Security requires complete segregation of OT and IT networks using a DMZ.  All inbound firewall ports must stay closed.  Unlike a VPN, this ensures that any attack on IT does not propagate to OT.  The ...