Industrial DMZiDMZ
An industrial DMZ is a buffer network placed between the plant control network and the enterprise network so that no traffic passes directly between the two. Servers in the iDMZ, such as patch relays, historian mirrors, and remote-access brokers, terminate connections from each side.
In Purdue terms the iDMZ sits at Level 3.5. Business systems that need production data read it from a replica in the DMZ; vendors who need remote access land on a jump host in the DMZ; updates are staged there before they reach the plant. The control network never accepts an inbound connection from the corporate side.
It is a specific kind of DMZ: the ordinary perimeter DMZ protects the internet edge, while the industrial DMZ protects the boundary between IT and OT inside the company.
Why it matters in cement, mining, and aggregates
Most plants Potenza assesses have no iDMZ. Office workstations reach controllers directly and vendor VPNs terminate on the control network. Establishing an iDMZ is usually the single largest segmentation change on a plant's roadmap, and it is where remote access finally gets governed.