The Purdue Model for Industrial Control Systems: A Layered Blueprint for OT and IT
The Purdue Model organizes industrial control systems into layered levels, from sensors to enterprise, that separate and connect operational technology and IT.
.png)
The Purdue Model for industrial control systems is a layered reference architecture that organizes a plant's technology into levels, from the sensors touching the physical process up to the enterprise network running the business. It separates operational technology from information technology while letting the two exchange data under controlled conditions.
Decades on, the Purdue Model still shapes how engineers think about industrial control, network segmentation, and ICS security.
What the model never answered is the question facing multi-site operators today: how do you govern not one plant, but dozens, each running its own version of the same six levels?
What the Purdue Model organizes
Originally the Purdue Enterprise Reference Architecture, developed at Purdue University in the early 1990s for computer-integrated manufacturing and often called the Purdue Reference Model, the framework maps how data flows through industrial networks.
The Purdue Model sorts systems by function and response time, then stacks them into a hierarchy. Lower levels sit closest to the physical processes and respond fastest; higher levels handle business decisions like ordinary IT systems.
The Purdue Model draws a hard line between two worlds, OT and IT. Operational technology (OT) runs the equipment. Information technology (IT) runs the company.
The six levels, from Level 0 physical process to the enterprise network
Network segmentation between OT networks and the enterprise zone
Between site operations and the business sits Level 3.5, the demilitarized zone. It was not in the original Purdue Model. Engineers added it once industrial control systems stopped being isolated and started connecting to corporate networks.
For years, the boundary was an air gap: OT networks had no physical link to IT networks or the internet, which made lateral movement between them impossible. That air gap has mostly gone. Remote access, cloud analytics, and the pull of live data opened bidirectional data flows that a true air gap cannot allow.
Network segmentation replaced the air gap. Rather than isolate the OT network completely, teams divide the architecture into network segments and control the conduits between them. Firewalls filter incoming and outgoing traffic at the DMZ, and security controls such as multi-factor authentication govern who reaches critical OT systems. The aim is to let process data reach the enterprise zone without letting a compromise in IT systems cascade into the physical processes below.
This layered structure is why the Purdue Model still anchors so much ICS security guidance. NIST SP 800-82, the standard for OT security, and the ISA/IEC 62443 series of zones and conduits both build on its hierarchy to help security practitioners determine where to place security measures and how to contain lateral movement and cyber threats.
Greg Lanza, the Sr. Software Product Manager at CrossnoKaye, shared the following when asked about the wrong way of providing insights into visibility for leadership:
"The "wrong" way to give them visibility to L1 and L2 data on traditional control systems would be to use unsecured channels and to ignore the recommendations from the control system vendors "Defense in depth" strategies. If the advice is followed, there are ways of gaining visibility to those layers of the system, they just require a lot of careful infrastructure and integration that costs a lot to implement and even more to maintain.
In general, I don't think that things break when they punch those holes, but to do it in a secure way is costly and requires specialized knowledge and skills."
One plant versus a portfolio: the ICS network architecture gap
The Purdue Model describes one plant. That is its blind spot. A multi-site operator does not run one industrial control system; it runs many industrial control systems, and no two are the same.
Each facility carries its own stack of levels, PLCs/DCS controllers and their I/O, configuration and operator PC infrastructure, plant-wide historians, and layers of networking integration built up over years of software and technological evolution. The ICS network architecture is coherent at each site and incoherent across the portfolio. Best practices stay trapped as tribal knowledge.
Real portfolios show the scale. Lineage runs close to 480 facilities worldwide, and, as Eric Krupa, GE & ML, puts it, "no two are the same." Americold set out to consolidate more than 20 different control systems onto one platform for a single corporate view. The Purdue Model tells each site how to organize itself. It says nothing about making 480 comparable, and that gap is where cost, risk, and lost time across these industrial environments accumulate.
See how CrossnoKaye standardizes control across a multi-site portfolio. Contact the team.
Is the Purdue Model still relevant to modern ICS security?
Yes, but as a way of thinking rather than a rigid network diagram. Modern ICS security now accounts for edge devices and the Industrial Internet of Things, where a Level 0 sensor can send data straight to the cloud, skipping the hierarchy. That flattening breaks the vertical stack the model drew, reshaping ICS environments everywhere.
Most teams treat the Purdue Model as a reference, then adapt it to cloud and edge realities rather than abandon it. Increasingly, that adaptation layers zero trust onto the model's zones, verifying each request between levels instead of trusting a segment by location, while leadership keeps permissioned control over who changes what. This is IT/OT convergence in practice.
For OT environments modernizing on top of legacy systems, the blueprint does not have to be replaced to stay useful. It has to be extended.
Governing many Purdue stacks as one system
The Purdue Model organizes a site. Governing a portfolio needs a layer the model never described: one that sits above the individual stacks and makes them comparable without ripping any of them out.
That is the job of an ATLAS Enterprise Control Platform. It connects to the existing control systems at each site, the PLCs, the OEM systems, and the historians, then standardizes their data into one governed operating model. Leadership gains portfolio-wide remote monitoring and permissioned control across every facility, while each site keeps running its own equipment. Standards get enforced from the top, and execution stays local.
This respects the Purdue Model instead of fighting it. Segmentation and site-level control authority stay intact, and operational efficiency improves as proven strategies roll out across sites. What changes is that Level 4 and Level 5 finally share one governed view of the portfolio, not 480 separate ones. Americold's move to consolidate more than 20 control systems, and Lineage's 20 to 30% savings from a common operating model, show what that governance looks like in production.
Request a demo to see how ATLAS standardizes industrial control across a multi-site portfolio.
Purdue Model FAQs
How does the Purdue Model improve ICS cybersecurity?
Securing industrial control systems with the Purdue Model comes down to where you place security controls: firewalls and access controls at each layer boundary, with the tightest inspection at the Level 3.5 DMZ between OT and IT. Because the layers are segmented, a breach in IT systems cannot move directly into the control systems governing physical processes. Standards such as ISA/IEC 62443 build on that structure to harden ICS environments.
How does the Purdue Model relate to the ISA/IEC 62443 standard?
ISA/IEC 62443 uses the Purdue Model's layered hierarchy as the starting point for its zones and conduits approach to industrial control systems security. Zones group assets that share security requirements, and conduits define the controlled communication between them. In effect, 62443 turns the model's descriptive levels into enforceable security controls.
Does the Purdue Model apply to industrial refrigeration and cold storage facilities?
Yes. A refrigeration or cold storage facility shares the same layered structure: sensors and compressors at Level 0, PLCs at Level 1, supervisory control at Level 2, and site systems above. The Purdue Model applies to any industrial environment that controls physical processes, which is why multi-site cold storage operators lean on it to standardize control across facilities.

Stay Connected
Subscribe to stay in the loop on the latest industry news.
Related Posts
.png)

_%20Definition%2C%20Use%20Cases%2C%20and%20Where%20It%27s%20Headed.png)