Securing Critical Infrastructure Through OT and IT Segregation
Executive Summary
As cyber threats targeting critical infrastructure expanded, a major Australian mining organisation launched an extensive program to fortify its operational technology (OT) networks and enterprise IT environments.
Historical convergence between corporate IT systems and industrial processing environments had created significant vulnerability vectors. Shared identity domains, co-mingled virtualization infrastructure, and flat network routes elevated the risk of enterprise ransomware or phishing breaches propagating directly into critical production and processing systems.
FLUX IT was engaged as a consultant to review, and co-execute an end-to-end industrial segregation program. Over the project lifecycle, FLUX IT delivered full Active Directory isolation, network micro-segmentation across a hardened Industrial Demilitarized Zone (IDMZ), and non-disruptive migration of live industrial applications across Cisco UCS blade platforms and VMware clusters, establishing sovereign operational boundaries with zero disruption to continuous mining production.
Dual-Zone Honeycomb Architecture
The infographic below illustrates the physical and logical boundary engineered between enterprise IT workloads and sovereign operational technology (OT) systems across the central Purdue demarcation line:
Operational Vulnerabilities Identified
The mining enterprise maintained highly automated, continuous processing operations where even minor control anomalies or unexpected outages carried severe safety, environmental, and financial implications. Architectural assessment identified four critical risks:
- Shared Active Directory Dependencies: A single-forest identity architecture allowed compromised corporate enterprise accounts to potentially escalate privileges into plant control domains.
- Flat Inter-Zone Communication: The absence of an enforced Industrial Demilitarized Zone (IDMZ) permitted direct, unmonitored IP routing between standard office subnets and PLC controllers.
- Shared Virtualisation Compute Clusters: Co-mingled virtual machines across enterprise hypervisors created resource contention liabilities and maintenance-related downtime risks for SCADA servers.
- Zero Downtime Tolerance: The continuous 24/7 crushing, haulage, and refining schedule meant that structural identity, firewall, and compute cutovers had to be executed live without halting production.
The FLUX IT Engineering Framework
FLUX IT reviewed and implemented a sovereign, zero-trust industrial framework aligned strictly with the Purdue Enterprise Reference Architecture (PERA), decoupling critical process control from enterprise vectors:
Sovereign Dual-Forest Identity Architecture
Designed and built a completely isolated Active Directory forest dedicated entirely to Operational Technology (OT). Eliminated all cross-forest trusts with the corporate IT domain, enforcing dedicated administrative jump-bastions and strict multi-factor authentication for maintenance access.
Purdue Model IDMZ & Micro-Segmentation
Deployed a hardened Industrial Demilitarized Zone (Level 3.5) with stateful proxy firewalls. Terminated all direct inter-zone IP sessions, ensuring only strictly inspected, encrypted application-level data transfers could traverse between corporate ERP and plant telemetry.
Cisco UCS Compute & SAN Modernisation
Engineered dedicated, resilient computing infrastructure utilising Cisco UCS blade chassis, Fabric Interconnects, and enterprise SAN storage fabrics. Configured isolated VMware vSphere clusters to provide high-availability computing specifically for plant historians and SCADA servers.
Live Workload Migration & Operational Continuity
Developed comprehensive validation protocols and phased cutover schedules. Successfully migrated mission-critical industrial databases, historian feeds, and telemetry systems to the newly segregated infrastructure with sub-second failover and zero production stoppages.
Transformation Matrix
| Domain | Legacy Converged Environment | FLUX IT Segregated Architecture |
|---|---|---|
| Identity & Directory | Single enterprise Active Directory domain controlling both IT and OT assets. | Sovereign Multi-Forest Model with isolated OT directory and jump-host bastions. |
| Network Perimeter | Direct routed IP communication between corporate office LAN and plant subnets. | Hardened Purdue Level 3.5 IDMZ with no direct routing and proxied data exchanges. |
| Compute & Storage | Shared virtualization clusters hosting corporate and industrial workloads. | Dedicated Cisco UCS Blade Fabric and isolated VMware clusters for plant telemetry. |
| Access Control | Standard corporate credentials capable of managing field operational assets. | Role-Based Administrative Bastions requiring separate, privileged OT credentials. |
| Lateral Threat Risk | High risk of enterprise ransomware propagating directly into plant PLC controllers. | Deterministic Blast-Radius Containment blocking all lateral malware traversal. |
Verified Business Impact
The segregation program delivered long-term industrial cyber resilience, establishing a hardened defensive perimeter without imposing operational overhead on daily mining production:
- Deterministic Threat Containment: Established impenetrable logical boundaries between enterprise networks and plant control systems, neutralizing lateral propagation pathways.
- Zero Operational Disruption: Completed identity migrations, network micro-segmentation, and compute cutovers without interrupting 24/7 mining operations or ore dispatch.
- Purdue Compliance Alignment: Transformed infrastructure to meet leading critical infrastructure security benchmarks and Australian industrial cybersecurity guidelines.
- Compute Resilience: Upgraded Cisco UCS and VMware infrastructure delivering verified high-availability failover and dedicated performance for industrial telemetry.
- Sovereign Administration: Enforced rigorous least-privilege governance, ensuring compromised corporate accounts cannot influence process control operations.
Capabilities & Technologies Involved
FLUX IT Capabilities Demonstrated
- OT Security Consulting
- Industrial Network Segmentation
- Critical Infrastructure Protection
- Active Directory Multi-Forest Design
- Cisco UCS Architecture & Deployment
- VMware Virtualisation
- Enterprise Storage Fabrics
- Application Migration Support
Core Technologies Deployed
- Cisco UCS Blade Servers
- Cisco Fabric Interconnects
- VMware vSphere & vCenter
- Active Directory (Isolated Forest)
- Industrial Demilitarized Zone (IDMZ)
- Purdue Model Architecture
- Enterprise SAN Storage