Most industrial networks are flat: every PLC, HMI and engineering laptop sits on the same broadcast domain. Segmentation does not require a security team or a six figure project. It starts with a managed switch and a clear map of what needs to talk to what.
What does network segmentation actually mean on a plant floor?
It means splitting the network into zones so that a device compromised in one zone cannot reach devices in another by default. On a plant floor that usually means separating the machine network (PLCs, drives, safety devices) from the office network (laptops, printers, email) and from any network with internet access, using VLANs and a firewall or managed switch ACLs to control what traffic can cross between them.
A flat network turns one infected laptop into a plant wide problem
Without segmentation, a single infected engineering laptop plugged into the same switch as the PLCs has direct network access to every controller on that switch. Ransomware and industrial malware that spread over standard Ethernet, such as the well documented cases affecting Windows-based HMI and engineering workstations, rely exactly on this: flat access from IT to OT with no boundary in between.
VLANs are the cheapest real segmentation tool available
A managed switch with VLAN support, available for a fraction of the cost of a dedicated OT firewall, lets you split machine traffic, HMI traffic and engineering access into separate logical networks over the same physical cabling. Traffic between VLANs only crosses through a router or firewall, where it can be filtered by port and protocol. This is the single highest impact, lowest cost step available to a plant without a dedicated security team.
The Purdue model is a reference, not a checklist
The Purdue Enterprise Reference Architecture describes industrial networks as layers, from field devices at the bottom to enterprise IT at the top, with a demilitarized zone (DMZ) separating OT from IT in the middle. Few real plants match it exactly, and that is fine. What matters is the principle it encodes: control traffic stays in its own zone, and anything crossing between OT and IT passes through a controlled, monitored point rather than a direct connection.
Default credentials and open ports are still the most common way in
Segmentation limits how far an intrusion can spread, but many industrial devices are still reachable with factory default logins, or expose services such as FTP, Telnet or an unused web server that were never disabled after commissioning. Changing default credentials and disabling unused services on every PLC, HMI and managed switch closes the gap segmentation alone does not cover.
What a first segmentation pass looks like without a dedicated security team
A practical starting point: map every device currently on the machine network and what it actually needs to talk to, put PLCs and drives on one VLAN, HMIs and engineering access on another, block direct internet access from the machine VLAN entirely, and route anything that needs to leave OT, historian data, remote support, through a single controlled point. None of this requires new controllers or replacing existing hardware, it is a switch configuration and a network diagram.