Network segmentation validation compares design intent with observed traffic and carefully controlled reachability. GDF reviews the IT/OT boundary, cell and area zones, management networks, safety separation, wireless links, remote access, historian paths, and vendor support channels. Operator-designated authority approves any active method, process condition, maintenance window, stop points, and rollback plan. A passive or configuration-only review is used where active validation would create unacceptable process risk.
Map every legitimate crossing
The team identifies data flows, protocol direction, source and destination, service accounts, business owner, operating schedule, and failure consequence. Unexplained rules, broad address ranges, temporary exceptions, stale VPNs, direct internet access, and alternate paths are marked for validation.
Evidence from configuration, traffic, and controlled tests
Firewall and router configurations are compared with route tables, identity systems, passive traffic, remote-access logs, jump-host controls, and selected reachability tests. A blocked ping is not proof of isolation. Validation considers the services and trust relationships that an attacker or misconfigured system could actually use.
- IT/OT boundary and industrial DMZ assessment
- Cell, area, safety, management, and vendor-access path review
- Firewall-rule, NAT, route, and remote-access validation
- Dual-homed, wireless, modem, and alternate-path discovery
- Remediation sequence and post-change retesting
Change plans tied to production reality
Recommended changes identify affected owners, required protocol, monitoring option, safety and environmental dependencies, rollback condition, maintenance window, and expected risk reduction. Where immediate isolation is not feasible, compensating controls and detection opportunities are documented. Post-change testing covers the approved path and date; it does not establish that every alternate route has been eliminated.