Subscribe to the Non-Human & AI Identity Journal
Home FAQ Cyber Security How should water utilities compare OT segmentation approaches…
Cyber Security

How should water utilities compare OT segmentation approaches across mixed environments?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated July 30, 2026 Domain: Cyber Security

They should compare each approach by enforcement point, coverage, operational friction, and evidence output, not by vendor category. A tool that works well at the boundary may be weak inside the plant, while an identity-based model may cover more assets but depend on better asset data. The right choice is the one that fits the site list, not the brochure.

Why This Matters for Security Teams

Water utilities rarely run a single, clean OT architecture. Pump stations, treatment plants, remote telemetry units, contractor access paths, and legacy PLCs often create a mixed environment where one segmentation pattern cannot fit every zone. The real decision is not whether segmentation exists, but whether it constrains lateral movement, preserves operational continuity, and produces evidence that auditors and operators can both trust.

Security teams also need to compare controls in terms of how they behave during maintenance, failover, and emergency operations. A design that looks strong on paper can become brittle if it depends on perfect asset inventory or constant protocol parsing. NIST control guidance such as the NIST SP 800-53 Rev 5 Security and Privacy Controls is useful here because it frames segmentation as part of a broader control environment, not a single product decision.

In practice, many security teams discover weak segmentation only after an engineering change, remote support event, or incident response exercise has already exposed the gaps.

How It Works in Practice

Effective comparison starts by mapping each segmentation approach to the site’s actual enforcement points. In an OT setting, that may mean comparing network zone isolation, firewall policy enforcement, jump host mediation, microsegmentation, host-based controls, or identity-aware access paths. Each model shifts where trust is enforced and how much visibility it gives into east-west traffic, contractor sessions, and remote maintenance activity.

A practical comparison should test four things:

  • Enforcement point: Is segmentation enforced at the perimeter, within the plant network, on the endpoint, or through identity and policy?

  • Coverage: Does it protect only modern managed assets, or also older devices with limited security features?

  • Operational friction: Does it create unsafe delays for maintenance, alarm response, or engineering changes?

  • Evidence output: Can it show who accessed what, when policy blocked traffic, and how exceptions were approved?

For water utilities, this is especially important because safety, availability, and compliance can outweigh the appeal of a theoretically elegant design. Current guidance from the CISA ICS Security Guidelines and CIS Critical Security Controls support layering network segmentation with asset visibility, secure remote access, and monitoring rather than treating segmentation as a standalone fix. Where segmentation depends on asset identity, the quality of the inventory becomes part of the control itself. Where it depends on protocol inspection, encrypted tunnels or proprietary industrial protocols may reduce inspection depth and weaken policy precision.

Best practice is to test the design against normal operations and failure modes. That means validating whether a vendor session can be limited to one substation, whether a plant outage procedure still works, and whether logging is usable during an incident review. These controls tend to break down when the environment includes unmanaged legacy devices, shared engineering workstations, and emergency bypass processes because policy exceptions quickly outgrow the original segmentation model.

Common Variations and Edge Cases

Tighter segmentation often increases engineering overhead, so organisations have to balance stronger containment against faster maintenance and simpler operations. That tradeoff is real in water utilities, where some sites need strict isolation while others need flexible support for rotating contractors or seasonal process changes.

There is no universal standard for comparing ot segmentation approaches across mixed environments, so current guidance suggests judging each method by the assets it can actually protect and the exceptions it requires. Boundary firewalls may be effective for coarse zone control, but they often miss misuse inside a trusted segment. Identity-based models can improve precision, but they depend on reliable device records, stable credentials, and mature access governance. For utilities that rely on remote support, the comparison should also include how well the model supports temporary access, session recording, and rollback after maintenance.

Utilities should also consider hybrid designs. A site may use perimeter segmentation for large zones, host-based controls for critical HMIs, and identity-driven approvals for remote engineers. That combination is often more realistic than a single control strategy, especially where brownfield equipment cannot be reconfigured easily. The CISA Industrial Control Systems resources are helpful for framing layered resilience, but the final choice should still be validated against the site’s topology, outage tolerance, and evidence needs rather than against a generic architecture template.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack surface, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, and NIS2 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.ACSegmentation is a core access control and protection capability in mixed OT environments.
NIST SP 800-53 Rev 5SC-7Boundary protection and internal segmentation are central to OT network design choices.
NIS2NIS2 raises expectations for operational resilience and risk-managed control selection in critical infrastructure.
MITRE ATT&CKT1021Remote services are a common path for lateral movement across poorly segmented OT networks.

Define trust zones, restrict paths between them, and review whether controls actually limit lateral movement.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on July 30, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org