← Blog

NIS2 and OT/IT segmentation: proving the isolation you claim

For years, “we segment IT from OT” was a design statement — something you asserted in an architecture diagram and revisited during the occasional audit. Under the EU’s NIS2 Directive, that era is closing. The bar is no longer whether you designed isolation between your corporate network and your industrial control systems. It’s whether you can prove the isolation still holds today, and demonstrate the change control that has kept it intact since the last time anyone checked.

NIS2 widened the net considerably. It reaches essential and important entities across energy, water, transport, health, digital infrastructure, and public administration — sectors where a network mistake doesn’t just cost money, it can take a service offline for a region. As of May 2026, 21 of 27 member states have transposed the directive into national law, and enforcement is no longer theoretical. In late 2025, Germany’s cybersecurity authority issued formal non-compliance notices to dozens of entities. For essential entities, penalties can reach up to €10 million or 2% of global turnover.

Convergence made the line harder to hold

The reason segmentation is under scrutiny is that OT and IT no longer live in separate worlds. Industrial control systems that were once genuinely air-gapped now share infrastructure with business networks: remote engineering access, historian data flowing up to analytics, vendor maintenance tunnels, shared directory services. Each of those is a legitimate business need — and each is a path that can erode the boundary you drew.

Article 21’s technical measures respond to exactly this. They call for an OT asset inventory, network segmentation between IT and OT environments, and configuration change management for the control systems that run physical processes. Read together, those three requirements describe a single discipline: know what you have, keep the boundary between the two worlds enforced, and control every change that could weaken it.

The hard part is that segmentation is not a static property. A firewall rule added for a temporary project and never removed, a routing change that quietly creates a path around your DMZ, a VRF boundary that shifts during a migration — any of these can open a route between IT and OT without anyone filing it as a security event. The diagram still says you’re segmented. The live network says otherwise. For a deeper primer on the boundary itself, see our note on OT/IT segmentation.

From claim to continuous evidence

Proving segmentation is really a question about state over time. Not “is there a firewall between these zones?” but “has any change in the last quarter created reachability that shouldn’t exist, and can I show an auditor the full history?”

That’s where continuous tracking of deep network state changes the conversation. When routing, BGP, VRF and MPLS boundaries, and device configuration are captured continuously and kept as a history, the IT/OT boundary stops being a claim and becomes something you can query. You can see the segmentation as it actually exists right now, compare it to how it looked before a change window, and produce the configuration and change evidence a regulator expects — without a fire drill every audit cycle.

It also shifts the work earlier. Predicting the impact of a proposed change before it’s made means you can catch the routing edit that would have punched a hole through segmentation before it ships, rather than discovering it in a post-incident review. That’s the difference between demonstrating control and explaining an outage. Our utilities and energy solutions and security and compliance platform are built around this idea: assurance you can evidence, not just assert.

The reframe NIS2 forces

The useful way to read NIS2 is not as a new list of controls, but as a shift in burden of proof. Regulators are increasingly assuming that a boundary you cannot continuously demonstrate is a boundary you cannot rely on. Segmentation drifts. Configurations change. People leave. The entities that will handle enforcement comfortably are the ones who can answer, on any given day, “here is our IT/OT boundary, here is every change that touched it, and here is the proof it still holds.”

Everything Phantom does runs entirely on your own infrastructure — air-gap friendly, with nothing leaving your network — which matters when the environment under scrutiny is critical national infrastructure. If you’d like to see what continuous segmentation evidence looks like against your own topology, book a demo.

Change the network with confidence.

Book a demo