What segmentation actually looks like
- VLANs for office, production, SCADA, Wi-Fi, voice, cameras and guest
- Firewall rules that permit only the traffic required by an application
- Industrial DMZ between control and enterprise zones
- Cell/area zone isolation so one production line cannot affect another
- No direct internet access for production equipment
- Controlled vendor access through a jump server, not a VPN
- Logging and monitoring of cross-zone traffic