Purdue Model – the global standard for industrial network architecture
| Level | Name | Typical devices & systems | Allowed communication |
|---|---|---|---|
| 5 | Enterprise network | ERP, e-mail, internet, office PCs | Only to Level 4 (DMZ) |
| 4 | Site business planning | MES, historians, patch servers, antivirus servers | To Level 3.5 (OT DMZ) and Level 5 |
| 3.5 | OT DMZ (demilitarised zone) | Terminal servers, update mirrors, jump hosts | Strictly controlled, firewalled |
| 3 | Site operations | SCADA, HMI, engineering workstations, alarm servers | To Levels 2–0 and 3.5 |
| 2 | Area supervisory control | Supervisory SCADA, advanced controllers | To Level 1–0 |
| 1 | Basic control | PLC, RTU, DCS controllers | Only to Level 0 and Level 2 |
| 0 | Process | Sensors, actuators, drives, I/O | Only within Level 0 and to Level 1 |
Core principle: zones & conduits
- Each level = separate zone
- Communication between zones only via strictly defined and firewalled conduits
- One-way or heavily restricted data flow (especially IT → OT)
Real-world impact (Polish factories 2024–2025)
- Without segmentation → ransomware from an office laptop shuts down the entire production line in <4 h
- With correct Purdue segmentation → infection stops at Level 5/4, production continues uninterrupted
Proper implementation of the Purdue model is mandatory for NIS2, ISO/IEC 62443 and Polish KSC/UKE requirements.