Somewhere in your document management system is a network segmentation diagram. It has firewalls drawn as neat little brick icons, VLANs labeled by cell or line, and a DMZ sitting politely between IT and OT. It was probably accurate the day it was drawn. It is almost certainly not accurate now. That gap — between the segmentation you designed and the segmentation you actually have running on the floor — is about to become a much more expensive problem than it used to be.
CISA’s work formalizing secure-by-design pledges, and the attestation frameworks that major automation and control system vendors have been building out through 2025 and into 2026, is pushing the industry toward a world where “we have a segmentation plan” isn’t good enough. Attestation means someone signs their name to a claim that the architecture matches a standard — typically IEC 62443’s zone and conduit model — and increasingly that claim needs evidence behind it, not just intent. Cyber insurers are moving the same direction independently, adding documented network segmentation to renewal questionnaires and, in some cases, to binding conditions. If you can’t produce current, verifiable segmentation evidence, you’re looking at higher premiums, coverage exclusions, or a renewal that just doesn’t happen.
My argument here is simple: plants that treat this as a paperwork exercise will get caught flat-footed, and plants that treat it as a new procurement cycle will overspend and still miss the actual problem. The fix is neither. It’s an audit of what you already have, using tools you probably already own, aimed squarely at the one gap that causes almost every OT segmentation failure — the difference between as-designed and as-built.
Why the diagram and the plant floor disagree
Segmentation diagrams rot for boring, structural reasons. A controls engineer adds a temporary VPN tunnel to troubleshoot a robot cell remotely during a shift and never tears it down. A skid vendor ships a packaged unit with its own embedded switch and a flat network inside that gets bridged into the plant network during commissioning “just for now.” An instrumentation tech runs a flying lead between two cabinets that were supposed to be on separate VLANs because the fieldbus gateway didn’t have a free port anywhere else. None of this gets updated in the Visio file. All of it defeats the zone and conduit boundaries the diagram claims exist.
IEC 62443 is explicit that zones and conduits are supposed to be defined based on risk and then enforced with actual controls — firewalls, managed switch ACLs, unidirectional gateways, physical separation — not just documented as an intention. An attestation built on a diagram nobody has validated against the live network is, in the most literal sense, a false attestation. That’s a legal exposure question as much as a technical one once a named individual is signing it.
The specific gap you need to find first
Before you touch a single switch config, get clear on what you’re actually comparing:
- As-designed segmentation — the zone/conduit architecture in your engineering documentation, commissioning package, or original systems integrator deliverable.
- As-built segmentation — what the network actually enforces today, including every exception, bridge, flat switch, and undocumented remote access path added since commissioning.
Almost every plant has a wide gap here, and almost nobody has measured how wide. That’s the deliverable an auditor or insurer will eventually ask for, whether they call it a segmentation attestation, a network architecture review, or an IEC 62443 zone/conduit assessment. It’s also, not coincidentally, the exact artifact CISA’s secure-by-design attestation language is pushing vendors and asset owners toward producing.
Closing the gap without a new procurement cycle
The instinct in a lot of plants is to solve this with a tool purchase — a new OT asset discovery platform, a new passive monitoring appliance, a consulting engagement to redraw everything from scratch. Sometimes that’s genuinely warranted. But most plants already own enough to do the first, most important pass of this work.
1. Pull what your existing asset inventory tool already knows
If you have any passive network monitoring, an OT asset inventory platform, or even managed switches with decent logging, you have traffic flow data. That data tells you what’s actually talking to what — across VLANs, across what should be conduit boundaries, across the IT/OT DMZ. This is the single fastest way to find undocumented conduits, because unauthorized traffic flows don’t lie the way diagrams do.
2. Map real traffic against the zone/conduit model, not the org chart
IEC 62443 zones should be defined by risk and function — safety systems, process control, supervisory, business systems — not by department boundaries or building layout. Take the flow data from step one and sort it against that model. Anywhere traffic crosses a zone boundary without going through a documented, controlled conduit, you’ve found a finding.
3. Physically verify a sample, not everything
You don’t need to walk every cabinet in the plant. Pick a statistically honest sample across cell types, especially anywhere skid vendors or third-party integrators installed equipment, and physically trace cabling and switch configs against what the traffic data claims. This is where you catch the flat internal networks inside packaged units that never show up in a Layer 3 diagram.
4. Redraw the diagram from the evidence, then date it
The output isn’t a prettier version of the old diagram — it’s a new one built from verified traffic and physical checks, with an explicit revision date and the method used to validate it. That date matters. Insurers and auditors are increasingly asking not just “do you have a segmentation diagram” but “when was it last validated against the live network, and how.”
5. Triage the gaps by consequence, not by ease of fix
You will find things. Prioritize by what a compromised zone could actually reach — safety instrumented systems and anything with physical consequence first, business-adjacent supervisory systems last. Some fixes are a firewall rule change this week. Some require a real project and a capital request. Say so honestly in the documentation rather than quietly deferring it.
What this means for your next twelve months
The plants that get ahead of this treat it as a recurring audit discipline, not a one-time scramble before a renewal deadline. Build the as-built verification into your change management process — any new skid, any new remote access request, any network change triggers a segmentation re-check, not just an IT ticket. That’s a process change, not a purchase order.
The honest reason this matters now is that the excuse is running out. “We have a segmentation diagram” used to be enough to satisfy an auditor skimming a checklist. Attestation frameworks built around secure-by-design principles, and insurers who’ve been burned enough times to start asking harder questions, are both converging on the same demand: show me the network doing what you say it does. If you haven’t checked lately, assume it isn’t, and go find out before someone else asks you to prove it.
This article was written with the assistance of artificial intelligence. While we aim for accuracy, the information may be incomplete, out of date, or incorrect, and should be independently verified before you rely on it for any decision. It is provided for general information only and does not constitute professional advice.
