Resources · Tool
OT/IT Segmentation Planner
Tick the things that happen on your site — a vendor dialling in, a laptop that goes between the office and the floor, a USB stick on an HMI — and the planner maps them onto the Purdue model and ranks every crossing by how far it reaches. It names the control for each one, in the order they are worth fixing.

Everything below runs in your browser. Nothing you enter is sent to us, stored, or logged, and closing the tab discards it. Answering honestly costs you nothing here — none of it leaves the browser, and an incomplete list is the only way to get a wrong answer.
What actually happens on site
UNIT 01These are the twelve crossings we find on real sites. Tick every one that is true, including the ones that are true only occasionally — an occasional crossing is a permanent path.
How the networks are separated today
UNIT 02This decides how much of the risk above is already mitigated — and how much of it is not mitigated by anything, because some crossings walk past a firewall in a rucksack.
Zone map and crossings
UNIT 03
About the model
UNIT 04The zones come from the Purdue Enterprise Reference Architecture as it is used in industrial security work: field devices at Level 0, control at Level 1, supervisory at Level 2, site operations at Level 3, an industrial demilitarised zone at Level 3.5, and the enterprise and the outside world at Levels 4 and 5.
A crossing's risk here is how many levels it spans, plus what it inherently is, less what your current separation already mitigates. A DMZ mitigates the flows that ought to terminate in one. It does nothing at all for an engineering laptop that reads email in the morning and programs a controller in the afternoon, which is why that row stays high however good the firewall is.
This is a planning aid, not an assessment. It cannot see your firewall rules, your patch levels or the access point somebody installed for convenience last year. What it can do is name the crossings that have to be deliberate, which is where most of the argument in an OT security conversation actually sits — and give you the list in a form you can hand to whoever owns the network.
Technical references
UNIT 05What the reasoning on this page is drawn from. Where a standard costs money to read it is marked, and where a free document covers the same ground better it is listed first.
- NIST SP 800-82 Rev. 3NISTGuide to Operational Technology Security. Free, several hundred pages, and the most useful single document in this field. The segmentation logic in our planner follows its zone and conduit reasoning.
- ISA/IEC 62443Paid standardISAThe industrial automation security series. What a customer or insurer will name when they ask how your OT is secured.
- ISA-95Paid standardISAThe enterprise-control integration standard the Purdue level model comes from. Levels 0 to 4 as they are actually defined.
- Industrial control systemsCISAFree advisories and guidance, including the vulnerability notices that will name equipment on your own floor.
Links open in a new tab so anything you have entered above survives. Every one was checked at build time; if one has rotted since, tell us and it comes out rather than getting patched from memory.
Every one of these tools is a compressed version of a conversation. If yours turned up something you would rather talk through than read about, that is what the scoping call is for — bring your result with you.
Have the boundary reviewed before you connect anythingAlso on the shelf
- Tool
Readiness assessment
Score a proposed integration across the five dimensions that decide whether it survives contact with a plant floor, and find out which one is your binding constraint.
- Tool
Payback calculator
Work out the recoverable hours, the build cost band and the payback period on a process you are thinking of automating — including the case where the answer is don't.
- Tool
Scope estimator
Describe the equipment, the sites and the compliance load, and get the complexity band, the ranked cost drivers and an engineering duration range.