Industrial DMZ (IDMZ)
An industrial DMZ (IDMZ) is a buffer network between enterprise IT and the plant control network, often called Purdue Level 3.5, where shared services are hosted so that no traffic passes directly between IT and OT.
An industrial demilitarised zone (IDMZ) is a buffer network placed between the enterprise IT network and the operations or control network, often called Level 3.5 in the Purdue model. Its purpose is to ensure that no traffic passes directly between IT and OT: each side connects only to services hosted in the IDMZ, and firewalls on both sides, or a firewall with separate interfaces, restrict communication to defined flows.
Typical IDMZ services include a replica historian or data broker that publishes plant data to business users, patch and antivirus update servers that stage updates for OT systems, remote access gateways and jump servers for vendors and engineers, and file transfer services. This design lets enterprise applications consume production data and lets support staff reach plant systems without exposing controllers to the corporate network or the internet.
Common design principles are that all sessions terminate in the IDMZ rather than passing through it, that no essential control function depends on IDMZ services, so the plant keeps running if the IDMZ is disconnected, and that the IDMZ is monitored closely because it is a natural target for attackers moving from IT towards OT. Where data needs to flow only outward, data diodes can replace bidirectional firewalls. The IDMZ is a common way to implement IEC 62443 conduits between IT and OT zones.
Key points
- Sits between enterprise and operations networks, often called Purdue Level 3.5
- Hosts brokered services such as replica historians, patch servers and jump hosts
- All sessions terminate in the IDMZ; none pass straight through
- The plant should keep operating if the IDMZ is disconnected
Where AiVibe comes in
In AiVibe's AiAmbA AI Factory, the AiAmbA IoT edge layer keeps writes to machines deny-by-default and AI agents only propose changes that a trained operator confirms. AiVibe's security services include vulnerability assessment and penetration testing, and AiVibe is ISO/IEC 27001:2022 certified.
Related terms
- Purdue ModelOT & Industrial Cybersecurity
- OT Network SegmentationOT & Industrial Cybersecurity
- Data Diode (Unidirectional Gateway)OT & Industrial Cybersecurity
- Secure Remote Access for OTOT & Industrial Cybersecurity
- Industrial FirewallOT & Industrial Cybersecurity
- Zones and ConduitsOT & Industrial Cybersecurity