DCOS Network
Site & campus fabric
Engineered building-management, OT, campus, security and management networks — designed, accepted and operated as one governed fabric across new build, overlay, managed and mixed-vendor estates.
- Scope
- BMS · OT · Campus · Security · OOB
- Delivery
- New build · Overlay · Managed
- Vendors
- Single or mixed-vendor
- Acceptance
- Documented standard
Outcomes
What this plane guarantees when it is in place.
One accepted fabric
Every network domain is engineered against a documented standard and accepted before it carries production traffic.
Segmentation by design
BMS, OT, security and management planes are segmented with explicit trust boundaries, not incidental VLANs.
Operable from day one
Topology, health, paths and dependencies are modeled so the NOC can operate the fabric, not just watch it.
Network domains
Building-management networks
Dedicated, segmented BMS networks with controlled access to controllers, gateways and field devices.
OT & industrial networks
Purdue-aligned OT segmentation with brokered north-south flows and monitored east-west boundaries.
Campus & aggregation
Resilient campus and aggregation fabric with documented redundancy, failure domains and capacity headroom.
Out-of-band management
Independent OOB network and console access so the fabric stays manageable during in-band disruption.
Security networks
Dedicated transport for PACS, VMS and intrusion systems with converged incident context into operations.
Mixed-vendor operation
Federate approved existing switching, routing and firewall estates without forced rip-and-replace.
Capabilities
Building-management networks
Dedicated, segmented BMS networks with controlled access to controllers, gateways and field devices.
OT & industrial networks
Purdue-aligned OT segmentation with brokered north-south flows and monitored east-west boundaries.
Campus & aggregation
Resilient campus and aggregation fabric with documented redundancy, failure domains and capacity headroom.
Out-of-band management
Independent OOB network and console access so the fabric stays manageable during in-band disruption.
Security networks
Dedicated transport for PACS, VMS and intrusion systems with converged incident context into operations.
Mixed-vendor operation
Federate approved existing switching, routing and firewall estates without forced rip-and-replace.
Operating contract
How this plane upholds the shared platform contract.
Contract guarantees
- Every network element, path and segment carries stable identity that survives reconfiguration and vendor change.
- Read authority (visibility) and command authority (change) are declared separately for every network domain.
- Network events join the shared detect → validate → correlate → coordinate → restore → prove lifecycle.
- Dependencies between paths, services and assets are explicit so blast radius and restoration order are known.
Reference profiles
| Domain | Segmentation | Redundancy | Management |
|---|---|---|---|
| Building management | Dedicated VRF / zone | Dual-path where required | OOB + governed in-band |
| OT / industrial | Purdue-aligned zones | Zone-level resilience | Brokered, monitored access |
| Campus / aggregation | Role-based segments | Redundant uplinks | In-band with OOB fallback |
| Security transport | Isolated PACS/VMS plane | Path diversity | Converged incident context |
| Out-of-band | Fully independent | Separate power & path | Console + gateway access |
Scope & boundaries
What this plane is — and deliberately is not — responsible for.
- DCOS Network engineers and operates the fabric; carrier, transport and interconnection are provided by DCOS Connect.
- It federates approved existing network estates rather than mandating a single vendor.
- It does not replace safety-rated control-system interlocks on OT plant.
Technical FAQs
Frequently asked questions
Explore the family
Related products
DCOS Connect
Waves, dark fiber, transit, remote hubs, cloud on-ramps and customer interconnects — procured, engineered, accepted and operated.
DCOS Secure
Perimeter, access control, video, intrusion, visitor management and dispatch — as a protective system and a governed data domain.
DCOS Operations
24/7 NOC, SOC, service desk, CALS event orchestration, ITSM/CMMS/DCIM and field services under an accountable operating model.
CriticalOps Cloud
Identity, private access, monitoring, dashboards, CALS, evidence, APIs, backup and multi-site operations as a hosted plane.
Bring DCOS Network into your reference architecture
We map this plane to your sites, existing systems and assurance obligations, then agree a delivery path.