TL;DR: Flat industrial networks, shared VPNs, and lingering credentials let one maintenance session expose multiple PLCs, control servers, and downstream systems, according to Corsha. Identity-based microsegmentation shifts segmentation from network redesign to session-level access control, which is the practical path when uptime constraints make rip-and-replace unrealistic.
At a glance
What this is: This guide argues that industrial microsegmentation works best when access is governed by identity and session context rather than by reworking legacy plant networks.
Why it matters: For OT, IAM, and PAM teams, the issue is how to constrain lateral movement and vendor reach without disrupting production or relying on brittle network rebuilds.
Context
Industrial microsegmentation is the practice of restricting which systems, functions, and zones a connection can reach inside an operational environment. In this article, the core problem is that flat plant networks, shared VPN paths, and long-lived access patterns make lateral movement possible even when the original task is narrow.
The governance gap is not just network design. In industrial manufacturing and similar high-throughput environments, access often outlives the maintenance session that created it, and visibility into what else was reached is limited. That makes identity, session control, and revocation timing the practical control plane for segmentation.
The article’s premise is typical for legacy OT estates: production uptime has historically outranked segmentation discipline, so security teams need controls that work with existing systems rather than replacing them.
Key questions
Q: How should security teams reduce lateral movement risk in enterprise networks?
A: Start by reducing the number of internal trust paths an identity can cross. Separate user and admin accounts, remove unnecessary local administrator rights, segment sensitive systems, and alert on unusual credential reuse. The goal is to make one foothold hard to turn into broad access, even when the attacker has valid credentials.
Q: Why do shared VPNs and jump boxes increase lateral movement risk in OT networks?
A: They concentrate trust into a small number of reusable paths, so one approved login can reach far more assets than intended. In a flat plant network, that makes internal trust too broad and turns a single compromise into a route across multiple controllers, zones, or production lines.
Q: What are the signs that OT segmentation is failing in practice?
A: Look for maintenance paths that can reach more than one zone, credentials that remain usable after the job ends, and limited visibility into what the session actually touched. Those are signs that segmentation is still being enforced by assumption rather than by policy.
Q: When should industrial teams choose identity-based segmentation over network redesign?
A: Choose it when uptime constraints, legacy systems, or production risk make VLAN rebuilds, firewall rework, or topology changes unrealistic. Identity-based segmentation is the better fit when the control objective is to reduce lateral reach without interrupting operations.
Technical breakdown
Why flat industrial networks amplify lateral risk
Industrial networks are often built for availability, not isolation, which means internal trust is assumed across users, devices, and zones. When a technician or vendor connects through a shared VPN or jump box, that path can expose more than the intended controller if the network does not enforce zone boundaries. The technical issue is not only reachability but uncontrolled transitive access. In practice, one approved session becomes a bridge to multiple PLCs, control servers, and downstream systems. The absence of effective microsegmentation means network adjacency becomes access, even when the business task is narrowly scoped.
Practical implication: treat flat reachability as an exposure problem and identify where a single connection can traverse multiple OT zones.
How identity-first segmentation works at session level
Identity-first microsegmentation moves the control point from VLAN design to authenticated sessions. A user or machine is verified, bound to a specific identity, and then limited to the exact systems, functions, or zones required for the task. Just-in-time access and automatic revocation reduce the time window in which credentials can be reused or abused. This is different from static network segmentation because the policy is evaluated at connection time and can change with the identity, the request, or the context of the session. The result is segmentation by intent rather than by subnet.
Practical implication: govern access at issuance and revocation time, not only at network architecture design time.
Why legacy OT environments make rip-and-replace unrealistic
Many industrial sites run aging systems that were never designed for modern segmentation controls, and changing those systems can create production risk. Rebuilding firewalls, reconfiguring VLANs, or replacing remote access patterns across live plant operations often exceeds the tolerance for downtime. That constraint is why identity-based controls matter: they layer protection over existing infrastructure instead of forcing wholesale redesign. The important architectural point is that segmentation can be enforced without touching the underlying production logic. This lets practitioners close lateral paths while preserving uptime and operational continuity.
Practical implication: use compensating identity controls where network rearchitecture would be too disruptive or too slow.
Threat narrative
Attacker objective: The objective is to expand a narrow maintenance foothold into broader access across OT systems and create conditions for disruption or theft of control reach.
- Entry occurs when a technician, vendor, or attacker uses a shared VPN or reused login to reach an initial OT endpoint.
- Credential access is amplified when the same credentials persist after the maintenance task, enabling repeat use or theft through phishing.
- Lateral movement follows when the flat network allows that session to traverse from one PLC or control server to other production assets.
- Impact is operational, because a single exposed session can create broad security risk, production disruption, or downstream downtime.
Breaches seen in the wild
- Schneider Electric Jira breach 2024: Credentials linked to a Lumma infostealer infection gave Hellcat access to Schneider Electric's Jira; 40GB and 400,000 user rows claimed.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity is becoming the practical segmentation boundary in industrial operations. The article shows that network boundaries are often too rigid to redesign and too weak to trust, which pushes control into the session itself. That is not a cosmetic change, because the access decision now has to carry the segmentation burden. Practitioners should treat identity enforcement as the real containment layer for OT lateral risk.
Flat network trust is the governance assumption that fails first. Industrial environments often presuppose that internal reachability can be tolerated because the network is closed and operations are controlled. This breaks when vendors, remote sessions, and modern connectivity create pathways that are technically internal but operationally wide open. The implication is that legacy perimeter thinking no longer describes actual access behavior in plant environments.
Session-level access control is the right unit of policy for uptime-constrained OT estates. The article’s value is that it reframes microsegmentation as an access governance problem rather than a firewall project. That matters because many OT teams cannot absorb a topology rewrite, but they can enforce who can connect, from where, and to what scope. The practical conclusion is to govern connections as first-class identities.
Vendor and technician access needs lifecycle discipline, not just connectivity. The risk described here is not only initial reach but the persistence of access after the work is done. When credentials linger, the environment retains a path that should have expired with the task. Practitioners should examine offboarding, session expiration, and reuse of remote access accounts as part of OT identity governance.
Identity-first microsegmentation creates an identity blast radius model for industrial zones. Instead of asking whether the network is segmented enough in the abstract, teams should ask how far any one authenticated session can actually move. That gives security and operations a shared control objective that respects uptime constraints. The practical conclusion is to define blast radius by identity scope, not by plant map alone.
What this signals
Identity-first segmentation becomes the containment model when plant networks cannot be rebuilt. The practical signal for OT teams is that session scope now matters more than subnet design, because that is where lateral movement is either stopped or allowed to expand. Programs that still rely on static trust zones should expect their weakest controls to appear at remote access entry points.
Industrial microsegmentation should be measured by the reach of any one authenticated session. If a technician or vendor login can move from one controller to several systems without explicit policy enforcement, segmentation is only cosmetic. The next governance step is to align access reviews, session expiry, and remote access policy to the real movement paths in production.
Identity blast radius is the concept to watch. In OT environments, the question is no longer whether the network is segmented in principle, but how far one approved session can travel before it is blocked. That framing is useful because it turns a topology problem into an access governance question that operations teams can actually control.
For practitioners
- Map lateral paths from shared remote access Inventory the VPNs, jump boxes, and shared logins that can reach multiple PLCs, control servers, or downstream systems from one session. Use that map to identify where one authenticated path has excessive operational reach.
- Bind access to unique machine and user identities Replace broad, reusable access with unique identities that are verified before a session opens and scoped to the specific systems, functions, or zones needed for the task.
- Apply just-in-time session expiration Set remote access to expire automatically when the maintenance task ends, so credentials do not remain available for repeat use or reuse in later sessions.
- Track all OT session activity in real time Collect and review connection logs that show who connected, from where, and which systems were reached, so lateral movement is visible while the session is still active.
Key takeaways
- Industrial environments often expose too much lateral reach because access paths are shared, legacy, and designed for uptime rather than isolation.
- The article’s central pattern is that one authenticated maintenance session can fan out across PLCs, control servers, and downstream systems if segmentation is not enforced at the session level.
- Identity-first controls reduce that blast radius by binding access to a specific session, scope, and expiration point instead of relying on network redesign.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Flat OT access paths give one session too much reach across controllers and zones. |
| NHI-01 — Improper Offboarding | Lingering vendor credentials after maintenance create repeat access opportunities. | |
| Recommendation — Scope remote access so a single OT identity cannot traverse beyond its required controller or zone. Revoke plant access when the maintenance task ends and remove stale vendor credentials promptly. | ||
| MITRE ATT&CK | TA0008 — Lateral Movement | The article centers on movement from one industrial session into multiple systems. |
| Recommendation — Map OT remote access paths to TA0008 and block uncontrolled movement between industrial zones. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is about controlling who can reach what in industrial environments. |
| Recommendation — Apply PR.AA-05 to enforce identity-scoped permissions for OT and vendor sessions. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Least privilege is the core control principle behind session-level segmentation. |
| Recommendation — Use AC-6 to limit industrial access to the minimum systems and functions needed for the task. | ||
Key terms
- Identity-based Microsegmentation: A segmentation approach that uses identity, context, and policy to decide whether a connection should be allowed inside a network zone. In OT, it helps reduce lateral movement without relying only on IP addresses or broad subnet rules.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Session-level segmentation: Session-level segmentation is the practice of enforcing access boundaries at connection time, so each session is constrained to specific systems, functions, or zones. It matters in industrial environments because it can reduce lateral movement without forcing immediate changes to the underlying plant architecture.
- Just-in-Time Access Request: Just-in-Time Access Request is a pattern that grants access only when it is needed and only for the duration required. It reduces standing privilege by making access temporary, policy driven, and task scoped. This approach is especially useful for contractors, sensitive systems, and short-lived operational work.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org