Building-Management & OT Network
The OT communication substrate
A dedicated, segmented communication substrate for BMS, EPMS, controllers, metering and PrecisionDCMS acquisition — engineered as operational technology, not as an extension of the corporate LAN.
- Class
- Operational technology
- Model
- Purdue-aligned zones & conduits
- Default
- Read-only, local-first
- Evidence
- IEC 62443 / NIST where scoped
Product outcomes
What this network delivers when it is engineered, accepted and operated as part of DCOS Network.
Segmented substrate
Field, controller and integration traffic live in engineered zones and conduits — never a shared flat VLAN.
Local-first operation
The site keeps running on one authoritative path even when the enterprise or cloud boundary is unavailable.
Read-only by default
Command authority is explicit and brokered; there is no generic remote PLC access.
What it carries
The building-management network is the communication substrate for the systems that keep a site alive.
It is operational technology
It is not a flat device VLAN and it is not an extension of the corporate LAN. It is engineered, segmented and operated as operational technology — BMS, EPMS, PLCs and PFCs, utility and microgrid systems, meters, UPS, ATS, switchgear and generator interfaces, cooling, packaged equipment, PrecisionDCMS Field/NX, Site Connector and collectors, and existing BMS or SCADA integration.
Functional layers
Traffic is engineered through explicit functional layers, from field signal to a controlled enterprise boundary.
Field / process
Sensors, actuators and process signals at the equipment.
Controller / equipment
PLCs, PFCs and packaged-equipment controllers.
OT access switching
Dedicated access layer for controllers and field devices.
OT distribution / routing
Segmented distribution with explicit routing between zones.
OT services
Time, naming, acquisition and collector services, local-first.
OT DMZ / integration
Brokered north-south integration to enterprise and cloud.
Enterprise / Cloud boundary
Controlled, monitored boundary — never a flat extension.
Design principles
- Local-first operation
- One authoritative path
- Read-only by default
- No generic remote PLC access
- Protocol-aware security
- Resilient time and naming
- Explicit availability accounting
- Configuration lifecycle
- Environmental and power fit
Managed services
DCOS Network engineers, accepts and operates the OT substrate end to end.
- Asset and flow discovery
- Zones and conduits
- Addressing and routing
- VLAN / VRF / firewall plan
- Protocol map
- Hardware, optics and cabling
- Staging and configuration
- Certificates
- 24/7 monitoring
- Vendor access
- Change and maintenance
- Incident response
- Cybersecurity
- IEC 62443 / NIST-aligned evidence where scoped
Technical FAQs
Frequently asked questions
Explore the family
Related products
DCOS Network
Engineered building-management, OT, campus, security and management networks — new build, overlay, managed or mixed-vendor.
DCOS Operations
24/7 NOC, SOC, service desk, CALS event orchestration, ITSM/CMMS/DCIM and field services under an accountable operating model.
DCOS Secure
Perimeter, access control, video, intrusion, visitor management and dispatch — as a protective system and a governed data domain.
CriticalOps Cloud
Tenant-aware identity, private access, monitoring, dashboards, CALS, workflow, evidence, APIs, backup and disaster recovery — with local protection always independent of the hosted service.
Engineer building-management & ot network as part of one governed fabric.
DCOS Network designs, accepts and operates every network domain under the same operating contract.
