Manufacturers should treat every connection as untrusted and design controls around least privilege, segmentation, and continuous verification. In connected factories, ERP, OT, and ICS environments expand the attack surface, so security must limit lateral movement between systems and contain compromise quickly. Zero Trust works best when policy is enforced at the communication layer, not just at the perimeter.
Applying Zero Trust to the factory network, not just the office network
zero trust in connected factories starts with a shift in where trust is enforced. The goal is to stop assuming that anything inside the plant network, or anything connected through a vendor path, is inherently safe. For manufacturers, that means applying policy at the communication layer between users, applications, controllers, historians, and engineering tools, so each exchange is evaluated on identity, context, and necessity.
That is especially important in industrial environments because IT and OT are increasingly coupled. ERP systems, MES platforms, remote engineering access, and supplier integrations can become pathways into control environments if they are treated as soft trusted zones. A practical Zero Trust design makes those connections explicit, narrow, and observable rather than inherited from network location.
Two architectural choices matter most: segmentation and policy enforcement. Segmentation limits how far a compromise can travel, while enforcement points make sure that access decisions are applied consistently instead of relying on flat network reachability. In factory settings, this often means separating production cells, engineering workstations, remote access paths, and business systems so a problem in one layer does not automatically become a plant-wide event.
For deeper background on the architecture principle, see NIST SP 800-207 Zero Trust Architecture. For OT-specific guidance on applying those ideas in industrial environments, NIST SP 800-82 Rev 3 remains the more practical reference point.
Why industrial control systems need tighter trust boundaries than traditional IT
ICS environments are not just another application stack. Availability, safety, determinism, and process integrity often matter more than flexibility, which means the Zero Trust design has to respect operational constraints. The point is not to bolt enterprise IAM controls onto controllers and hope for the best; it is to reduce implicit trust while preserving the timing and reliability requirements that industrial processes depend on.
Manufacturers also need to recognise that some of the highest-risk paths are not the obvious ones. Engineering laptops, remote support channels, jump hosts, protocol gateways, and shared service credentials often create more exposure than the core controller network itself. If those paths are overly permissive, an attacker or a misconfiguration can move from a business system into a production segment with very little resistance.
Industrial Zero Trust therefore depends on knowing which interactions are truly necessary and which are legacy conveniences. If a vendor session only needs access to one device for a short maintenance window, the access should look like that, not like standing network reachability to the whole plant. If a historian only needs read access to a subset of telemetry, broad write paths or control-plane access are an unnecessary risk.
For plant operators, the hard part is often not deciding whether segmentation is useful, but deciding how granular to make it without breaking operations. Current guidance suggests that the right balance is usually cell- or zone-based isolation with tightly governed conduits between zones, rather than a monolithic plant network that assumes internal trust.
What Zero Trust changes operationally for manufacturers
Zero Trust is most effective when it changes day-to-day operational behaviour, not just network diagrams. That means every high-value connection should have a named owner, a clear purpose, and a reviewable policy. Remote administration, third-party maintenance, and machine-to-machine interactions should be time-bounded where possible and constrained to the minimum set of destinations and actions required.
The most common implementation mistake is to stop at perimeter hardening. In a connected factory, the perimeter is porous by design because business applications, cloud services, support teams, and suppliers need to interact with production systems. If policy is not enforced at the point of communication, a breach of one connected system can still become a lateral-movement problem inside the plant.
Manufacturers also need to build visibility into the control plane itself. You cannot enforce least privilege or verify trust continuously if you cannot see which systems are talking, which accounts are used for those sessions, and which conduits are open. Where possible, pair network segmentation with strong asset inventory, session logging, and periodic review of exceptions so that temporary access does not quietly become permanent architecture.
For teams looking for a concrete industrial view of the attack surface and containment problem, CISA Industrial Control Systems is a useful operating reference, and the broader Zero Trust model is reinforced by NIST SP 800-207 Zero Trust Architecture.
Risk and Threat Considerations
Connected factories create concentrated exposure when IT and OT are linked without strict trust boundaries. The main risk is not only external intrusion, but also lateral movement from a compromised business system, vendor path, or engineering workstation into systems that influence production, safety, or process integrity.
Failure mechanism: Flat or weakly segmented networks, overbroad remote access, and permissive communication policies let a compromise cross from one zone into another, where it can be used to disrupt operations, alter process data, or expand access.
Impact: A single foothold can turn into wider plant impact, including downtime, production loss, safety exposure, and more difficult incident containment because trust was inherited from location instead of being verified at each connection.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RR-01 — Organizational Context | Connected factory trust boundaries depend on business and OT context. |
| PR.AA-01 — Identity Management, Authentication, and Access Control | Zero Trust in factories depends on verifying each access path before use. | |
| PR.PT-04 — Least Functionality | Manufacturing segments should expose only the communications each process needs. | |
| Recommendation — Define OT and IT ownership for every critical factory connection. Require explicit authentication and authorization for plant access paths. Restrict factory services and conduits to the minimum required functions. | ||
| NIST SP 800-63 | IAL/AAL/FAL — Digital Identity Assurance and Federation Assurance | Remote plant access and privileged sessions need strong identity assurance. |
| Recommendation — Use appropriate assurance levels for remote and privileged factory access. | ||
| NIST Zero Trust (SP 800-207) | PL-1 — Policy Decision Point and Enforcement | Zero Trust requires policy enforcement at communication points, not the perimeter. |
| AC-4 — Policy Enforcement and Segmentation | Segmentation limits lateral movement between IT, OT, and ICS zones. | |
| Recommendation — Place enforcement points where factory traffic is actually brokered. Segment plant zones so compromise cannot spread freely across them. | ||
| CIS Controls v8 | 6 — Access Control Management | Factory remote access and engineering paths need tight account and permission control. |
| 12 — Network Infrastructure Management | Industrial Zero Trust relies on managing network boundaries and conduits. | |
| Recommendation — Remove unnecessary access paths and review privileged factory accounts regularly. Document and harden the conduits that connect business and control networks. | ||
Practitioner Guidance
What to prioritise: Start with the connections that can do the most damage, which are usually remote access paths, engineering workstations, supplier conduits, and anything that bridges business and control environments. Those are the places where Zero Trust gives the fastest reduction in blast radius.
What to verify: Make sure every exception has a business owner, an expiry condition, and a technical enforcement point. If a connection cannot be described as a specific source, destination, purpose, and duration, it is not yet ready for production use under a Zero Trust model.
Practitioner takeaway: In industrial environments, Zero Trust is less about banning connectivity and more about preventing connectivity from becoming implicit trust; the right measure of success is whether compromise can be contained before it crosses from one operational zone into another.
Related resources from NHI Mgmt Group
- Why do legacy industrial systems complicate zero trust access models?
- How should security teams apply zero trust to data estates that span cloud, SaaS, and on-prem systems?
- How do Zero Trust principles apply to certificate operations?
- Why do agentic systems complicate zero trust and access control assumptions in enterprise environments?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org