The typical starting position
In many manufacturing companies that have grown over time, there is exactly one network. Machine controllers, operator panels, measuring stations and test benches sit in it on equal terms with office PCs, the ERP server, printers and the guest WLAN.
Historically this is understandable. Production was connected step by step, and every new machine went wherever a network socket happened to be free. As long as everything works, nobody notices.
Why this is a problem
Production technology ages differently from office IT. A machine tool runs for fifteen or twenty years, and so, often, does the controller it was delivered with. Operating systems without manufacturer support are the rule in production halls, not the exception. Patching is frequently impossible, because the machine manufacturer does not release changes or because the warranty depends on it.
These systems are therefore permanently vulnerable, and that cannot be changed. What can be changed is how easily they can be reached.
In a flat network the rule is simple: whatever hits an office PC also reaches the controller. Ransomware from an email attachment does not just spread through administration, it brings production to a standstill as well. The damage is then caused not by lost files but by idle lines, contractual penalties and late deliveries.
The approach
Separation follows the zone model as described, among others, in IEC 62443. Areas with different protection requirements are bounded off from one another, and the transition between them is controlled.
With AIMdefense as the transition between the zones, this means in practice:
- Production and office become separate zones. Communication between them only takes place where it is actually needed, for example between MES and ERP.
- What is needed is what is permitted. Instead of allowing everything and blocking individual cases, access is granted selectively. For machine networks this is feasible, because the communication relationships there are manageable and stable.
- The route to the internet is defined. Controllers usually do not need one. Where they do, it runs through the firewall and is logged.
- Propagation is contained. An incident in the office network stays in the office network. Within production, areas can be subdivided further, for example by hall or production line.
What matters is not the individual rule but the fact that there is a named point at which rules take effect at all. A flat network does not have that point.
Implementation without stopping production
The usual objection is this: we do not know exactly who talks to whom, and if we separate the networks, the hall comes to a halt.
That is why the approach starts with observation. AIMdefense is first operated alongside the network and records the actual communication relationships. Only once the picture is complete do rules take effect, first logging, then blocking. The changeover itself takes place in a planned window, usually during a maintenance break that is scheduled anyway or at the weekend.
The logging stage is the real safety belt. A rule that initially only reports instead of blocking shows, before the changeover, what it would later prevent. Anything that was overlooked therefore comes to light during normal operations rather than on Monday morning.
In parallel, the device inventory is recorded and the configurations are backed up, so that the state reached can be restored.
What changes afterwards
The vulnerable legacy systems remain vulnerable, and no firewall changes that. But they can no longer be reached from every workstation. The most likely route into production, namely the detour through office IT, is closed.
For companies that have to provide evidence to customers, insurers or auditors, there is a further point: a documented zone structure with traceable rules can be audited, whereas a flat network cannot. This does not replace certification, but it does support the evidence that the areas really are separated.
At a glance
| Field of application | Manufacturing, mechanical engineering, industrial production |
|---|---|
| Initial problem | Shared network for production and office IT |
| AIM products | AIMdefense, AIM including VAS module |
| Role of AIMdefense | Controlled transition between the zones |
| Approach | Observation, logging rules, changeover in a maintenance window |
| Orientation | Zone model in line with IEC 62443 |
More about AIMdefense
For the functions behind segmentation, rule sets and logging, please see the Features page.
For an example of what structural separation looks like in a grown environment with IT and OT devices, see the success story Hospital group with more than 20 hospitals.