A uniform Zero Trust rollout can break the legacy manufacturing IoT devices your plant depends on. Agents, MFA prompts, aggressive scans, and poorly timed segmentation changes may disrupt deterministic communications. They may delay maintenance access or halt production. A security project can then create availability and functional-safety risk.
Zero Trust for IoT: Is It Practicable for Manufacturing? Yes, when controls match the asset, process, and operational risk. Do not force every device into an agent-and-MFA model. You can inventory assets passively and enforce identity through gateways, zones, and a Purdue-aligned DMZ. Compensating controls can protect unmanaged equipment. This approach reduces ransomware and third-party access risk without gambling with uptime.
Zero trust works when each asset gets
Zero Trust is feasible when a plant verifies access at the safest point for each asset. That point may be a gateway, firewall, jump host, or industrial DMZ.
Assets ready for direct controls
IIoT gateways, engineering jump hosts, remote-access portals, SCADA servers, historians, and managed cameras are early candidates. They often support MFA, logging, patching, and modern identity tools. These systems bridge zones. A compromise can become a route into the plant.
Assets needing indirect protection
Use industrial firewalls, network access control (NAC), hardened jump hosts, protocol allowlists, and passive monitoring. A compensating control protects a device that cannot protect itself. Think of a fragile museum item. You do not glue a lock onto it. You protect the room, display case, and visitor path.
Legacy devices need protection around them, not inside them.
Device identity means more than giving an asset a name at deployment. Passive discovery should record each device's expected MAC address, IP address, protocol behavior, owner, location, and approved peers. Plant teams should then review changes. Examples include a new controller, an unknown engineering laptop, or a gateway using an unusual conduit.
Legacy OT devices may not support certificates or agents. In those cases, enforce identity at the switch port, NAC system, gateway, or firewall.
This supports context-based authorization for OT and SCADA security. It avoids authentication delays in deterministic OT traffic.
IT-style controls can disrupt deterministic OT traffic
IT-style Zero Trust can disrupt factory operations when it adds latency. It can also change a fixed path or block an unknown dependency.
Flows that must be mapped first
Passive discovery listens to network traffic without sending probes to controllers. Run it through production, maintenance, shift changes, batch transitions, and backups. In many plants, that means between 14 and 30 days. A single weekday capture is not enough.
Do not place a proxy, inspection engine, or certificate check in a safety-critical loop without controls-engineer approval. The engineer must validate timing and failure behavior. A fail-closed security device may suit a web portal. It may be dangerous between a safety PLC and its required peer.
The most common error is treating OT traffic like office network traffic. Factory messages can depend on fixed timing, known paths, and old protocols.
Choose controls by asset exposure and outage impact
Asset priority should combine production criticality, external exposure, lateral-movement potential, safety impact, and shutdown cost.
The table below supports a first decision. “Direct control” means the device can often support the control itself. “Indirect control” means a nearby system enforces it.
| Asset | Safe first control | Outage risk | Priority |
|---|
| PLC | Firewall allowlist, jump host | High | Protect indirectly |
| HMI | Named accounts, PAM, hardening | Medium-high | High |
| SCADA or historian | IAM, patch plan, logging | Medium | High |
| IIoT gateway | Device identity, MFA, ZTNA | Low-medium | First pilot |
| Legacy sensor | Gateway allowlist, NAC | Medium | Indirect |
| Vendor access | ZTNA, MFA, recorded sessions | Low | First pilot |
PLCs and HMIs need different treatment
PLCs are computers that run physical equipment. Protect them with narrow network conduits, approved engineering workstations, and monitored command paths. Avoid untested agents, automatic updates, or certificate rotation on controllers that cannot tolerate them.
Gateways and vendor sessions come first
A common case involves a supplier troubleshooting a robot cell. An approved, recorded jump-host session cut access from an entire OT subnet. The supplier received access to one workstation for one two-hour window. This reduced risk without touching the robot controller.
Robots and industrial cameras need separate viability decisions. Do not group them with generic endpoints. Treat a robot controller like a PLC. Avoid agents and inline inspection in motion or safety-related paths.
Use an industrial firewall, approved workstation, and protocol allowlist for robot engineering access. Managed cameras are often better direct-control candidates. Their credentials, firmware, and outbound destinations can be governed. Keep cameras in a dedicated video zone. They should have no route to control networks.
One control model does not fit every connected asset. This distinction improves manufacturing and industrial IoT security by avoiding a one-size-fits-all approach.
Purdue zones and the industrial DMZ enforce safe boundaries
A workable architecture uses the Purdue Enterprise Reference Architecture. It separates enterprise IT, plant operations, and basic control layers. Strong controls sit at the boundaries.
A reference path for remote support
A vendor should authenticate with MFA to a ZTNA service. The vendor then enters a hardened jump host in the DMZ. The vendor can reach only an approved HMI or engineering station. The vendor should not receive direct PLC network access or a flat VPN route.
Policies should follow conduits
A conduit is a controlled communication path between zones. Define each rule by source, destination, service, protocol, direction, and time. “Allow OT subnet to OT subnet” is not a conduit. It is a broad opening that helps lateral movement.
Safe enforcement path for a legacy controller
Vendor + MFA→ZTNA→DMZ jump host→Industrial firewall→PLC conduit
Identity checks occur before the controller. The firewall permits only the approved engineering path.
East-west policy should follow production cells and functions. It should not follow only a broad OT subnet. A packaging-line HMI may reach its assigned controllers and historian services. It should not reach another line's PLCs without a documented maintenance need.
Industrial firewalls can enforce cell-to-cell conduits by protocol, destination, direction, and maintenance window. Approved engineers also need tested break-glass access.
Boundaries stop one infected cell from becoming a plant-wide event. This limits ransomware spread while preserving stable, deterministic production communications.
Pilot access paths before enforcing microsegmentation
A low-risk rollout starts with observation. It then uses monitor-only rules. Limited enforcement follows on noncritical paths.
A five-phase rollout that protects uptime
- Discover: Passively identify assets, protocols, and owners for 14 to 30 days.
- Map: Document Purdue zones, conduits, remote paths, and safety dependencies.
- Observe: Run proposed segmentation rules in alert-only mode. Investigate exceptions.
- Enforce: Start with vendor access, gateways, and noncritical IT/OT paths. Keep a tested rollback.
- Expand: Move cell by cell after engineering confirms availability and functional safety.
Track the share of assets found through passive discovery. Track broad rules removed and vendor sessions protected by MFA and recording. Track blocked unauthorized connections that engineers confirm were unnecessary. Also track avoided downtime and unplanned outage minutes.
A pilot succeeds when access shrinks without changing production behavior.
Legacy PLCs need compensating controls, not forced upgrades
Legacy OT can join a Zero Trust program without agents, modern certificates, or device-level MFA.
Do not make a legacy control loop depend on online certificate checks without testing. Controls engineers must approve the failure behavior. Keep certificate checks at gateways and remote-access services where possible. Monitor expiry between 30 and 60 days ahead. Keep a documented emergency process with dual approval.
Controls that contain unmanaged devices
Contain unmanaged devices with the indirect controls described above: firewall and gateway rules, NAC, hardened jump hosts, protocol allowlists, and passive monitoring. For future purchases, require device identity and secure boot. Require supported firmware updates, documented ports, and vendor vulnerability notice periods. NISTIR 8259 and NIST SP 800-213 give U.S. buyers a practical IoT security baseline.
Forced upgrades can create more risk than indirect controls.
Approve a narrow first phase with measurable proof
Approve Zero Trust as a series of bounded plant changes. Do not approve it as a promise to replace every legacy asset.
The best first approval is a 30-to-90-day pilot. It should prove identity coverage and reduce broad access. It should leave production behavior unchanged. Use the CISA Zero Trust Maturity Model and the Cybersecurity and Infrastructure Security Agency performance goals as reference points. Let plant evidence set the pace.
Do not start broad enforcement without passive OT flow observation. Do not start if no operations owner can approve changes. Also wait during production windows where changed communications could affect functional safety. Limit work to inventory, monitoring, and secure remote access. Continue until the plant can validate dependencies.
If your team is preparing a budget request, use the asset matrix above. Ask one production engineer and one security lead to select one pilot. Choose remote access or a gateway. Define its rollback plan and document the downtime risk removed.
Start small, prove safety, then expand one cell at a time.
Common questions
Is zero trust for IoT practical in manufacturing?
Yes, when controls match the asset and process risk. Gateways, vendor access, and IT/OT boundary systems are practical first targets. Legacy PLCs need indirect controls through firewalls, jump hosts, and monitored network paths.
Can a PLC use MFA or endpoint agents?
Usually no. Forcing either control can create availability risk. Apply MFA to the engineer or vendor session. Restrict PLC access through an approved workstation and firewall conduit.
How long should passive OT discovery run?
Run passive discovery for at least 14 to 30 days in most plants. Extend the period for seasonal batches, monthly maintenance, rare changeovers, or standby equipment.
Does microsegmentation add latency to control traffic?
It can when inspection sits inside a real-time control loop. Place enforcement at Purdue zone boundaries first. Controls engineering must validate latency and failure behavior before protecting tighter paths.
What happens if a certificate expires in OT?
An expired certificate can block a remote-access, gateway, or application connection. Monitor expiry 30 to 60 days ahead and name an owner. Avoid untested certificate checks as a single failure point for safety-critical traffic.
What proves the investment is working?
Proof includes more inventoried assets and fewer broad allowed flows. It also includes recorded, MFA-protected vendor sessions and confirmed blocks of unauthorized communications. The strongest measure is less exposure without unplanned production downtime.