Is the Purdue Model still relevant for OT security with the rise of Cloud and IIoT?
Traditional OT security relies on the Purdue Enterprise Reference Architecture (PERA) to air-gap systems. But with IIoT sensors sending data directly to the AWS/Azure cloud, isn't the Purdue Model dead? How do we maintain a secure perimeter when every sensor is now an entry point for an attacker?
2025-09-22 in Operational technology by Linda Moore
| 11075 Views
All answers to this question.
The model still provides the best "Defense in Depth" strategy. You just have to treat the Cloud as a new layer (Level 5) and secure the transit.
Answered 2025-01-15 by Barbara Nelson
-
Exactly, Barbara. The principles of layering haven't changed, only the location of the data processing has shifted slightly toward the edge.
Commented 2025-01-20 by Linda Moore
The Purdue Model isn't dead, but it has definitely evolved into a "Cell/Zone" architecture under ISA/IEC 62443. While sensors might talk to the cloud, they should still go through an industrial gateway at Level 2 or 3 that acts as a proxy. This prevents a direct "pipe" from the internet to your process controllers. In our 2024 refresh, we used micro-segmentation to ensure that even if a cloud-connected sensor is compromised, the attacker cannot move laterally to the safety instrumented systems (SIS). It's about logical separation now.
Answered 2025-11-05 by Patricia Taylor
Are you seeing more success with software-defined networking (SDN) to enforce these zones, or are you sticking with physical hardware firewalls?
Answered 2025-12-12 by Thomas Wright
-
Thomas, we've found that SDN is great for flexibility, but many of our older switches don't support it. We ended up using a hybrid approach with ruggedized hardware.
Commented 2025-12-20 by Daniel Scott
Write a Comment
Your email address will not be published. Required fields are marked (*)

