What problem does it solve?
Flat OT networks leave PLCs, HMIs, and safety systems exposed to lateral movement and unauthorized access. This Skill guides the design and implementation of IEC 62443-3-2 compliant security zones and conduits, replacing unsegmented industrial networks with enforced, risk-based boundaries.
Core Features & Use Cases
- Zone Partitioning & SL-T Assignment: Partition IACS assets into zones by criticality and assign Security Level Targets aligned with the Purdue Reference Model.
- Conduit & Firewall Configuration: Configure industrial firewalls (Cisco ISA-3000, Fortinet, Palo Alto OT) with OT protocol DPI, Modbus function code filtering, and default-deny inter-zone ACLs.
- Data Diode & Validation: Deploy unidirectional historian replication and validate the architecture with cross-zone connectivity tests and a Python data diode validator.
- Use Case: A refinery with a flat 10.10.0.0/16 OT network uses this Skill to baseline traffic, define five Purdue-aligned zones, deploy firewalls in monitor mode, then enforce segmentation during a maintenance window.
Quick Start
Ask the AI to design an IEC 62443 zone and conduit architecture for your facility, including firewall rules, VLAN assignments, and validation tests for your OT network.