Approach

A structured, independent and field-oriented method

Reducing risk without disconnecting architecture from real operational constraints or business priorities.

IT/OT Architecture

From field to cloud — IT/OT levels through the Purdue Model

The Purdue Model structures the levels of an IT/OT architecture — from the electromechanical layer (EPO) up to enterprise systems and the cloud, with a demilitarized zone (DMZ) as the security boundary between OT and IT.

Purdue Model IT/OT — RĒSUNIX
1

Understand the environment

Stakeholder listening, context analysis, operational constraints, critical assets and dependencies.

2

Synthesize requirements and constraints

Connecting business needs, technical limits, risks, budgets and field feasibility.

3

Design for sustainability

Defining segmented, secure, maintainable, documented and scalable architectures.

4

Support, train and transfer

Team support, targeted training, knowledge transfer and clear, usable, audit-ready documentation.

Frameworks

Recognized models, adapted to field realities

Standards and models should not be applied as simple checklists. RĒSUNIX adapts them to real constraints: real-time performance, availability, legacy systems, maintenance, supplier access, segmentation, governance and operational continuity. The frameworks listed here are the most common — other sector-specific, regulatory or organization-specific frameworks may apply depending on the mandate.

NIST SP 800

Publications for cybersecurity and risk management, including SP 800-82 for OT.

Purdue model

Structuring levels, zones, conduits and flows between IT and OT environments.

ISA/IEC 62443

Best practices for securing industrial automation and control systems.

ITSG (Canada)

Canadian guidance applicable to risk, controls, wireless, telecommunications and sensitive systems.