How should a manufacturer separate its office and production networks?
By putting production equipment and office computers in separate network zones with a deliberate, narrow set of permitted connections between them. It is the highest-value design decision available in a factory, because it means an incident on the office side cannot become a production stoppage.
Most small manufacturers run a flat network, and it happened by accident rather than by decision. The office was cabled, then equipment was added as it arrived, each machine plugged into whatever port was nearest, and over years everything ended up able to reach everything. Nobody chose that, and it means a laptop in the front office and a controller running a production line are neighbours in the only sense that matters to malware.
The scenario to design against is specific. Someone in the office opens an attachment, ransomware executes, and it does what ransomware does: it looks for other machines it can reach and encrypts them. On a flat network that includes the computers attached to your production equipment, the machine holding your programs, and the historian recording your process data. The office incident that would have cost a day of paperwork instead stops the line, and the machine-side computers are frequently the hardest to restore because nobody has an image of them.
Segmentation prevents that by making the two environments strangers with a controlled introduction. In practice, for a business this size, that means logical separation using VLANs and firewall rules on the physical infrastructure you already have, rather than building a second physical network. Office devices sit in one zone, production equipment in another, and the routes between them are explicit: this server may talk to that machine on that port, and nothing else is permitted.
Getting it right requires observation before enforcement, and this is the step that determines whether the project succeeds. Before applying rules, watch what actually communicates with what, because manufacturing environments are full of undocumented dependencies: a machine that reports to a server nobody mentioned, a licensing check that reaches the internet, a supplier's remote support connection that has been there for years. Segmenting from a diagram rather than from observed traffic produces a stoppage on day one and a business that will not try again.
Remote access from equipment vendors deserves its own decision, because it is common and frequently uncontrolled. Machine suppliers often want a connection for diagnostics and updates, and in many factories that arrived as a modem or a permanently open tunnel nobody reviews. Replace it with access that is requested, time-limited, logged and closed afterwards. Vendors accept this readily when asked, and the arrangement removes a genuine route into the production zone that sits outside everything else you control.
The zones also let you apply different rules honestly, which is the underrated benefit. Office computers can be patched aggressively, run modern security tooling and be replaced on a cycle. Production computers frequently cannot, because the equipment vendor supports only an older platform and a stoppage costs real money. Rather than pretending they can be managed identically, segmentation lets you accept that a machine-side PC will stay on an old operating system and compensate by allowing it to reach almost nothing.
Tindo Solar is the shape of this in practice. An 80-plus person solar panel manufacturer growing rapidly, where the brief was a modern, externally-supported IT foundation that could scale alongside closing critical cybersecurity gaps. In a manufacturing business those two goals meet at the network, because the infrastructure that carries growth is the same infrastructure that either contains an incident or spreads it.
Two practical points on doing it. Document the result, because segmentation nobody understands gets undone by the next person who needs something to work quickly, usually at ten at night during a breakdown. And build a defined process for exceptions, since somebody will legitimately need a new connection between zones and a system with no route to yes produces a permanent hole punched in a hurry.
The honest caveats. Segmentation is a project rather than a setting, and it needs someone who will do the observation work rather than applying a template. It does not remove the need for the other controls, since it limits spread rather than preventing the initial compromise. And in a very small operation with a handful of machines the effort may exceed the benefit, which is a judgement worth making honestly. If you want it designed around your actual traffic, call 1800 456 567.
Stop an office incident reaching the floor
We design and implement network segmentation for manufacturers, so production keeps running when something goes wrong on the office side.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business