OT Security Architecture
Secure IT/OT data paths without direct access to the controller
ZenFactory shows more than protocols. The demo shows how an industrial architecture draws security boundaries: production data flows outward, while process write commands and model delivery follow separate, constrained paths with their own approvals.
Measured values. Measurements flow from the control network through the edge computer and an approved conduit into the OT DMZ. From there, the historian, asset administration shell and analytics read them.
Write path. A setpoint command returns through the same boundary: Policy Gate, human approval, canary and watchdog, then via the edge gateway to one of 21 approved points — for example the feed override at ST020, capped at ±0.08 per step.
Model rollout. The registry does not open a connection to the plant: the edge device pulls an evaluated, signed model over a TLS session it initiates. Planned inference runs locally; its finding follows the telemetry path without PLC write access.
Click a component
Direct IT/AI access to the PLC or process values is blocked. The attempt ends at the firewall; model operation is separate and uses signed delivery to the edge.
Architecture principle
AI, optimisers and conventional analytics generate proposals. Deterministic policies, defined write points, human approval for risky actions and a monitored trial run remain authoritative. A model has no direct PLC access. A separate rollout is planned: the edge device pulls evaluated, signed artefacts over a TLS session it initiates for local inference; this does not grant process write access.
Measurements and findings
Sensors → edge inference → broker/historian → control-loop proposal
Process write path
Policy Gate → human approval → canary → watchdog → 21 approved points
Model delivery · planned
Historian → training/evaluation → registry → edge pull over TLS
Evidence in ZenFactory
- OT-DMZ: Broker and historian-facing components logically separated from the control network.
- 21 write points: the only process write path to the controller, not general remote control — example ST020 in Governed write path.
- Policy Gate: safety, quality and energy are checked before execution.
- Audit Ledger: proposal, gate, approval, execution and effect remain traceable.
- Model registry: planned rollout of evaluated, signed models for edge inference only.
What the demo shows for OT Security Architect skills
| Skill | Concrete evidence |
|---|---|
| Develop OT security architecture | Zones, conduits, firewall boundaries and permitted services are visibly modelled. |
| Implement Industrial Security | Write permissions are limited to defined points and pass through Policy Gate, approval and trial run. |
| Own IT/OT integration | OPC UA, Modbus, MQTT/Sparkplug, historian and AAS are connected. Model rollout to the edge and process access remain separate paths. |
| Communicate risks | Every boundary names purpose, evidence and limit of the demo. This creates an architecture story that can be reviewed. |