Safety, reliability, and control are paramount in all industries, not just on the plant floor or field but also on your digital infrastructure. As industrial operations become increasingly connected through Industrial Control Systems (ICS), SCADA networks, and remote access technologies, cybersecurity threats are no longer theoretical but operational hazards.
A robust firewall is a crucial first step; however, in high-stakes environments like chemical refineries, manufacturing facilities, electrical generation, and various others, adopting a multi-firewall approach is essential.
Let’s explain when and why you should consider deploying two or more firewalls in your refinery’s network.
Why Firewalls Matter in OT Environments
Organizations rely on tightly integrated systems:
- PLCs and DCSs control process equipment
- SCADA systems monitor real-time operations
- Corporate IT handles business operations and remote access
Without proper segmentation, a vulnerability in one area, such as ransomware from a phishing email on a corporate laptop, can cascade into your operational environment, jeopardizing equipment, personnel, and production.
Firewalls enforce boundaries, monitor traffic, and prevent unauthorized access; however, relying on a single firewall may be insufficient for protecting critical infrastructure.
When You Need More Than One Firewall
1. Separating IT and OT/ICS Networks
Your corporate IT network and plant OT/ICS network should never completely trust one another. OT systems often run on legacy software, cannot be patched frequently, and are not designed with security in mind.
Solution: Position a firewall between the IT and OT zones to regulate and log all traffic crossing the boundary. Permit only specific protocols and approved connections.
2. Creating a Secure DMZ for Data Exchange
Many systems must transmit data, such as sensor readings or system status, to business systems for analysis or reporting.
Solution 1: Clearly define zones between network segments:
- One zone between the OT network and the Industrial DMZ.
- Another zone between the Industrial DMZ and the IT network.
Solution 2: Use a dual-firewall DMZ:
- One firewall between the OT network and the Industrial DMZ.
- Another is between the Industrial DMZ and the IT network.
This architecture ensures attackers can’t easily reach your core OT/ICS systems even if the DMZ is compromised. Depending on your organization’s resources (budget and manpower), one solution may be more suitable.
3. Enforcing Zone-Based Segmentation
Not all parts of your refinery need the same level of access to:
- Engineering workstations
- Safety instrumented systems (SIS)
- Remote I/O racks
- Contractor laptops
Solution: Use internal firewalls to create logical zones based on function, risk level, or access requirements. Each zone gets tailored rules, reducing lateral movement if one device is breached.
4. Supporting Redundancy and High Availability
Organizations operate 24/7. Unplanned downtime isn’t just expensive, it can be dangerous.
Solution: Deploy redundant firewalls in a high-availability (HA) setup. If one firewall fails due to hardware issues or maintenance, the other takes over seamlessly.
5. Separation of duties
Separation of duties is a key principle in dual-firewall architecture that enhances security, accountability, and operational resilience in industrial environments. In this model, the IT firewall is administered by the corporate IT team, while the operations or engineering team manages the OT firewall. This deliberate division ensures that no single group has unilateral control over both sides of the enterprise-to-plant boundary, reducing the risk of misconfigurations, unauthorized changes, or insider threats. This separation not only strengthens governance and change management but also fosters collaboration between teams without compromising the integrity of either network.
Solution: Deploy a firewall that you can manage, and another that your OT engineers manage, to maintain a clear line of responsibilities. This way, each team can focus on their unique requirements.
6. Vendor Diversity
Using two different firewall vendors, one for the IT firewall and another for the OT firewall, is a form of vendor diversity or technology diversity, and it’s a powerful strategy for enhancing security through resilience and layered defense.
Solution: Often, firewall requirements differ depending on your network architecture, and different vendors may help address the organization’s security needs.
7. Cybersecurity Standards and Compliance
Regulatory frameworks such as NIST SP 800-82 (Guide to Industrial Control Systems Security) and ISA/IEC 62443 emphasize network segmentation and the protection of control systems as critical security principles. While they do not specifically require multiple firewalls, they recommend architectures such as segmented zones and industrial DMZs, where multiple firewalls are often the most practical and effective implementation.
Option 1: A single, well-configured firewall can support segmentation and help meet compliance objectives while simplifying maintenance and audits.
Option 2: Multiple firewalls provide an additional layer of separation and control, making it easier to demonstrate robust security practices and policy enforcement, especially when combined with strong logging, regular audits, and strict access controls.
Firewalls for Remote Access and Third-Party Vendors
Remote maintenance and monitoring are standard in OT environments. However, each remote connection is a potential entry point for attackers.
Solution: Use dedicated firewalls (or firewall zones) for:
- VPN connections
- Third-party access
- Mobile devices or tablets used in the field
Pair this with multi-factor authentication and strict time-based access windows for maximum safety.
OT vs. IT Firewalls: Why You Need Both in Your Industrial Environment
In today’s converging industrial landscape, one of the most common questions is:
“Do I need a special OT firewall if I already have an IT firewall?”
The short answer: Yes. You need both.
What’s the Difference?

Why You Need Both
The rise of Industry 4.0 and remote operations has eliminated the traditional OT air gap. This increases exposure to threats that IT firewalls alone cannot handle.
- Ransomware, such as EKANS and Industroyer, targets ICS systems directly.
- Lateral movement from IT can compromise OT environments.
- Standards such as IEC 62443 and NIST SP 800-82 require defense-in-depth.
A layered security model with IT and OT firewalls is crucial for protecting modern industrial networks.
What a Secure Architecture Looks Like

- IT firewalls address external and enterprise threats.
- DMZs safely facilitate data exchange and remote access.
- OT firewalls tightly control traffic into critical control systems.
Advanced setups may include internal OT firewalls and data diodes for one-way communication.
Final Thoughts: Safety Isn’t Just Physical Anymore
You’ve invested in physical safety, now it’s time to bring that same rigor to your digital safety. As OT and IT continue to converge, a cyber breach doesn’t just threaten data; it can halt production, damage equipment, or endanger lives.
A robust multi-firewall architecture isn’t just IT hygiene, it’s mission-critical infrastructure. When you deploy dedicated IT and OT firewalls, you gain:
- Purpose-driven separation of systems
- Reduced exposure to external threats
- Protection against lateral movement
- High availability and redundancy
- A path to regulatory readiness and peace of mind
Ready to Fortify Your OT/ICS Perimeter?
Let’s build a layered, resilient firewall strategy that aligns with your operations and compliance needs.
“IT firewalls protect your business; OT firewalls protect your process. Together, they safeguard your people, production, and profits.”
Contact us at info@enaxy.com to schedule a network assessment and receive a tailored roadmap for securing your industrial infrastructure.