TL;DR: Water utilities evaluating OT segmentation are being asked to compare seven approaches, 14 vendor questions, and a proof-of-value protocol that prices licensing, prerequisites, and staff effort against real site conditions, according to Elisity. The deciding issue is no longer whether segmentation is worthwhile, but whether a chosen method can enforce reliably across mixed OT assets and remote sites.
NHIMG editorial — based on content published by Elisity: Water Utility OT Security: How to Evaluate Segmentation Approaches, Vendors, and a Proof of Value
Questions worth separating out
Q: How should water utilities compare OT segmentation approaches across mixed environments?
A: They should compare each approach by enforcement point, coverage, operational friction, and evidence output, not by vendor category.
Q: What breaks when segmentation depends on topology instead of identity?
A: Topology-based controls become fragile when devices move, sites expand, or remote assets cannot be cleanly redrawn into static network zones.
Q: How do you know an OT segmentation platform is actually ready for enforcement?
A: It is ready when the platform has completed a real baselining period, can classify new devices consistently, and can simulate policy against observed traffic before blocking anything.
Practitioner guidance
- Build a site-specific enforcement map Classify each site by the control point it can realistically support, then separate enforce-capable assets from observe-only assets before vendor scoring begins.
- Require simulation before enforcement Run policy in monitor mode against real traffic and only approve controls that survive a full baseline period without breaking historians, engineering workstations, or remote support flows.
- Price hidden prerequisites explicitly Include hardware refresh, re-addressing, appliance placement, and staff time in every evaluation so the three-year cost reflects operational reality, not the license line alone.
What's in the full article
Elisity's full article covers the operational detail this post intentionally leaves for the source:
- The full seven-approach comparison with licensing models, infrastructure prerequisites, and best-fit environments.
- The 14 procurement questions in the exact wording the article recommends for side-by-side vendor comparison.
- The proof-of-value protocol with dated stages, acceptance criteria, and staff effort estimates.
- The article's discussion of what evidence utilities should produce for EPA assessment and insurance review.
👉 Read Elisity's evaluation guide for OT segmentation in water utilities →
Water utility OT segmentation: what procurement teams need to compare?
Explore further
Identity-dependent microsegmentation becomes a governance control when the asset cannot host an agent. In utility environments, the control question is not whether segmentation exists, but whether policy can follow the identity of a device or user across sites without requiring re-addressing or software on fragile assets. That makes directory data, passive observation, and asset records part of the control plane. Practitioners should treat identity-linked segmentation as a coverage problem first and a policy problem second.
A question worth separating out:
Q: What should procurement teams ask before selecting an OT segmentation vendor?
A: They should ask what the product enforces on, what percentage of the estate it can cover, what infrastructure it needs, and what evidence it produces for compliance and recovery planning. Those questions expose the real architecture, the hidden cost, and the operational work the vendor will not carry for you.
👉 Read our full editorial: Water utility OT segmentation evaluation: what teams should ask