/ THE SHORT ANSWER
- 01Inventory IT and OT assets.
- 02Observe traffic before blocking it.
- 03Control every vendor connection.
/ dotSuper point of view
Simple, documented boundaries can reduce ransomware blast radius and supplier risk before a company funds a full security transformation.
What changed?
Connected production systems increase the operational consequence of an incident.
NIST guidance recommends identifying communication between security zones and restricting unnecessary traffic.
CISA also provides a dedicated small and medium business pathway for foundational cyber practices.
Why does it matter?
The result can move from an IT outage to stopped output and missed customer commitments.
Segmentation also improves diagnosis.
When owners know which systems belong in each zone and which connections are approved, unexpected traffic becomes easier to investigate and block.
What should we watch?
Asset discovery and traffic observation must come before enforcement.
Network separation is not a complete ransomware programme.
Identity security, patching, backups, phishing controls, vendor access, incident response, and restoration testing remain necessary.
What should we do?
Record the owner and business purpose for every connection between zones.
Remove unused paths, require managed remote access with multifactor authentication, and keep backups unreachable from ordinary accounts.
Test restoration using a production-representative system and record the time, dependencies, and missing instructions.
- Inventory IT and OT assets.
- Observe traffic before blocking it.
- Control every vendor connection.
- Test an offline restoration.
What this page cannot conclude
- 01Poorly planned firewall changes can interrupt production, safety systems, vendor support, quality records, or machine communications. Asset discovery and traffic observation must come before enforcement.
- 02Network separation is not a complete ransomware programme. Identity security, patching, backups, phishing controls, vendor access, incident response, and restoration testing remain necessary.
Sources
- 01Cybersecurity risk mitigation for small manufacturersNational Institute of Standards and Technology · accessed Sep 12, 2026
- 02Cybersecurity starting point for manufacturersNational Institute of Standards and Technology · accessed Sep 12, 2026
- 03Small and medium business cybersecurityCybersecurity and Infrastructure Security Agency · accessed Sep 12, 2026
Our editorial standard · Found an error? Send a correction with its source.
/ CITE OR SHARE THIS GUIDE
Make the evidence easy to verify.
When you reference this guide, link to its canonical URL. That gives readers one stable place for the evidence, limitations and future updates.
dotSuper Research Desk. (September 12, 2026). Segment Factory Networks Before Ransomware. dotSuper. https://dotsuper.net/feeds/daily-briefing/2026-09-12-factory-network-segmentation-ransomware
