
Light OT/ICS: network segmentation for Caribbean factories
PLC on the same WiFi as the office: recipe for disaster. OT/ICS segmentation without a six-figure project.
At manufacturing plants in Puerto Rico — from food processing in Arecibo to textiles in the metro area — we find PLCs and HMIs on the same VLAN as accounting laptops. CISA regularly warns about ransomware crossing IT/OT; one phishing click should not be able to write Modbus registers, but without segmentation that is exactly what happens.
OT/ICS segmentation does not require a six-figure industrial firewall on day one. Start with simplified Purdue zones: Level 3 (corporate IT) separated from Level 1-2 (control and field) via deny-by-default firewall rules. Allow only documented traffic: historian to SCADA, patch server to HMI during maintenance windows. NIST SP 800-82 r2 is mandatory reading for any plant manager with a cybersecurity budget.
Bruce Schneier has written about IT/OT convergence as risk amplification: IT wants cloud visibility; OT needs 99.9% uptime on bottling lines. The practical compromise is an OT DMZ with audited jump hosts, no general browsing from operator consoles, and USB disabled on engineering stations.
Local automation vendors often request permanent remote access for support. Document sessions, use MFA, time-bound access, and screen recording. Krebs on Security has documented incidents where OT vendor credentials were the initial vector — a shared integrator password beats a zero-day exploit for opportunistic attackers.
Caribbean manufacturing competes on tight margins; stopping a line for malware is direct loss. Well-designed segmentation costs weeks of consulting, not years of project. Measure success: can a compromised reception laptop reach a PLC? If yes, you are not done yet.

Writes about practical cybersecurity for SMBs in Puerto Rico and the Caribbean — no fluff, just what actually needs to get done.


