Not every connection has
to lead into every network

Separate production and office areas and define the communication paths required.

Flat networks make data access easy, but also hard to limit. With new IIoT and remote maintenance connections, it has to remain clear which systems may communicate with each other.

IQstruct Engineering develops segmentation and hardening concepts and implements controlled connections. VLANs, firewalls, DMZ structures and allowlisting are coordinated with applications and operation. Zones and their connections help to organise the architecture in a traceable way.

Start now at no cost

In a free first conversation we look at your network plan and name the first dividing line.

See the person in charge

Scope of services

Separate network areas by task

Production, office and connected services are assigned deliberately.

Define permitted paths

Communication is aligned with the exchange required.

Consider access and operation together

Remote maintenance, backup and monitoring are integrated into the architecture.

Controlled paths between production and IT

IQstruct Engineering develops segmentation and hardening concepts and implements controlled connections.

After a survey, VLANs, firewalls, DMZ structures and allowlisting are coordinated with applications and operation. Zones and the connections between them organise the architecture in a traceable way.

A middleware between machine and IT opens up a new data path. Its ports and directions of communication are therefore included in the network concept, as are remote maintenance and backup. Data access thus remains limited to the systems that need it.

Network switches with connected patch cables and status indicators

Network security

Every connection leads into the network it is intended for

With new IIoT and remote maintenance connections, it remains clear which systems may communicate with each other.

Approach in the project

  1. Two people record the network diagram with office, production, servers and transitions on the screenAi

    1

    Record the network inventory

    Office IT, production, servers, NAS and transitions are shown in one network diagram.

  2. A planner defines switches, VLANs and ports on the screen, a network rack beside herAi

    2

    Design the network

    Switches, routers, VLANs and patch panels are planned with labelled ports.

  3. Two technicians configure VLANs on the screen, the network rack with labelled cabling beside themAi

    3

    Install the network

    Cabling and devices are installed with labels, and the VLANs are configured.

  4. An employee follows traffic and device states in the monitoring while a colleague works at the network rackAi

    4

    Monitor the network

    Traffic, states and security findings are reviewed in monitoring.

Building blocks of segmentation

VLANs and zones

Separate network areas for production, office and services.

Firewalls and DMZ

Controlled transitions between the zones.

Allowlisting

Only released communication between defined systems.

Information security

Protecting confidential project data reliably

In the automotive industry, TISAX creates a common basis for handling confidential information.

Manufacturers and suppliers exchange design data, software and further sensitive project information. TISAX makes it possible to assess information security against common criteria and to share the results with business partners. As an engineering service provider in this supply chain, IQstruct Engineering likewise commits to protecting the information entrusted to it and holds a TISAX label. Clear access rights, governed data exchange and traceable responsibilities are therefore part of the cooperation in a project as well.

Information security, audits and evidence

Frequently asked questions

We are glad to answer your detailed questions in a personal conversation.

Are two separate network ports enough?

Network separation needs rules for communication and access. We coordinate these rules with the connections your systems need.

How is a new IIoT connection classified?

The ports and directions of communication of the middleware are included in the network concept and limited to the data exchange required.

Is remote maintenance included?

Yes. Remote access is integrated into the segmentation.

First conversation

Arrange a free first conversation

Describe your task. We agree a date and discuss the possible project scope.

  1. Notebook on a desk with an open calendar and a selected appointmentAi

    1

    You request an appointment

  2. Joint planning of a segmented IT and OT infrastructure on a network diagramAi

    2

    We discuss your requirements

  3. Discussion of a security analysis with a network diagram and a list of measuresAi

    3

    You receive a quotation for the agreed scope

Philipp Niemann-Stryczek
Philipp Niemann-StryczekManaging DirectorLeads the company on the commercial side and answers questions on IT/OT security, asset administration shells, compliance and research projects.
Free first conversation

Describe your task in the contact form. We come back with a proposed date.

Arrange a first conversation

Not quite what you need?

Discover further suitable services.

Networking

Connect office, server and machine networks with a coordinated switching and routing structure.

OT security

Connect machine knowledge with segmentation, access protection and planned operation.

Remote access

Limit external access to released systems, people and time windows.