Securing the Plant Floor: What Pacific Northwest Manufacturers Get Wrong About OT and IT Convergence

By Raj Sidhu, Founder & CEO of inTech Consulting, author of "Beyond the Prompt: A Business Owner's Guide to Understanding AI." Published September 29, 2026.

The most common mistake Pacific Northwest manufacturers make is running a flat network where a single compromised office workstation has a direct path to the machines on the floor. Fixing that starts with segmentation and an honest asset inventory, not a new firewall brand or a bigger budget line.

What's the Real Difference Between IT and OT Environments?

IT exists to move and protect data. OT exists to keep physical processes running safely and continuously. That difference drives everything else. An IT server can reboot at 2 a.m. for a patch with no one noticing. A PLC controlling a stamping press cannot go down mid-shift without stopping production or, worse, creating a safety incident.

That's why OT environments tolerate patching badly. A patch that's routine on a laptop can be untested against the specific firmware version running a twenty-year-old machine controller, and a failed patch on the floor costs a lot more than a failed patch in an office.

Why Does a Flat Network Put the Whole Plant at Risk?

In a flat network, office workstations, the ERP system, and the machines on the floor all sit on the same broadcast domain with no meaningful separation. That means a phishing email opened at a front-office desk can, within the same network, reach the PLCs running production equipment.

This is precisely how a number of well-documented manufacturing ransomware incidents actually spread once inside: not through a direct attack on OT, but through lateral movement from a compromised IT endpoint into an unsegmented OT network.

What Is the Purdue Model, in Plain Language?

The Purdue Model organizes a manufacturing network into layers, from the physical process at the bottom up through control systems, then a demilitarized zone, then the business IT network at the top. The point isn't to memorize the layer numbers. It's the principle underneath: traffic between the office network and the plant floor should pass through a controlled, monitored zone, not flow directly.

In practice, that means your ERP system talks to a defined gateway, not directly to a PLC. A compromised laptop in accounting shouldn't be able to reach a machine controller without crossing a boundary that logs and can block that traffic.

What Should a Manufacturer Actually Do First?

Four steps, in order, before anything else.

  1. Build a real asset inventory. Most plants can't answer, with confidence, exactly what's connected to the network, what firmware it's running, or who has remote access to it. That inventory is the foundation everything else depends on, and it's the step most often skipped in favor of buying a security tool first.
  2. Segment the network. Separate OT from IT with a firewall or managed switch configuration that enforces the boundary, not just a diagram that shows one on paper.
  3. Gate remote vendor access. Equipment vendors often have standing remote access for support. That access should be time-limited, logged, and require approval, not an always-on VPN credential sitting unused between service calls.
  4. Document what can't be patched, and compensate for it. A legacy Windows system running a machine controller the vendor no longer supports isn't going away this quarter. Isolate it, monitor it, and restrict what can talk to it, rather than treating it as an unsolvable problem.

Not sure what's actually connected to your plant network? Get a straight assessment of your OT and IT environment before segmentation planning starts.

Get the Assessment Book a 30-Minute Call

What Do You Do When the Vendor Won't Support an Upgrade?

This is the scenario that stalls most manufacturers. The machine still runs fine, the controller software is unsupported, and the vendor's answer is "replace the equipment." Full replacement isn't realistic on most capital budgets.

The realistic path is isolation rather than replacement: put the legacy system on its own segmented zone with tightly restricted inbound and outbound rules, remove it from any path to the internet, and monitor traffic to and from it specifically. This won't make the system current, but it contains the exposure to a single, watched zone instead of the whole network.

Illustrative example, not a specific client engagement: a tier 2 machining supplier in the Kent Valley running a 2008-era CNC controller isolated that single machine onto its own VLAN with no direct internet path and remote vendor access gated through a scheduled, logged connection. The controller itself never changed. What changed was that a compromise anywhere else on the network could no longer reach it.

What Do IEC 62443 and NIST SP 800-82 Actually Cover?

IEC 62443 is the leading international standard for industrial automation and control system security, and it maps closely to the segmentation and zone-based approach described above. NIST SP 800-82 is the U.S. government's guide to industrial control system security and covers similar ground with a framework more familiar to defense supply chain manufacturers already working with NIST SP 800-171.

Neither standard requires a manufacturer to become a compliance department. Both point toward the same practical starting point: know what's on the network, segment it, and control access.

Why Does This Matter More for PNW Aerospace and Defense Suppliers?

Manufacturers in the Pacific Northwest aerospace and machining supply chain face a second layer of pressure beyond general ransomware risk. Prime contractors are increasingly requiring evidence of security controls, including network segmentation, as part of supplier qualification, independent of where CMMC's federal timeline currently stands. Organizations like the Pacific Northwest Defense Coalition (PNDC), the Pacific Northwest Aerospace Alliance (PNAA), and the Association of Washington Business (AWB) have all flagged OT security as a growing supplier expectation, not a future one.

The Kent Valley industrial corridor carries a dense concentration of tier 2 and tier 3 suppliers, many running the exact legacy equipment profile described above. Segmentation work started now positions a supplier ahead of the requirement rather than scrambling to document it during a bid.

Frequently Asked Questions

What's the difference between IT and OT security?

IT security protects data and business systems and tolerates routine patching and downtime. OT security protects physical processes and equipment where unplanned downtime or a failed patch can stop production or create a safety incident, which means OT requires a more cautious, segmented approach.

Why is network segmentation important for manufacturers?

Without segmentation, a compromised office workstation can reach machine controllers directly. Segmentation forces traffic between IT and OT networks through a controlled, monitored boundary, which is how most real-world manufacturing ransomware incidents are contained or, without it, allowed to spread.

What is the Purdue Model?

A framework for organizing manufacturing networks into layers, from the physical process up through control systems to business IT, with the principle that traffic between layers should pass through a controlled zone rather than flow directly between the office network and the plant floor.

What should we do about legacy equipment the vendor won't support?

Isolate it on its own segmented network zone with restricted inbound and outbound access and no direct internet path, and monitor traffic specifically to and from that system, rather than treating the lack of vendor support as an unsolvable problem.

Do IEC 62443 and NIST SP 800-82 apply to small and midsize manufacturers?

Both provide practical frameworks for industrial control system security that scale to any size manufacturer, centered on the same starting point: asset inventory, network segmentation, and access control, regardless of whether the manufacturer pursues formal certification against either standard.

How does OT security connect to CMMC and defense supply chain requirements?

Prime contractors in the aerospace and defense supply chain are increasingly requiring evidence of network segmentation and OT security controls from suppliers independent of CMMC's federal certification timeline, making this a supplier qualification issue now rather than a future compliance deadline.

Get a clear picture of what's actually connected to your plant network. We work with manufacturers across the Pacific Northwest aerospace and industrial supply chain on OT and IT segmentation, asset inventory, and vendor access control.

Get the Assessment Book a 30-Minute Call