OT Security Architecture

Secure IT/OT data paths without direct access to the controller

ZenFactory shows more than protocols. The demo shows how an industrial architecture draws security boundaries: production data flows outward, while process write commands and model delivery follow separate, constrained paths with their own approvals.

Measured values. Measurements flow from the control network through the edge computer and an approved conduit into the OT DMZ. From there, the historian, asset administration shell and analytics read them.

Write path. A setpoint command returns through the same boundary: Policy Gate, human approval, canary and watchdog, then via the edge gateway to one of 21 approved points — for example the feed override at ST020, capped at ±0.08 per step.

Model rollout. The registry does not open a connection to the plant: the edge device pulls an evaluated, signed model over a TLS session it initiates. Planned inference runs locally; its finding follows the telemetry path without PLC write access.

Click a component

CONTROL NETWORK · ISA-95 0–2OT NETWORK · VLANEDGE · CONTROL CABINETBOUNDARY · OT DMZOT DMZ · BROKER, HISTORIAN, CONTROL LOOPIT · ANALYTICS · AIProcess write path · 21 points · e.g. ST020Edge pull · evaluated, signed model · stage 2IT → PLC · BLOCKEDPLC · Line A8 stationsOPC UAPLC · Cell B5 machinesOPC UAPLC · Filling6 unitsOPC UAPCS · Reactors2 vesselsOPC UABand saw ZS-100Built 1998Modbus RTUModbus converterRS-485 → TCPManaged switchDedicated VLAN · no route to office networkIndustrial PC in the control cabinetreads, maps, buffers · only OT-side handoffOPC UA clientSubscription · 250 ms628 variablesModbus connectorPolling · 1 s15 registersEdge calculationOEE · filteringBuffer on disconnectAI inferencelocal · plannedFinding · MQTT 20 sWrite allowlist21 of 670 pointsprocess values onlyFirewall · OT-DMZ3 constrained pathsMQTT broker · OT-DMZSparkplug B · publishallowlisted topicsHistorian · OT-DMZappend-only · TimescaleDBevidence retainedAPI and control loopPolicy → human → canarywatchdog · rollback · ledgerIT · historian reads, training and model managementAAS / twinSemanticsno control accessAnalytics + trainingHistorian · batch windowTraining · plannedModel registryversioned · evaluatedsigned artefactchanges only · ~125 values/sMQTT over TLS · one portInference finding · not a process commandREFERENCE TOPOLOGY · LAB / VIRTUAL · NO PHYSICAL FIREWALL OR PRODUCTION CONNECTION
View the write path in detail →
Measured values · upwards Write path · 21 points Model · training and delivery Direct access · blocked

Direct IT/AI access to the PLC or process values is blocked. The attempt ends at the firewall; model operation is separate and uses signed delivery to the edge.

Architecture principle

AI, optimisers and conventional analytics generate proposals. Deterministic policies, defined write points, human approval for risky actions and a monitored trial run remain authoritative. A model has no direct PLC access. A separate rollout is planned: the edge device pulls evaluated, signed artefacts over a TLS session it initiates for local inference; this does not grant process write access.

Measurements and findings

Sensors → edge inference → broker/historian → control-loop proposal

Process write path

Policy Gate → human approval → canary → watchdog → 21 approved points

Model delivery · planned

Historian → training/evaluation → registry → edge pull over TLS

Evidence in ZenFactory

  • OT-DMZ: Broker and historian-facing components logically separated from the control network.
  • 21 write points: the only process write path to the controller, not general remote control — example ST020 in Governed write path.
  • Policy Gate: safety, quality and energy are checked before execution.
  • Audit Ledger: proposal, gate, approval, execution and effect remain traceable.
  • Model registry: planned rollout of evaluated, signed models for edge inference only.

What the demo shows for OT Security Architect skills

SkillConcrete evidence
Develop OT security architectureZones, conduits, firewall boundaries and permitted services are visibly modelled.
Implement Industrial SecurityWrite permissions are limited to defined points and pass through Policy Gate, approval and trial run.
Own IT/OT integrationOPC UA, Modbus, MQTT/Sparkplug, historian and AAS are connected. Model rollout to the edge and process access remain separate paths.
Communicate risksEvery boundary names purpose, evidence and limit of the demo. This creates an architecture story that can be reviewed.
View controlled write path Resilience and Degraded Mode Network plan and data paths