OT/IT segmentation is the separation of operational technology — the systems that run physical processes like the power grid, water treatment, rail, or a factory floor — from information technology, the corporate network of email, files and business applications.
What it is
OT and IT have very different priorities. IT prizes confidentiality and frequent change; OT prizes safety, availability and stability, often running equipment with lifespans measured in decades. Keeping them segmented means traffic can only cross the boundary along tightly controlled, pre-approved paths — so a problem on the IT side (a compromised laptop, malware) can’t reach into systems that control physical processes.
Segmentation is usually enforced with the same building blocks as any isolated network — separate routing domains and carefully controlled crossing points (see network segmentation).
Why it matters
As OT and IT converge for efficiency, the boundary between them becomes both more useful and more dangerous. A segmentation error here isn’t just an outage — it can be a safety and compliance event. Critical-infrastructure frameworks around the world now treat IT/OT segmentation as a core control, and increasingly require organisations to demonstrate it on an ongoing basis, backed by evidence of configuration and change.
What good looks like
The bar has moved from designing segmentation to continuously proving it. That means always knowing which systems can reach which, watching the crossing points, alerting the instant something bridges the boundary that shouldn’t, and keeping the change and configuration history that auditors ask for — so “it’s isolated” is a fact you can demonstrate, not a claim you hope holds.