Skip to Content

You can only separate what you know is on the network

Why separating the production network from the office network starts with a complete inventory, and how AIM records, assesses and documents that installed base.

The typical starting position

In many manufacturing companies that have grown over time, there is exactly one network. Machine controllers, operator panels, measuring stations and test benches sit in it on equal terms with office PCs, the ERP server, printers and the guest WLAN.

Historically this is understandable. Production was connected step by step, and every new machine went wherever a network socket happened to be free. Anyone who asks today which devices are on the shop floor and what condition they are in usually receives a list that nobody keeps up to date.

Why this is a problem

Production technology ages differently from office IT. A machine tool runs for fifteen or twenty years, and so, often, does the controller it was delivered with. Operating systems without manufacturer support are the rule in production halls, not the exception. Patching is frequently impossible, because the machine manufacturer does not release changes or because the warranty depends on it.

These systems are therefore permanently vulnerable, and that cannot be changed. What can be changed is how easily they can be reached. In a flat network the rule is simple: whatever hits an office PC also reaches the controller.

At exactly this point, however, separation projects rarely fail for technical reasons. They fail on the state of the data. Zones cannot be cut sensibly while it remains unclear which devices exist, who talks to whom and which configuration is currently running. Separating without that picture risks precisely what everyone fears: an idle hall on Monday morning.

The approach

The separation itself follows the zone model as described, among others, in IEC 62443. Areas with different protection requirements are bounded off, and the transition between them is controlled. AIMdefense forms that transition.

The foundation for it is provided by AIM – Advanced Infrastructure Management:

  • Automatic asset discovery across manufacturer and site boundaries. Only once it is established which systems are working on the network can it be decided which device belongs in which zone.
  • Assessment through the VAS module, applied directly to the recorded installed base and without an additional third-party solution. With production technology this is done with appropriate restraint, because active scans can disturb sensitive controllers.
  • Central configuration backup. Device states are backed up automatically, changes are traceable and a defined state can be restored. For a changeover in a maintenance window, this is the fallback.
  • Integrated wiki. Which machine sits in which zone, which communication relationship is justified in operational terms and who approved it is held where the work is done rather than in a separate repository.
  • Maintenance calendar for the individual systems, with deadlines for licence renewals and warranties held in one place.

The layout of the zones therefore stops being an estimate and becomes a decision based on the actual installed base.

Implementation without stopping production

The usual objection is this: we do not know exactly who talks to whom, and if we separate the networks, the hall comes to a halt.

That is why the approach starts with observation rather than with rules. The installed base is recorded, the actual communication relationships are captured and the configurations are backed up. Only once the picture is complete do rules take effect at the zone transition, first logging, then blocking. The changeover itself takes place in a planned window, usually during a maintenance break that is scheduled anyway or at the weekend.

After the changeover, the installed base stays under management in AIM. New devices on the shop floor are noticed instead of quietly appearing on the network, and the zone layout stays maintained rather than frozen.

What changes afterwards

The vulnerable legacy systems remain vulnerable, and no separation changes that. But they can no longer be reached from every workstation, and their condition is known and assessed for the first time.

For companies that have to provide evidence to customers, insurers or auditors, this is the real benefit. A documented zone structure with a recorded installed base, backed-up configurations and continuous assessment can be audited. This does not replace certification, but it does support the evidence that the separation is not only planned but also demonstrable.

At a glance

Field of applicationManufacturing, mechanical engineering, industrial production
Initial problemShared network for production and office IT, incomplete inventory
AIM productsAIM including VAS module, AIMdefense
Role of AIMAsset discovery, assessment, configuration backup, documentation
ApproachRecord the installed base, observe, logging rules, changeover in a maintenance window
OrientationZone model in line with IEC 62443

More about AIM

For the modules behind asset discovery, VAS assessment, configuration backup and wiki, please see the Modules page.

For an example of how this foundation is built in a grown environment with IT and OT devices, see the success story Hospital group with more than 20 hospitals.