商务支持

技术支持

About Guangxun

关于光迅

Unauthorized Intrusions from Office Networks Into Production Networks! All-Optical Hard Isolation Safeguards Factory Core Production Data
2026-09-12 11:28:17 6

Unauthorized Intrusions from Office Networks Into Production Networks! All-Optical Hard Isolation Safeguards Factory Core Production Data

A phishing email compromises an office endpoint. After attackers move laterally across the intranet for dozens of hours, production systems get locked down and assembly lines grind to a halt. Such scenarios have already occurred multiple times in reality.

Attackers do not even need to touch any production equipment. Paralyzing the IT systems that underpin manufacturing is enough to stop production lines. If one PC on the office network gets compromised, the entire production line shuts down accordingly. Many factories have no boundary between production and office networks: PCs on employee desks can ping PLC controllers on the shop floor. Once attackers breach office terminals, they can reach production control devices and MES servers directly over the same network.

I. Why Can Office Networks Reach Production Systems Directly?

Flat network architecture: Office and production share one large Layer 2 network

Many factory networks adopt a flat design, where office terminals and production-line devices reside on the same large Layer 2 network. Employee PCs can directly access PLCs, MES servers and AGV dispatching systems. When malware infects an office endpoint, it can scan production devices straight across the Layer 2 network without passing through any gateway or firewall. Without clear boundaries separating office and production networks, the production environment becomes wide open once attackers gain access to the office segment.

VLAN isolation relies on manual configuration; missing settings break all protection

Some factories implement VLAN segmentation, yet VLAN isolation depends on switch-by-switch configuration, which is prone to human error and omissions. When adding new production lines or adjusting workstations, misconfigured VLANs render isolation ineffective. More critically, VLANs are software-level logical isolation; tags can be forged. Attackers can modify tags to traverse network domains. Isolation maintained merely by configuration files is inherently unreliable.

Perimeter firewalls cannot see east-west traffic

Traditional firewalls are deployed at network boundaries and monitor north-south traffic: inbound traffic from the internet and outbound internal traffic. However, malware lateral movement inside the intranet — jumping from office PCs to shop-floor PLCs — falls under east-west traffic and never passes through perimeter firewalls. Once an office terminal is compromised, malware can freely spread across the internal network to reach production systems. Perimeter defenses are largely ineffective against lateral movement.

IT-OT convergence dismantles legacy physical isolation

In the past, factory production networks were physically isolated. No internet connection equated to safety. Driven by smart manufacturing, production-line devices now require network access for data collection, remote maintenance and real-time AI inspection feedback. Physical isolation has been broken, exposing OT systems to the network without corresponding security boundaries. Once IT and OT networks are interconnected, OT devices generally have far weaker security posture than IT assets, drastically expanding the attack surface. Attackers do not have to compromise PLCs directly; disabling supporting IT systems is sufficient to halt production lines.

II. How All-Optical Hard Isolation Protects Core Production Data

To resolve blurred boundaries between office and production networks, AINOPOL’s solution redesigns the network architecture. It shifts isolation between office and production networks from “configuration-based rules” to protection embedded deep within the network infrastructure.

Separate PON ports: Office and production traffic travel over independent optical channels

Production and office networks are divided using dedicated PON ports. One PON port serves the office network, while another handles the production network. The two service channels are physically separated. Industrial-grade ONUs are deployed on production lines to enforce physical isolation between production and office networks. Even if attackers take control of all office network devices, they will find no physical pathway to reach the production network. The production line keeps running even if the office network is breached.

VLAN segmentation: Multiple services on one fiber network without crosstalk

For scenarios carrying multiple services on a single fiber network, the all-optical network creates independent security zones for production, office and guest networks through VLAN isolation. Different service zones have no mutual connectivity by default. Even if the office network is compromised, attackers cannot scan PLC IP addresses in the production zone. VLAN policies are deployed centrally on the OLT, instead of configured switch by switch, eliminating manual configuration omissions.

Full traffic auditing: Lateral movement leaves traceable logs

Traditional firewalls cannot inspect east-west traffic. The all-optical solution centrally collects and retains access logs and traffic records from all connected terminals. Every access event to production equipment is logged: who accessed it, when, and from which source. In the event of lateral infiltration, security teams can quickly pinpoint the source of compromise instead of carrying out blind full-network investigation.

Redundant core OLT with hot standby for uninterrupted production networking

Core OLT devices adopt dual-link hot standby with 20ms failover to sustain continuous network operation. If one link fails, services automatically switch to the backup link within milliseconds, preventing production shutdowns caused by temporary network fluctuations.

A factory’s network architecture determines its resilience against cyberattacks. If office PCs can ping shop-floor PLCs and MES servers share the same subnet, the network offers almost no buffer against breaches. Attackers do not need to compromise production equipment directly; crippling supporting IT systems can halt the whole production line. This is not purely a technical issue — it is an architectural one. The fix does not require tearing down the existing network. Instead, architecturally separate office and production networks, so attackers who break through one zone cannot reach the other.

FAQ

Q: What is the difference between traditional VLAN isolation and all-optical hard isolation?
A: Traditional VLAN is software-based logical isolation, requiring switch-by-switch configuration that is error-prone, and VLAN tags can be forged. All-optical hard isolation uses independent PON ports for physical separation: office and production traffic run on distinct optical paths, and packets never cross into the opposite channel.

Q: What level of isolation is required between office and production networks?
A: Logical isolation is the minimum requirement: create separate security domains for office and production networks with no default connectivity. Physical isolation via dedicated PON ports is ideal, completely eliminating the risk of cross-network attacks.