Manufacturing environments live at the intersection of two worlds that historically refused to speak to each other: operational technology (OT) that runs the production line and information technology (IT) that runs the business. When those worlds collide without planning, the result is downtime, safety risk, and security exposure. This guide walks through the infrastructure decisions that matter most for manufacturers building or modernizing their IT-OT environment.
OT vs IT Network Separation
The first principle of manufacturing IT is that production networks and business networks should not be flat. A PLC controlling a hydraulic press should not share a subnet with the marketing laptop browsing email. The Purdue Enterprise Reference Architecture provides a model: Level 0-1 covers physical processes and basic control, Level 2 is supervisory control, Level 3 is manufacturing operations (MES, historian), and Level 4 is enterprise IT (ERP, email, internet). A firewall or DMZ should sit between Level 3 and Level 4, and ideally between Level 2 and Level 3 as well.
Practically, this means separate VLANs for OT devices, managed switches with port-level segmentation on the factory floor, and strict rules about what crosses the boundary. Use a jump host in a DMZ for any traffic that must cross between OT and IT — never allow direct browsing from a Level 4 machine to a Level 1 controller. If a vendor needs to access a PLC, they authenticate to the jump host, which sits in a zone you can monitor, log, and disconnect instantly if needed.
SCADA System Security and Industrial IoT on the Factory Floor
SCADA systems and industrial IoT devices share a common vulnerability: many were designed for reliability, not security. Default credentials, unencrypted protocols like Modbus TCP, and devices that can't be patched are common. Start by inventorying every networked device on the production floor — HMI panels, PLCs, smart sensors, barcode scanners, and wireless access points. Identify which devices support authentication and encryption and which don't. For devices that can't be secured, isolate them on a VLAN with no internet access and no routable path to business systems.
Industrial IoT introduces scale to the problem. A facility with 200 smart sensors generating telemetry data needs a data architecture: where does the data land, who can access it, and how long is it retained? Deploy an edge gateway that aggregates sensor data, applies local analytics, and forwards only summarized data to cloud or on-prem systems. This reduces bandwidth, limits exposure, and gives you a single point to enforce access controls rather than 200 individual endpoints.
Backup Strategies for Production Environments
Production backups differ from office backups. An ERP backup that's six hours old is an inconvenience; a PLC program backup that doesn't exist when a controller fails can mean days of line downtime. Maintain current backups of all PLC logic, HMI configurations, drive parameters, and calibration settings. Store these both locally (on a hardened engineering workstation) and offsite (in a secure cloud repository). Label everything with the device serial number, revision date, and the engineer who made the change.
For MES and historian databases, implement application-consistent backups — not just file-level copies. A SQL Server hosting your production historian needs transaction log backups if you want point-in-time recovery. Test restores in a non-production environment at least quarterly. A backup that has never been restored is an assumption, not a recovery capability. Document the recovery time objective (RTO) and recovery point objective (RPO) for each production system, and make sure those numbers align with what operations can actually tolerate.
Compliance: ISO 27001 and NIST for Manufacturing
Manufacturing compliance is driven by customer requirements, not just regulation. Automotive suppliers face TISAX, aerospace faces CMMC and ITAR, and food manufacturers face FDA traceability rules. ISO 27001 provides a certifiable information security management system that's recognized globally — many OEMs now require their Tier 1 and Tier 2 suppliers to demonstrate ISO 27001 alignment. NIST SP 800-171, while designed for federal contractors, has become a de facto baseline for manufacturing cybersecurity because CMMC builds on it.
Start with the CMMC-required practices: multifactor authentication on all systems, FIPS-validated encryption for data at rest and in transit, documented incident response, and continuous vulnerability monitoring. If you handle CUI (controlled unclassified information), you'll need to implement all 110 controls in NIST SP 800-171 and produce a System Security Plan (SSP) that documents how each control is implemented. Begin the SSP early — it's the document auditors will scrutinize most closely.
Disaster Recovery for Production Lines and Vendor Remote Access
Production disaster recovery is measured in hours, not days. A blown motor on a critical line may have a 12-week lead time for replacement; your DR plan should account for the fact that some failures can't be quickly fixed. Identify your single points of failure on each line — the one PLC, the one drive, the one sensor whose failure stops everything. Maintain spares for critical components and document the swap procedure. For IT-dependent lines, maintain a manual operating procedure so operators can continue at reduced throughput if the MES or historian is down.
Vendor remote access is one of the most exploited attack surfaces in manufacturing. Every OEM and systems integrator wants remote access for support, and each connection is a potential entry point. Standardize on a single remote access platform — a VPN with per-vendor credentials, MFA, session recording, and automatic session timeout. Never allow vendors to install their own remote access tools (TeamViewer, AnyDesk, LogMeIn) on production machines. Provide the access platform, enforce the rules, and log everything. Revoke access between support incidents rather than leaving persistent connections open.
Legacy System Modernization
Many manufacturing facilities run Windows XP or Windows 7 on HMI panels because the software vendor never certified their application on newer OS versions. These systems can't be patched, can't run modern antivirus, and often browse the network with no restrictions. Modernize incrementally: first, isolate legacy systems on a dedicated VLAN with no internet access. Then, explore virtualization — many HMI applications can run in a locked-down virtual machine on a modern host, with USB device redirection for any specialized hardware. For systems that can't be virtualized, implement a hardware refresh plan that budgets for replacement over 2-3 years rather than a disruptive rip-and-replace. Prioritize modernization by risk: the Windows XP HMI connected to the internet goes first; the isolated Windows 7 engineering workstation with no network access can wait.
Conclusion
Manufacturing IT is about protecting uptime, not just data. Network separation, SCADA security, production-grade backups, compliance alignment, controlled vendor access, and incremental modernization each reduce the risk of the one event that every manufacturer fears: a preventable line stoppage caused by an IT failure. Build your infrastructure to keep production running, and treat every connected device as a potential point of both productivity and risk.
Beawit Consulting provides IT services to small and midsize manufacturers in the Vancouver and Portland metro area, specializing in Azure, Microsoft 365, hybrid cloud, and network engineering. We understand the unique demands of OT-IT convergence and can help you build infrastructure that protects both your production line and your business systems.
Looking for reliable internet connectivity for your business? Use our Scout lookup tool to search available options from over 75 providers, including AT&T, Comcast, Cox, Crown Castle, Fidium, Frontier, Lumen, Spectrum, Verizon, and Zayo — with instant pricing proposals and contracts.
Contact us at contactus@beawit.net or call (360) 399-6834 to discuss your manufacturing IT needs.