Network segmentation
Network segmentation is the practice of dividing a network into separate, controlled sections so that a compromise in one section does not automatically give an attacker access to everything else. In OT environments, this typically means logically or physically separating corporate IT networks from control-system networks, often with firewalls, unidirectional gateways (devices that only allow data to flow one way, out of the OT network), or a demilitarized zone (DMZ) sitting between the two. The Purdue Model is the most common reference architecture for deciding where those boundaries should sit.