Network Segmentation for Manufacturers: Keeping the Plant Floor Safe

Walk into most small manufacturers and you will find one flat network. Front-office PCs, the guest Wi-Fi, label printers, the ERP server, the PLCs, the HMIs, and the press that has been running the same program for eleven years all sit on the same address space, all able to reach each other. It works — right up until the day it does not.

Why one flat network is a production risk

On a flat network, a phished email in accounting is one hop from the plant floor. Ransomware does not know or care that a control panel is "just a machine." It looks for anything reachable, spreads, and encrypts what it can. Even when malware cannot infect a controller directly, the noise it generates — port scanning, broadcast traffic, encrypted file shares — is often enough to stall the systems that feed those controllers their instructions.

The consequence is different in manufacturing than it is in an office. When email goes down, people are annoyed. When the line stops, you are paying labor to stand still, missing ship dates, and explaining it to your customers.

Why you cannot just patch OT gear like a PC

The usual advice — patch everything, install the security agent, reboot monthly — runs into hard walls on the operations technology (OT) side:

  • Vendor lock. The machine builder validated a specific software and OS build. Patching it yourself can void support, and in regulated shops it can invalidate qualification.
  • Old operating systems by design. Plenty of HMIs still run embedded builds of Windows that have been out of support for years. The machine is fine. The OS underneath it is not, and there is no update path.
  • Uptime. There is no maintenance window. Rebooting a controller mid-run is not a minor inconvenience; it can mean scrapped material and a requalification cycle.
  • No room for agents. Many control systems will not run modern endpoint protection, and some vendors explicitly forbid it.
  • Mismatched lifecycles. A capital machine is expected to last twenty years. The computer bolted to the side of it was never going to.

Since you cannot harden the device, you harden what can reach it. That is segmentation.

What practical segmentation looks like

  1. Inventory first. You cannot segment what you have not found. Identify every device on the floor, what it talks to, and which vendor supports it. This step routinely surfaces forgotten cell modems and unmanaged switches.
  2. Separate with VLANs. Split the network by function: office, guest, cameras and building systems, and OT. Guest Wi-Fi in particular should never share a broadcast domain with production.
  3. Put a firewall between IT and OT. Default deny, then allow only the specific flows the business actually needs — a historian pulling data, an MES pushing work orders. Everything else stays blocked.
  4. No direct internet for OT. Control devices should not browse, fetch updates, or be reachable from outside. If a machine needs to send telemetry, broker it through a controlled system in the middle.
  5. Control vendor remote access. Standing remote-access tools and cellular modems installed by machine builders are one of the most common back doors we find. Replace them with brokered access that is requested, time-boxed, multi-factor, and logged.
  6. Monitor passively. OT traffic is predictable. Once you know what normal looks like, an unexpected device or protocol stands out immediately.

Doing it without stopping production

The fear that segmentation means downtime is fair, and it is why so many shops never start. It does not have to work that way. Map traffic passively for a few weeks first so the rules are based on real behavior, not guesses. Run new firewall policies in log-only mode long enough to catch the flows nobody documented. Then cut over one cell or one area at a time, during downtime that is already scheduled, with a tested rollback. Segmentation done in stages is boring, and boring is the goal.

Where to start

If you only do one thing this quarter, get guest Wi-Fi and vendor remote access off the production network. Those two changes remove the most common paths in and rarely require touching a machine at all. Network support from Equal Tech Solutions covers the rest — inventory, VLAN design, IT/OT firewall policy, and monitoring built around your production schedule instead of fighting it.

If your plant floor and your front office are still one network, that is worth fixing before something forces the issue. Equal Tech Solutions works with manufacturers across Chattanooga, Cleveland, and the Southeast US. Contact Equal Tech Solutions for a straight assessment of your plant network.