DMZ (Demilitarized Zone)DMZ
A DMZ is a separate network segment placed between two networks of different trust so that systems needing exposure to the less trusted side can be reached without opening the more trusted side. At the internet edge it hosts public servers; inside an industrial company, the industrial DMZ separates IT from OT.
Traffic into a DMZ is filtered by one firewall and traffic out of it into the protected network by another, or by a single firewall with distinct rule sets per interface. Nothing on the untrusted side gets a direct path to the trusted side.
The term is general; in OT conversations it almost always means the industrial DMZ at Purdue Level 3.5.
Why it matters in cement, mining, and aggregates
A plant that already has a perimeter DMZ for its website has solved the wrong boundary. The one that matters for production is the internal boundary between the office network and the controllers.