By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: ElisityPublished July 30, 2026

TL;DR: Water utilities evaluating OT segmentation are being asked to compare seven approaches, 14 vendor questions, and a proof-of-value protocol that prices licensing, prerequisites, and staff effort against real site conditions, according to Elisity. The deciding issue is no longer whether segmentation is worthwhile, but whether a chosen method can enforce reliably across mixed OT assets and remote sites.


At a glance

What this is: This is an evaluation guide for water and wastewater utilities comparing OT segmentation approaches, vendor questions, and proof-of-value methods, with the main finding that no single model fits every site or asset class.

Why it matters: It matters because segmentation decisions in OT depend on enforcement point, coverage, and operational fit, and identity-dependent approaches only work when utilities understand where device identity, network controls, and staff workflows intersect.

👉 Read Elisity's evaluation guide for OT segmentation in water utilities


Context

Water utility OT segmentation is a governance and operating model problem before it is a tooling decision. In plants and distribution environments, the real question is not whether to segment, but how to enforce policy across fixed equipment, remote sites, and devices that cannot support agents or frequent change. That makes asset identity, network topology, and operational constraints inseparable from the security design.

This article is explicitly about the evaluation layer. Elisity frames the decision as method selection after a shortlist exists, which is the right place to focus when procurement needs to compare controls, licensing, prerequisites, and proof-of-value evidence. For identity and access teams, the intersection is real: segmentation only becomes durable when policy is tied to trustworthy asset and directory data rather than brittle static network assumptions.


Key questions

Q: How should water utilities compare OT segmentation approaches across mixed environments?

A: They should compare each approach by enforcement point, coverage, operational friction, and evidence output, not by vendor category. A tool that works well at the boundary may be weak inside the plant, while an identity-based model may cover more assets but depend on better asset data. The right choice is the one that fits the site list, not the brochure.

Q: What breaks when segmentation depends on topology instead of identity?

A: Topology-based controls become fragile when devices move, sites expand, or remote assets cannot be cleanly redrawn into static network zones. They also struggle to express who or what a device is, which makes policy hard to reuse across plants. That is why identity-linked policy is often more durable in distributed utility estates.

Q: How do you know an OT segmentation platform is actually ready for enforcement?

A: It is ready when the platform has completed a real baselining period, can classify new devices consistently, and can simulate policy against observed traffic before blocking anything. Readiness is shown by stable classifications, clear rollback paths, and evidence that critical flows remain intact under policy review.

Q: What should procurement teams ask before selecting an OT segmentation vendor?

A: They should ask what the product enforces on, what percentage of the estate it can cover, what infrastructure it needs, and what evidence it produces for compliance and recovery planning. Those questions expose the real architecture, the hidden cost, and the operational work the vendor will not carry for you.


Technical breakdown

How OT segmentation enforcement differs across water utility environments

OT segmentation is not one control, but a set of enforcement models that operate at different layers. VLANs and ACLs separate traffic by topology, firewall zones enforce boundary policy, 802.1X admits devices at connection time, host agents enforce at the operating system, and identity-based microsegmentation classifies devices from passive observation plus identity attributes. The architectural trade-off is coverage versus friction. In utilities, the hardest constraint is that many assets are unmanaged, unpatchable, or cannot run software, so any model that depends on local installation will leave structural gaps.

Practical implication: Map each plant and site to the lowest-friction enforcement point that still gives measurable coverage.

Why discovery and baselining matter before enforcement

Policy quality depends on what the platform can observe before it blocks anything. In OT, a baselining period is needed to learn normal device-to-device communication, classify assets, and reduce false enforcement. Without that period, vendors may mislabel IT assets that perform OT functions or miss undocumented dependencies such as historians, engineering workstations, and remote support paths. The practical distinction is between visibility and confidence: a product can see traffic quickly, but safe enforcement usually requires a longer operating window to avoid breaking production flows.

Practical implication: Demand a simulation phase with explicit acceptance criteria before any deny policy is activated.

What licensing and prerequisites reveal about segmentation maturity

Licensing and prerequisites are not commercial footnotes. They are architecture signals. If a product requires agents, re-addressing, dedicated appliances, or specific hardware and firmware, it is telling you where enforcement really happens and what operational change the rollout will force. Mature evaluation treats those dependencies as part of the control design, not as implementation noise. For utilities, the most important question is whether the vendor can enforce on your actual asset mix, including remote pump stations and devices that cannot be touched during production.

Practical implication: Price the full deployment path, including infrastructure changes and staff time, before comparing approaches.


Threat narrative

Attacker objective: The objective is to move laterally inside the OT environment and reach systems that can alter operations or expose sensitive process data.

  1. Entry typically begins through an exposed boundary, weak internal segmentation, or a device that can communicate more broadly than intended inside the OT zone.
  2. Escalation happens when an attacker or misconfigured system reaches engineering workstations, historians, or other trusted intermediaries that can bridge otherwise separated zones.
  3. Impact follows when movement reaches process assets, allowing disruption, unauthorized access, or manipulation of operational traffic.

NHI Mgmt Group analysis

Identity-dependent microsegmentation becomes a governance control when the asset cannot host an agent. In utility environments, the control question is not whether segmentation exists, but whether policy can follow the identity of a device or user across sites without requiring re-addressing or software on fragile assets. That makes directory data, passive observation, and asset records part of the control plane. Practitioners should treat identity-linked segmentation as a coverage problem first and a policy problem second.

Segmentation programs fail when they are evaluated as product categories instead of enforcement models. A firewall, ACLs, 802.1X, host agents, and identity-based policy solve different problems, and the utility may need two or three together. The mistake is expecting one architecture to protect every plant class, every remote site, and every device type. Practitioners should compare where each model enforces, where it only observes, and what happens when production conditions change.

Discovery latency is the hidden governance cost in OT security. In water environments, the period between first visibility and safe enforcement can be weeks, and that delay often gets underestimated in procurement. The real decision is whether the organisation can tolerate a controlled baseline period before blocking begins. Practitioners should plan around discovery latency rather than treat it as a vendor inconvenience.

Licensing economics now determine control feasibility as much as technical fit. If the deployment model depends on hardware refresh, agent rollout, or site-by-site prerequisites, the security programme inherits an operational programme. That is why vendor comparisons need to include staffing, maintenance windows, and evidence for assessment bodies, not just feature matrices. Practitioners should fund the whole control path or avoid the control entirely.

For regulated OT, the most defensible segmentation choice is the one you can prove in production. Water utilities need controls that can produce evidence for assessment, show what was allowed, and explain why the policy will not collapse when an endpoint or site changes. That is the standard against which segmentation should be measured. Practitioners should demand proof-of-value results tied to their own inventory and site map.

What this signals

Water utilities should expect segmentation programmes to shift from perimeter thinking to enforcement realism. The control that matters is the one that can survive mixed OT assets, remote sites, and incomplete inventories without forcing disruptive redesign. That means procurement, operations, and identity data owners have to evaluate the same control path together, not as separate workstreams.

Enforcement realism: the point at which a proposed control can actually be applied to the estate it claims to protect. In OT, that test will increasingly determine whether a segmentation programme becomes a durable control or an expensive visibility layer. Practitioners should make that concept part of every proof-of-value review.

For identity teams, this article is a reminder that segmentation and identity governance meet at the asset record. If the identity data is stale, the policy engine will classify poorly; if the network model is brittle, the best identity data still will not prevent operational disruption. The next programme increment is tighter alignment between CMDB quality, directory truth, and enforcement design.


For practitioners

  • Build a site-specific enforcement map Classify each site by the control point it can realistically support, then separate enforce-capable assets from observe-only assets before vendor scoring begins.
  • Require simulation before enforcement Run policy in monitor mode against real traffic and only approve controls that survive a full baseline period without breaking historians, engineering workstations, or remote support flows.
  • Price hidden prerequisites explicitly Include hardware refresh, re-addressing, appliance placement, and staff time in every evaluation so the three-year cost reflects operational reality, not the license line alone.
  • Test evidence outputs against assessments Ask each vendor to show the artifacts needed for an AWIA Risk and Resilience Assessment, a sanitary survey, and insurance review, then reject any platform that cannot produce them cleanly.

Key takeaways

  • Water utility segmentation succeeds or fails on enforcement fit, not on feature count.
  • Discovery, baselining, and operational prerequisites are part of the control, not implementation detail.
  • The strongest proof of value is evidence that the chosen policy works on the utility’s own sites and assets.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Segmentation and access restriction are central to OT enforcement decisions.
NIST SP 800-53 Rev 5AC-4Information flow enforcement fits the article's segmentation and boundary-control focus.
CIS Controls v8CIS-12 , Network Infrastructure ManagementThe article focuses on network control, topology, and segmentation governance.
MITRE ATT&CKTA0008 , Lateral Movement; TA0004 , Privilege EscalationThe article's risk model centers on blocking movement inside OT networks.
ISO/IEC 27001:2022A.8.20Network security controls are directly relevant to segmentation and policy enforcement.

Map segmentation gaps to lateral movement paths and test whether policy stops escalation between zones.


Key terms

  • OT Segmentation: The practice of separating industrial systems into controlled zones so traffic and access can be restricted by operational need. In effective programmes, segmentation depends on trustworthy asset identity, accurate communication mapping, and enforced rules that reflect how the environment really behaves.
  • Proof Of Value: A proof of value is a controlled evaluation that tests a security product against the buyer's own assets, traffic, and operating constraints. In regulated environments, it should prove enforcement coverage, operational fit, rollback safety, and the evidence the organisation will need later.
  • Identity-based Microsegmentation: A segmentation approach that uses identity, context, and policy to decide whether a connection should be allowed inside a network zone. In OT, it helps reduce lateral movement without relying only on IP addresses or broad subnet rules.
  • Baselining Period: A baselining period is the time a security platform spends observing normal communications before blocking traffic. In OT, it matters because production systems often have unusual but legitimate dependencies, and premature enforcement can interrupt historians, controllers, or remote support paths.

What's in the full article

Elisity's full article covers the operational detail this post intentionally leaves for the source:

  • The full seven-approach comparison with licensing models, infrastructure prerequisites, and best-fit environments.
  • The 14 procurement questions in the exact wording the article recommends for side-by-side vendor comparison.
  • The proof-of-value protocol with dated stages, acceptance criteria, and staff effort estimates.
  • The article's discussion of what evidence utilities should produce for EPA assessment and insurance review.

👉 Elisity's full post covers the approach comparison, procurement questions, and proof-of-value protocol in detail.

Deepen your knowledge

NHI Mgmt Group covers identity security, NHI governance, and agentic AI through independent research, practitioner guides, and the NHI Foundation Level course, the industry's only accredited NHI security programme. It is designed for teams that need a clear governance baseline across identity, privilege, and machine access.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 30, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org