Zones, conduits, remote access

Network Segmentation Validation

Find out whether your network boundaries actually protect critical systems. GDF tests access between networks and checks remote connections so your team knows which gaps to close.

Water treatment and electrical utility infrastructure.

The engagement

Design intent, compared with the reachable network

Network segmentation validation compares design intent with observed traffic and carefully controlled reachability. GDF reviews the IT/OT boundary, cell and area zones, management networks, safety separation, wireless links, remote access, historian paths, and vendor support channels.

Operator-designated authority approves any active method, process condition, maintenance window, stop points, and rollback plan. A passive or configuration-only review is used where active validation would create unacceptable process risk. The engagement produces evidence, not a marketing certification.

Validation compares the intended zone-and-conduit design with rule sets, observed flows, remote-access paths, recorded exceptions, and any active checks approved by the operator. Findings identify where the boundary holds, where it does not, and what the operator needs to change.

Scope

  • IT/OT boundary and industrial DMZ

    Boundary architecture reviewed against ISA/IEC 62443 zone-and-conduit concepts and the client's own reference design. Broker and DMZ services are examined for direction, protocol, and identity.

  • Cell, area, and safety separation

    Cell and area zone boundaries, safety instrumented system separation, and management network isolation reviewed. Broadcast and multicast leakage between zones is identified.

  • Firewall rule, NAT, and route validation

    Firewall rules, NAT tables, static and dynamic routes, and access control lists compared with intended flows. Overly broad rules and stale exceptions are marked.

  • Remote access and vendor paths

    Jump hosts, VPN concentrators, vendor gateways, cellular modems, and out-of-band management paths reviewed. Session recording and identity binding are checked.

  • Dual-homed, wireless, and alternate paths

    Dual-homed hosts, wireless bridges, engineering laptops, and modem or serial back doors identified. Documented and undocumented paths are separated.

  • Identity and privilege paths

    Trust between IT and OT identity providers reviewed. Cross-domain accounts, service accounts, and shared credentials that traverse zones are marked for correction.

  • Remediation and retest plan

    Recommended changes identify affected owners, protocol, monitoring, safety dependencies, rollback conditions, maintenance windows, and expected risk reduction. Post-change validation covers the approved path.

Separate networks do not mean separated systems

Two systems on different VLANs behind a firewall can still be one hop apart. A routing entry nobody remembers, a firewall exception added during an outage, an administrator account that works on both sides, a remote access tool on a dual-homed machine. Any one of these reconnects what the diagram keeps apart. Network segmentation validation is how you find out whether your boundary enforces the access you intend, or only the access you drew.

If an attacker lands on one side of the boundary, what can they reach on the other? A blocked ping does not answer that. Neither does a screenshot of the firewall policy. GDF answers it with configuration review, traffic evidence and, where you authorize it, controlled testing along specific paths. You get findings with the evidence attached and remediation written for the environment you actually run.

Intended access first, then actual enforcement

We start with the communications that have to keep working. For each material path we record the source, destination, service, direction, owner and reason. Once that table exists, your team has a way to tell a necessary connection from an exception that outlived its purpose. Without it, every rule looks equally important and nothing ever gets removed.

Then we look at three things that answer three different questions. Configuration review of rules, address translation and routes tells us what the devices were told to permit. Passive traffic shows what actually crossed during the observation period. Controlled tests from defined starting positions, where authorized, show what a connection attempt does right now. A rule that looks closed in the config but passes traffic in the capture is a finding either way.

Network paths are half the picture. A rule permitting remote desktop to a jump host says nothing about what the account can do once it is logged in. We look at the accounts, jump hosts, shared credentials and administrative relationships that span the boundary, because shared administrative credentials can extend access wherever the network permits them to be used.

The routes nobody is reviewing

The firewall everyone is auditing may not be the path that matters. A secondary network card on a server, a wireless bridge installed for a temporary sensor, a vendor gateway with its own cellular uplink, an engineering laptop plugged into both networks at once: these bypass the reviewed boundary entirely. We go through access control lists, firewall rules, routing tables and packet-level evidence to establish how traffic actually moves, then compare it with the diagram.

Take a vendor support connection that is supposed to reach one workstation. If the same tunnel lands the vendor on an entire control segment, the problem is the gap between intended and effective access. The report shows the gap and the conditions it depends on, then the specific rule change that closes it without cutting the vendor off from the one workstation they legitimately need.

Findings you can fix and a test you can repeat

Each finding gives you the affected path, the configuration that permits it, the observed behavior, what it means for the business, the proposed correction and how to verify the correction worked. Your network team makes the change. We retest the original path and record whether it is still open. Your auditor gets a before and an after.

In industrial environments the operator approves every active check before it runs. Where a live test would put the process at risk, we rely on configuration and passive data and say so in the report. A trustworthy answer about the boundary is worth more than a dramatic one.

Methodology

How segmentation validation runs

  1. Map

    Design documents, drawings, engineering files, and existing inventories are collected. Intended zones, conduits, and remote access are documented from the operator's perspective.

  2. Observe

    Configurations are exported. Passive traffic is collected at documented points. Identity and remote-access records are gathered for a defined observation window.

  3. Validate

    Observed reachability is compared with intended design. Where approved, controlled reachability tests confirm or reject specific paths under operator supervision.

  4. Recommend

    Findings are ranked by operational consequence. Remediation sequence, owner, protocol, monitoring, rollback, and window are documented. Post-change retest scope is defined.

Evidence commonly examined

Evidence reviewed

  • Firewall, router, and switch configuration exports
  • Passive traffic captures with documented collection points
  • Remote-access logs and identity provider records
  • Engineering drawings, network diagrams, and asset registers
  • Vendor access agreements and monitoring records
  • Controlled reachability tests approved by the operator

What you can expect

What you receive

  • Zone-and-conduit reachability map
  • Ranked findings with operational consequence
  • Recommended remediation sequence with owner and window
  • Post-change retest evidence for validated paths
  • Exception register for compensating controls

Frequently asked

Common questions

Does a VLAN prove isolation?

No. A virtual LAN separates traffic at layer two. Routing and access controls decide what crosses between VLANs, and a vendor bridge, a misconfigured trunk port or an unauthorized cross-connect can make the VLAN irrelevant.

Can you verify changes made by our network team?

Yes. Within the agreed scope, we compare the intended fix with the configuration, the traffic and, where approved, a live test of the path that was supposed to close.

Does this certify the whole environment?

No. The report states the boundaries, dates, methods, tested paths and untested paths it covers. It can feed a broader assurance program, but it is not a certificate for the environment.

Is active testing safe in an OT environment?

Active testing requires operator-designated authority, an approved process condition, stop points, and recovery steps. Passive and configuration-based methods are used where active methods could create risk. The operator retains authority over process safety and change windows.

Does a passing test mean the boundary is fully isolated?

No. Post-change testing covers the approved path and date. It does not establish that every alternate route has been eliminated. The report identifies untested surface and the conditions under which the test was performed.

Can this work satisfy a NERC CIP or Part 500 requirement?

The technical record produced can be used as evidence in a compliance program. Applicability, attestation, and submission remain with the Registered Entity, covered entity, or accountable owner. GDF does not provide legal compliance opinions.

Ask GDF to validate the boundary

Ask GDF to validate the boundary before an exception becomes an exposure. Tell us which systems should be separated, why the separation matters and what testing limits apply. We can scope the network segmentation validation, identify the paths that undermine it, support the fix and confirm whether the fix held. Your initial consultation is free.

Ask GDF to validate the boundary

Related services and resources: OT network assessment, cybersecurity penetration testing.

Talk with an examiner

Discuss your matter and next step

Tell us the systems, evidence and deadline. We can review relevant experience, potential conflicts and the scope before engagement.

Since 1992 · 24/7 dispatch · Court-tested experts

Or call 1-800-868-8189

Email or phone is required. A submission does not create an engagement. For an active incident, please call. Read what we send with the request.

Talk with an examiner

Discuss the matter and the next step.

Tell us what happened and what you need to find out. Speak with a GDF expert about how we can help.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.