The growing number of connected devices in critical infrastructure (energy, water supply, transport) significantly expands the cyberattack surface. According to ITU Facts and Figures 2025, about two-thirds of the world's population use the internet, making the protection of operational technology systems critical. IoT device isolation is a fundamental architectural solution to mitigate risks without losing operational control.
Impact on the industry
As legacy operational technology (OT) converges with modern IT systems, failing to secure IoT devices exposes critical infrastructure to devastating cyberattacks. For businesses and utility operators, this vulnerability can lead to service disruptions, financial losses, and regulatory penalties. Adopting robust isolation strategies ensures operational continuity and protects public safety.
Key strategies: segmentation and access control
The convergence of legacy operational technology (OT) with IT systems complicates security. Two main approaches are used to protect infrastructure:
- Network segmentation: dividing the network into isolated segments using VLANs or microsegmentation. This limits IoT device communication to designated controllers or gateways.
- Access control: implementing role-based access control (RBAC) policies, multi-factor authentication, and the principle of least privilege for device management.
Standardization and technological solutions
Firewalls, intrusion prevention systems (IPS), and specialized IoT gateways are used to build a secure architecture. Compliance with international standards plays a crucial role:
- ISA/IEC 62443: defines the zones and conduits concept for industrial network segmentation.
- NIST AI RMF 1.0: governs the risks associated with integrating artificial intelligence into operational technologies.
The development of private 5G networks, which the Ericsson Mobility Report projects will become dominant by the end of 2027, opens up new opportunities for secure connectivity of mobile and remote assets.
Maintaining manageability and monitoring
Device isolation requires maintaining control over them through the following tools:
- Centralized monitoring: collecting security data using SIEM systems and specialized management platforms.
- Secure over-the-air (OTA) updates: remote firmware updates to patch vulnerabilities.
- Incident response: rapid containment of threats within an isolated segment to prevent the attack from spreading.
How to prepare
To secure critical IoT infrastructure, organizations should take the following practical steps:
- Isolate networks using VLANs, microsegmentation, and specialized firewalls or IoT gateways.
- Enforce strict access control policies, including multi-factor authentication and the principle of least privilege.
- Align security architectures with international standards such as ISA/IEC 62443 and NIST AI RMF 1.0.
- Implement centralized monitoring via SIEM systems and establish protocols for secure OTA updates and rapid incident response.
Prepared by a Software Ukraine member. Original publication.