The Purdue Enterprise Reference Architecture remains the most widely used blueprint for structuring industrial control system networks. This article walks through the model level by level, explains the pivotal role of the industrial DMZ, and shows how to translate the reference model into a secure, resilient, standards-aligned network design.
1. Why a reference architecture
Industrial control system (ICS) networks fail safely and securely only when they are structured deliberately. The Purdue Enterprise Reference Architecture (PERA) — the “Purdue model” — gives engineers a common language for organising control networks into hierarchical levels, each with a defined function and a defined trust boundary.
Adopted by IEC 62443 and ISA-95, the model turns an abstract goal — “separate IT from OT” — into a concrete, testable network design with clear zones and conduits between them.
2. The levels at a glance
- Level 0 — Field devices: sensors, actuators, valves, motors; the physical process.
- Level 1 — Basic control: PLCs, RTUs, and safety instrumented systems (SIS) that read Level 0 and drive outputs.
- Level 2 — Area supervisory control: HMIs, SCADA, and engineering workstations that supervise a process area.
- Level 3 — Site operations: historians, MES, batch and production management shared across the site.
- Level 3.5 — Industrial DMZ (IDMZ): the brokered boundary between OT (Levels 0-3) and IT (Levels 4-5).
- Level 4 — Site business: enterprise IT for the plant (email, ERP clients, file services).
- Level 5 — Enterprise: corporate data centre, cloud, and wide-area business systems.
3. The industrial DMZ is the linchpin
The single most important design decision is that no traffic flows directly between the enterprise (Levels 4-5) and control networks (Levels 0-3). All exchange is brokered through the Level 3.5 industrial DMZ.
Replicated historians, patch and antivirus relays, jump/remote-access hosts, and reverse proxies live in the IDMZ so that IT systems talk only to IDMZ hosts, and OT systems talk only to IDMZ hosts — never to each other directly. If the IDMZ is compromised it can be shut down without stopping production.
- Terminate every cross-boundary protocol in the IDMZ; do not let it pass through.
- Use separate firewalls (or firewall contexts) on the IT and OT faces of the IDMZ.
- Allow no direct inbound path from Level 4/5 to Level 2/1; brokered, authenticated access only.
- For the highest-assurance flows (e.g. historian egress), consider unidirectional gateways / data diodes.
4. Segmentation within OT: zones and conduits
Segmentation does not stop at the IT/OT line. Following IEC 62443, group assets of equal criticality into zones and connect them only through defined conduits with enforced policy. Segment by process area or cell at Level 2, and isolate safety systems (SIS) from basic process control.
- Give each cell/area its own Level 2 zone; restrict east-west traffic between cells.
- Keep the SIS on a separate, tightly controlled zone — safety must survive a control-network incident.
- Default-deny between zones; permit only the specific protocols and endpoints required.
5. Designing the physical and logical network
- Use industrially-rated, managed switches with VLANs, port security, and deterministic performance.
- Build resilient topologies (ring/redundant-star) with fast failover so a link loss does not stop the process.
- Separate control traffic from engineering and monitoring traffic with VLANs and QoS.
- Plan addressing and naming per level/zone so policy and monitoring are legible.
- Provision out-of-band management and time synchronisation (PTP/NTP) within the OT boundary.
6. The model in a modern world
IIoT, virtualisation, MQTT/OPC UA, and cloud analytics stretch the classic model but do not retire it. The Purdue hierarchy still defines trust boundaries; modern designs layer zero-trust principles on top — per-asset identity, brokered publish/subscribe through the IDMZ, and edge gateways that push data outward without opening inbound paths to control.
The rule endures: data may flow up and out through controlled brokers, but control authority never reaches in from the enterprise.
7. Common pitfalls
- A flat control network with no Level 2 segmentation — one infection reaches everything.
- “Temporary” firewall rules that let Level 4 talk straight to PLCs.
- No industrial DMZ, or an IDMZ that merely routes rather than brokers.
- Safety systems sharing a zone with basic process control.
- Remote-access tools that bypass the IDMZ entirely.
8. How CDS delivers it
Cyber Data Services designs ICS networks from survey to commissioning: current-state assessment, a Purdue/IEC 62443 zone-and-conduit architecture, IDMZ and firewall rule design, resilient switching, secure remote access, and validation before handover — with as-builts and monitoring in place.
Contact info@cyberdatas.com to discuss an ICS network design or segmentation assessment for your site.