Cybersecurity network background
AI Readiness Services

DMZ Deployment

Expose your Unified Namespace to AI agents like chatUNS through a hardened Industrial DMZ — gaining full, natural-language insight into live operations while your OT network stays provably isolated behind an outbound-only, brokered boundary.

Purpose & Pain Points Solved

A DMZ Deployment resolves the fundamental tension of the AI era: your operation needs to be readable by intelligent agents and cloud analytics, but your OT network must never be exposed. We place a hardened, brokered demilitarized zone at Purdue Level 3.5 so the Unified Namespace flows outbound only — reachable by chatUNS, invisible to attackers.

AI Requires Access — OT Requires Isolation

Modern AI agents like chatUNS need to read your operational data, but exposing PLCs, SCADA, and your production broker directly to IT or the cloud violates every OT security principle you have.

Impact: Teams stall indefinitely, torn between the value of AI and the unacceptable risk of poking holes in the OT firewall

Inbound Firewall Rules Are a Non-Starter

Letting a cloud service or IT application initiate a connection into Level 2/3 means opening inbound ports through the OT firewall — the exact attack path ransomware and lateral-movement campaigns exploit.

Impact: A single inbound rule can become the pivot point that takes down production and safety systems

"Just Keep It On-Prem" Locks Out Insight

Air-gapping the plant keeps it safe but blind — no AI agents, no cloud analytics, no cross-site benchmarking, and no way to ask natural-language questions of your live operation.

Impact: You trade all the upside of a Unified Namespace for isolation, and competitors who solve exposure safely pull ahead

Flat Networks Blur the OT/IT Boundary

Without a segmented demilitarized zone, OT and IT traffic share the same trust level. There is no controlled hand-off point where data can be inspected, governed, and safely brokered.

Impact: Compliance findings (IEC 62443, NIST 800-82), audit failures, and no defensible architecture to show regulators or cyber-insurers

What This Service Enables

Provable OT Isolation

A Level 3.5 boundary with no inbound OT rules — the control network is unreachable from IT or the cloud

AI-Ready Exposure

chatUNS reads the live UNS from the DMZ broker — full insight without ever touching OT systems

Outbound-Only Bridging

The UNS is pushed up to the DMZ from inside the plant — there is no listening port for attackers to find

The DMZ Data Flow

Data moves in one direction — up and out. From the PLC to the AI agent, every hop is authenticated, contextualized, and brokered across a segmented boundary.

Level 1–2 · OT Zone

TOP Server

Captures live process data from PLCs/RTUs and serves it over secure OPC UA.

Level 3 · OT Zone

N3uron

Contextualizes OPC data into an ISA-95 UNS and publishes via MQTT Sparkplug B.

Level 3.5 · Industrial DMZ

HiveMQ / Mosquitto

The single hardened broker. Receives the UNS via outbound-only bridging.

Level 4 · IT / Cloud

chatUNS.ai

Subscribes read-only to the DMZ broker for natural-language operational insight.

The golden rule: every arrow points outward. The OT-side broker initiates the bridge up to the DMZ, and consumers only ever connect to the DMZ broker. No IT, cloud, or AI system can open a session back into Levels 1–3.

A Better Approach Than On-Prem Isolation

Keeping everything on-premise and cloud-free feels safe — but it blinds your AI initiatives. Direct exposure is fast — but reckless. A DMZ deployment gives you the third option: controlled, brokered exposure that keeps OT sealed.

CharacteristicOn-Prem-Only / Direct ExposureDMZ Deployment
OT ExposureDirect or flat-network access to OTZero — OT unreachable from IT/cloud
Connection DirectionInbound rules into OT requiredOutbound-only, initiated from OT
AI / Cloud AccessNone (air-gapped) or unsafe (direct)Full insight via governed DMZ broker
Boundary ControlNo brokered hand-off pointSingle brokered, inspected boundary
Compliance PostureHard to defend (IEC 62443)Defensible, audit-ready segmentation
Blast RadiusIT/cloud breach can reach productionContained at the DMZ, never OT
Access RevocationRequires touching OT systemsInstant, at the broker only

Enabling Tools & Technologies

The DMZ deployment is built on a proven, layered stack — each tool owning one Purdue level, connected only by authenticated, outbound MQTT.

TOP Server — OPC Data Capture (Level 1–2)

TOP Server acts as the OPC server on the plant floor, connecting to your PLCs, RTUs, and devices across 150+ protocols and surfacing that raw process data over OPC UA / OPC DA.

Key Capabilities:

  • Native drivers for Allen-Bradley, Siemens, Modbus, DNP3, and 150+ more
  • Serves live tags over secure OPC UA to the contextualization layer
  • Runs deep inside the trusted OT zone — never exposed to the DMZ
  • Redundancy and store-and-forward for uninterrupted acquisition
  • Signed, encrypted OPC UA sessions with certificate trust lists

N3uron — Contextualization & UNS Modeling (Level 3)

N3uron is the industrial edge platform that ingests TOP Server's OPC data, contextualizes it into an ISA-95 information model, and publishes the Unified Namespace to the broker via MQTT Sparkplug B.

Key Capabilities:

  • OPC UA/DA client modules pull directly from TOP Server
  • Builds a structured ISA-95 namespace (Enterprise/Site/Area/Line/Cell)
  • MQTT / Sparkplug B publisher with store-and-forward buffering
  • Data modeling, scaling, calculations, and metadata enrichment at the edge
  • Publishes outbound only — initiates the connection up to the DMZ broker

DMZ Broker — HiveMQ or Eclipse Mosquitto (Level 3.5)

An MQTT broker deployed in the Industrial DMZ (IDMZ) is the single, hardened point where the Unified Namespace is exposed. Nothing crosses the OT/IT boundary except brokered, authenticated MQTT.

Key Capabilities:

  • HiveMQ (enterprise, clustered HA) or Mosquitto (lightweight) in the DMZ
  • Broker bridging: the OT-side broker pushes UNS up to the DMZ broker
  • TLS 1.2/1.3 with mutual (client-certificate) authentication
  • Per-topic ACLs — external consumers get read-only, scoped access
  • No route from the DMZ broker back into the OT zone

chatUNS.ai — Governed AI Consumption (Level 4/Cloud)

chatUNS.ai subscribes to the DMZ broker to read the live Unified Namespace and answer natural-language questions — gaining full insight into operations while remaining completely outside the OT perimeter.

Key Capabilities:

  • Subscribes to the DMZ broker with a scoped, read-only credential
  • Natural-language querying over the live, contextualized UNS
  • Never establishes any connection into Level 2/3 systems
  • Access revocable at the broker with zero change to OT
  • All queries served from the DMZ-exposed data fabric only
Broker Bridging & Sparkplug B

Broker Bridging & Sparkplug B

MQTT broker bridging lets the OT-side broker mirror UNS topics up to the DMZ broker over a single outbound, mutually-authenticated TLS connection — using Eclipse Sparkplug B for state-aware, auto-discovering industrial messaging.

How We Deploy at Your Site

As expert system integrators, we follow a defense-in-depth methodology aligned to the Purdue model and IEC 62443 — delivering an audited, production DMZ from network segmentation to live AI consumption.

1

Assess & Segment the Network (Purdue Alignment)

3-5 days

Activities:

  • Map current architecture against the Purdue model / ISA-95 levels 0–5
  • Identify the Level 3.5 boundary and design the Industrial DMZ (IDMZ) segment
  • Provision dual firewalls (or a firewall with distinct OT and IT interfaces) around the DMZ
  • Define the golden rule: no protocol traverses the DMZ un-brokered, no inbound OT rules
  • Document trust zones, conduits, and data flows per IEC 62443 zones-and-conduits

Deliverable: Approved network segmentation design with an isolated IDMZ and firewall rule set

2

Deploy TOP Server for OPC Capture

3-4 days

Activities:

  • Install TOP Server in the trusted OT zone (Level 2) alongside the control network
  • Configure device drivers and channels for all PLCs/RTUs to be exposed
  • Enable secure OPC UA endpoints with certificate-based trust
  • Validate tag quality, update rates, and redundancy/store-and-forward
  • Lock down TOP Server so it is reachable only by the N3uron contextualization node

Deliverable: Live, secured OPC UA feed of all required process data inside the OT zone

3

Contextualize & Model the UNS in N3uron

4-6 days

Activities:

  • Deploy N3uron at Level 3 and connect its OPC UA client to TOP Server
  • Design the ISA-95 topic hierarchy (Enterprise/Site/Area/Line/Cell/Device/Tag)
  • Apply scaling, calculations, deadbands, and metadata enrichment for context
  • Configure the Sparkplug B / MQTT publisher and enable store-and-forward
  • Validate the modeled Unified Namespace against an internal test subscriber

Deliverable: A contextualized, ISA-95 Unified Namespace ready to publish from the edge

4

Stand Up the DMZ Broker & Bridge Outbound

3-4 days

Activities:

  • Deploy the MQTT broker (HiveMQ cluster or Mosquitto) inside the IDMZ
  • Configure N3uron / the OT-side broker to bridge UNS topics OUTBOUND to the DMZ broker
  • Ensure the connection is always initiated from the OT side — no inbound port to OT
  • Issue TLS server + client certificates and enforce mutual authentication
  • Confirm the DMZ broker cannot open any session back into Level 2/3

Deliverable: UNS mirrored into the DMZ broker via outbound-only, encrypted bridging

5

Harden Access Control & Expose to chatUNS

2-3 days

Activities:

  • Define per-topic ACLs granting chatUNS a read-only, scoped subscription
  • Provision a dedicated client certificate/credential for chatUNS.ai
  • Publish only the sanctioned namespace branches — withhold sensitive/control topics
  • Connect chatUNS.ai to the DMZ broker and validate natural-language querying
  • Verify chatUNS has zero network path to any OT-level system

Deliverable: chatUNS.ai reading the live UNS through the DMZ with least-privilege access

6

Validate, Monitor & Hand Off

2-3 days

Activities:

  • Run penetration and firewall-rule testing to prove OT is unreachable from IT/cloud
  • Verify end-to-end latency, store-and-forward recovery, and broker failover
  • Enable audit logging and monitoring on the DMZ broker and firewalls
  • Create runbooks for certificate rotation, ACL changes, and incident response
  • Train OT and IT teams on the segmented architecture and governance model

Deliverable: A production, audited DMZ deployment with monitoring, runbooks, and trained staff

Typical Implementation Timeline

17-25 Days

From network segmentation design to chatUNS consuming a live, DMZ-brokered Unified Namespace

Business Benefits

OT Stays Fully Isolated

No inbound firewall rules to the control network. AI and cloud consumers can only ever reach the DMZ broker — never a PLC, SCADA node, or the OT-side broker.

Outbound-Only by Design

Every connection across the boundary is initiated from inside the plant and pushed up. There is no listening port on the OT side for an attacker to target.

AI Without the Risk

chatUNS gets full, natural-language access to your live operation through a governed, brokered copy of the UNS — all the insight, none of the OT exposure.

One Auditable Boundary

A single, inspectable hand-off point makes IEC 62443 and NIST 800-82 compliance defensible and dramatically simplifies audits and cyber-insurance reviews.

Least-Privilege Exposure

Per-topic ACLs and client certificates mean each consumer sees only the sanctioned namespace branches, read-only, and access is revocable at the broker in seconds.

Resilient & Decoupled

Store-and-forward buffering and broker bridging mean a WAN or cloud outage never stalls production — the plant keeps running and the UNS catches up automatically.

Common Use Cases

Natural-Language Plant Insight for Leadership

Executives and engineers ask chatUNS live questions — "which line has the most downtime this shift?" — with answers drawn from the DMZ-exposed UNS, while the control network stays completely sealed.

Publishers (outbound): TOP Server → N3uron (ISA-95 UNS) → OT broker

Subscribers (read-only): chatUNS.ai via read-only DMZ broker subscription

Outcome: AI-driven operational insight with a provably isolated OT network

Safe Cloud Analytics & Benchmarking

Cloud analytics and cross-site dashboards subscribe to the DMZ broker to benchmark performance across plants, never establishing a route into any individual site's OT zone.

Publishers (outbound): Per-site N3uron nodes bridging UNS outbound to DMZ

Subscribers (read-only): Cloud analytics platforms, multi-site dashboards

Outcome: Enterprise-wide visibility without a single inbound OT firewall rule

Vendor & Integrator Remote Visibility

OEMs and system integrators receive a scoped, read-only slice of the UNS through the DMZ broker to monitor their equipment — with zero access to the rest of the plant.

Publishers (outbound): N3uron publishing sanctioned equipment topics only

Subscribers (read-only): Vendor dashboards via per-topic ACL credentials

Outcome: Collaborative remote monitoring with least-privilege, revocable access

IT/Enterprise App Integration

ERP, MES, and data-lake pipelines consume live operational context from the DMZ broker, bridging business and operations without ever crossing into Level 2/3 control systems.

Publishers (outbound): TOP Server → N3uron contextualized UNS → DMZ broker

Subscribers (read-only): ERP/MES connectors, data-lake ingestion services

Outcome: Contextualized IT/OT convergence on a secure, brokered boundary

Background

Ready to Expose Your UNS — Safely?

Stop choosing between AI-readiness and OT security. Let us design and deploy an Industrial DMZ that lets chatUNS read your live operation while your control network stays sealed behind an outbound-only boundary.