Network segmentation limits where an attacker can move by isolating systems and reducing cross-contamination between IT and OT zones. Data-centric security protects the file or record itself through encryption, access control, audit trails, and remote revocation, even after data is shared externally. Manufacturers usually need both, because one protects the environment and the other protects the asset.
Why This Matters for Security Teams
In manufacturing, the distinction matters because attackers rarely stay inside one trust boundary. Network segmentation is designed to slow lateral movement across IT, OT, and supplier-connected zones, while data-centric security is meant to keep sensitive engineering files, recipes, quality records, and credentials protected even when they leave the perimeter. That split becomes critical when production depends on shared files, remote maintenance, and third-party collaboration.
Security teams often overestimate what segmentation can do on its own. A segmented plant network can still leak sensitive data through sanctioned file transfers, cloud collaboration tools, removable media, or compromised contractor accounts. Data-centric controls help close that gap by making protection travel with the asset, including encryption, rights enforcement, logging, and revocation where supported. NIST’s NIST SP 800-207 Zero Trust Architecture is useful here because it reinforces that trust should not come from network location alone.
In practice, many security teams only discover the weakness after a plant disruption or a file has already been copied beyond the intended boundary.
How It Works in Practice
Network segmentation focuses on path control. In a factory, that usually means separating business systems from production systems, then further isolating zones such as engineering workstations, historians, safety systems, and remote access points. The goal is to reduce blast radius, constrain east-west traffic, and force traffic through monitored gateways or conduits. This is especially valuable for legacy OT assets that cannot be hardened as aggressively as modern endpoints.
Data-centric security focuses on the object itself. Instead of relying only on where a file resides, it attaches protection to the data through mechanisms such as encryption, classification, tokenization, digital rights management, access policy, audit logging, and revocation. Where mature tooling exists, access may be conditioned on user identity, device posture, location, or time, which creates a stronger control layer for drawings, bills of materials, production formulas, and quality evidence.
- Segment OT and IT to contain compromise and protect fragile production systems.
- Apply data classification so sensitive records get stronger handling automatically.
- Use encryption and key management to reduce exposure if data is copied or intercepted.
- Enforce least privilege and log access to detect misuse of shared technical documents.
- Set revocation and expiration policies for data shared with vendors or contract manufacturers.
NIST SP 800-53 Rev. 5 helps translate this into control families for access control, auditability, and system protection, which is useful when manufacturing teams need to prove both operational resilience and information protection. These controls tend to break down when flat legacy OT networks must remain open for unmanaged vendor support, because segmentation and object-level policy both lose effectiveness against direct trusted-path access.
Common Variations and Edge Cases
Tighter segmentation often increases operational overhead, requiring organisations to balance production uptime against reduced attack surface. That tradeoff becomes more visible in plants with aging PLCs, shared engineering assets, or just-in-time vendor access, where rigid boundaries can interfere with maintenance and line recovery.
There is no universal standard for this yet, but current guidance suggests treating segmentation and data-centric security as complementary rather than interchangeable. Segmentation is strongest when the question is “how far can an attacker move?” Data-centric security is stronger when the question is “who can still use this file, record, or credential after it is copied?”
Manufacturers should also account for edge cases such as offline plant operations, air-gapped engineering environments, and data that must be reconstituted on a machine without persistent identity services. In those cases, the data-centric model may degrade to encryption and offline access controls, while segmentation carries more of the containment burden. The most common failure mode is assuming one control family can compensate for the absence of the other, especially when engineering teams exchange sensitive data with suppliers, integrators, or remote service providers.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC | Segmentation and access control both support limiting attack spread and unauthorized access. |
| NIST Zero Trust (SP 800-207) | Zero trust supports the idea that location alone should not determine trust. | |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is central to both segmented environments and data-centric access enforcement. |
Separate critical zones and restrict access paths so compromise in one area does not spread freely.
Related resources from NHI Mgmt Group
- What is the difference between Zero Trust and traditional network segmentation in hybrid security?
- What is the difference between identity-centric security and traditional network security?
- What is the difference between data-centric security and an access graph in enterprise identity governance?
- What is the difference between perimeter security and data-centric security?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 1, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org