engineering laptop, or shared server, tightly defined east-west policies can prevent that foothold from reaching controllers, historians, recipe systems, or other production-critical assets. That containment gives defenders time to isolate affected segments, confirm what is still trustworthy, and recover in a controlled sequence.

Manufacturers should treat segmentation as an availability control as much as a security control. In a plant environment, an overbroad policy can be almost as harmful as no segmentation at all if it blocks legitimate machine-to-machine traffic, maintenance access, or time-sensitive OT services. The design challenge is to allow only the protocols, peers, and management paths that are operationally required, then continuously verify that those allowances stay narrow.

  • Start by mapping the minimum communications needed for each production cell, line, and shared service.
  • Separate business IT, engineering access, and OT runtime traffic so compromise in one layer does not automatically reach the others.
  • Prefer explicit allow rules for approved east-west flows over inherited trust from shared subnets or flat network zones.
  • Test failover and recovery paths under segmentation, because containment should not break safe restart or incident response.

For environments that use workload identity and service-to-service trust in production tooling, a model such as Guide to SPIFFE and SPIRE shows how identity-bound communication can support tighter segmentation without relying on network location alone. For a broader control view, Ultimate Guide to NHIs, Standards is useful when segmentation has to work alongside workload authentication and zero trust policy.

Where Segmentation Matters Most in OT and Plant Networks

Not every connection in a plant has equal operational importance. The highest-value segmentation boundaries are usually the ones between user endpoints and production services, between engineering workstations and controllers, and between shared infrastructure and line-specific systems. Those boundaries matter because ransomware commonly spreads laterally through reachable peers, administrative tools, and shared services that were originally connected for convenience rather than necessity.

Well-designed segmentation also respects the difference between monitoring traffic and control traffic. A historian, backup server, or patching service may need access to several systems, but it should not have unrestricted reach into everything. Likewise, remote maintenance should be time-bound, tightly scoped, and observable, because standing access paths are exactly what attackers try to reuse once they have a foothold.

In practice, the most reliable plant designs are usually the least ambiguous ones: small trust zones, explicit dependencies, and known exception paths. That makes it easier to verify what should still function during an attack, and easier to isolate what must be shut down without taking the entire line with it.

Current zero trust guidance from NIST SP 800-207 Zero Trust Architecture supports this approach by favoring explicit verification and least privilege over implicit network trust. For OT-specific implementation detail, NIST SP 800-82 Rev 3, OT Security Guide is the better reference for segmentation patterns in industrial environments.

How to Balance Containment With Safe Recovery

Segmentation only helps if it can support recovery, not just isolation. During a ransomware event, the objective is to keep essential production services running where safe, while preventing the attacker from pivoting into systems that would turn a partial incident into a plant-wide outage. That means recovery design has to include preplanned fallback connectivity, trusted management access, and a way to restore critical paths without reopening the whole network.

The best operational posture is usually selective continuity. Some systems may remain online under tighter trust conditions, while others are disconnected, rebuilt, or validated before reconnecting. This is especially important in manufacturing because a hard shutdown can create scrap, safety issues, or long restart delays even when the malware never reaches the control layer.

That trade-off makes exercise and validation essential. Teams need to prove that segmentation rules still permit safe diagnostics, backup restoration, and controlled operator access when normal trust relationships are degraded. If those paths are only theoretical, the organisation may discover during an incident that the network is secure but the plant cannot resume.

Risk and Threat Considerations

Ransomware succeeds operationally when lateral movement is easier than containment. In manufacturing, flat network design, shared administrative paths, and overbroad east-west access let a single compromised endpoint reach production services that should never have been directly reachable.

Failure mechanism: An initial foothold on a user device, engineering station, or exposed service can be used to discover reachable assets, encrypt shared resources, and disrupt or disable control and monitoring systems before defenders can isolate the intrusion.

Impact: The result can be line stoppage, loss of visibility, delayed recovery, and unsafe manual workarounds. Strong segmentation reduces that blast radius and can preserve enough operational capability to investigate and restore production in phases.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207), CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 SC-7 — Boundary Protection Segmentation limits ransomware lateral movement across plant zones.
AC-6 — Least Privilege Zero trust segmentation depends on minimizing reachable protocols and assets.
Recommendation — Define and enforce controlled communication paths between production zones and support systems. Restrict east-west access to only the services and protocols each system requires.
NIST Zero Trust (SP 800-207) Zero Trust Architecture The question is explicitly about using zero trust to contain ransomware spread.
Recommendation — Apply explicit verification and least-privilege trust decisions to every production communication path.
CIS Controls v8 CIS-12 — Network Infrastructure Management Network segmentation and controlled connectivity are core to limiting spread.
Recommendation — Segment manufacturing networks so compromise in one zone cannot freely traverse to others.
NIST CSF 2.0 PR.AA-05 — Network integrity is protected, including network segmentation and isolation where appropriate This directly maps to keeping ransomware contained through segmentation.
Recommendation — Isolate production assets and enforce segmentation rules that block unnecessary lateral movement.

Practitioner Guidance

What to prioritise: Treat the most operationally critical east-west dependencies first, not the largest number of hosts. A small number of badly trusted paths between workstations, shared services, and production assets usually creates more risk than broad but low-value network exposure.

What to verify: Validate segmentation under incident conditions, not just during normal operations. If a recovery team cannot still reach the systems needed for diagnosis, restore, and safe restart, the policy is too brittle for a ransomware event.

Practitioner takeaway: The right question is not whether production traffic is segmented, but whether the plant can keep its essential functions while every nonessential path is denied, observed, and recoverable.