Phi Tech Solutions

Engineering for process plants since 2005

phitech.com.pk (opens in a new tab)

Process engineering, process control and OT security, in one company.

Phi Tech Solutions has worked in process plants since 2005. PhiSecure is its OT cybersecurity practice, working alongside the company's process engineering, process control and reliability teams.

Visit phitech.com.pk (opens in a new tab)
Network architecture drawings spread on an engineering desk with a laptop, a tablet and equipment racks behind

Design

IT and OT Network Architecture Design

We design a zone and conduit architecture for your plant, based on the Purdue model and the constraints your operations work under.

Our approach

  1. Stage 01AssessMeasure your exposure
  2. Stage 02DesignPlan the architecture
  3. Stage 03DeployInstall the technology
  4. Stage 04SustainMaintain security
01

Overview

What the service covers and why it matters

You receive the design rationale, the drawings and a written record of what is allowed to pass between the plant and the business network. A contractor can price the work from these documents without further input.

The design follows the Purdue model, the reference that OT vendors and auditors already use, so the people who build it can work from it directly.

At a glance

Standard
Purdue model
Stage
Design, stage 2 of 4
Usually follows
Risk assessment
Sectors
All

What the design covers

  • Which assets belong in which zone, and why
  • What traffic may pass between zones, and in which direction
  • Where boundary devices are placed, and which team is responsible for each one
  • How engineers and vendors get remote access without a permanent opening
  • How the design accommodates new units added later
  • Which parts can be built while the plant runs, and which need a shutdown window

Why it matters

Reference diagrams assume a plant built at one time, by one contractor, to one standard. Most plants were built in stages by different contractors, and the drawings no longer match what is installed.

Segmentation projects often fail because the target design is drawn without checking what the process needs to communicate with. Production is then disrupted, the firewall is bypassed and the design is abandoned.

We check the design against the plant and its operations before any cable is moved, so that it can be built as drawn.

02

Scope

What this service does not include

  • Not a firewall purchase.Nothing is bought until the design shows what is needed and why. The choice of products and suppliers stays with you.
  • Not a penetration test.We do not attack any system, and we do not run scans that could disturb a controller.
  • Not a paper exercise.The design is only complete when it can be built in your plant, within your constraints.
  • No shutdown.We do not change or interrupt any running system during this work.
03

How it works

The steps and what you receive

  1. The as-built plant documented from drawings and a site walk
  2. Process constraints agreed with operations staff
  3. Zones and conduits proposed and reviewed with your team
  4. High level design approved before detailed design begins
  5. Low level design and drawings that a contractor can price
  6. A build sequence planned so that most of the work can be done while the plant runs

What you receive

  • High and low level designThe design rationale and the detailed design, both documented and both yours to keep.
  • Zone and conduit drawingsIn a format your contractor can price and build from.
  • Defined data pathsWhat passes between the plant and the business network, in which direction, and who approved it.
04

Who it is for

When this service is the right choice

  • You are about to invest in firewalls, switches or a DMZ
  • You have been asked for a segmentation plan and do not have one
  • A new unit or vendor connection is planned and no one owns the network boundary
  • An assessment has found that your control network is flat

Related services