Skip to content

Engineering tools · Beta

OT Network Architecture Designer

A browser-based diagramming tool for developing and reviewing operational-technology network architecture concepts. It helps make security boundaries, trust relationships and communication paths visible before they become implementation details.

Launch the beta tool Opens the application in a new tab.

What the designer supports

Use the canvas to describe an OT system using familiar architecture concepts: Purdue levels, security zones and conduits, industrial firewalls, an industrial DMZ (IDMZ), secure remote-access paths and segmented plant networks. The diagram provides a shared visual starting point for engineering and cyber-security review.

A useful diagram should show why communication is needed, which boundary it crosses and where control is applied. It can support requirements and workshops, but it does not by itself prove that a network is secure or compliant with IEC 62443.

Suggested workflow

  1. Define the system under consideration and the functions it must deliver.
  2. Place assets into defensible zones based on risk, function and trust.
  3. Draw only the required conduits and record their intended traffic.
  4. Identify firewalls, IDMZ services and controlled remote-access boundaries.
  5. Review the diagram against detailed requirements, configurations and evidence.

Beta scope and limitations

The tool is under active development. Treat exported diagrams as design inputs that require competent review. Asset inventory, risk assessment, firewall rules, identity controls, product capabilities, resilience and verification evidence remain separate engineering activities.

Related OT cyber-security resources