Between the controllers that run a process and the corporate systems that run the business sits a tier that is easy to overlook but does essential work: the plant information network. It is the level where process data is gathered, stored, and turned into the information the plant and the enterprise use, while being kept firmly separated from the control systems below it. This guide explains what the plant information network is, which systems live on it, why it is firewalled from control, and how it feeds the business network, complementing the wider Purdue model of network levels.
Plant information network in one line: A plant information network is the site-level information tier, Level 3 in the Purdue model, that sits above the process control network and hosts systems such as the plant historian, manufacturing execution system, and reporting and engineering servers. It aggregates data from the control layer into a form the plant and business can use, and it is deliberately separated from the control network below and the corporate network above by firewalls so that information can flow without exposing control systems.
The Purdue model arranges an industrial environment into levels, and the plant information network corresponds to Level 3, the site or plant operations level. Below it are the control network levels where controllers, I/O, and instruments do the real-time work of running the process. Above it is the enterprise level where corporate IT systems run the business. Level 3 is the meeting point: it is where the operational technology world hands data up toward the information technology world, and it does so in a controlled, aggregated way rather than exposing the control systems directly.
The systems that live on this network are the ones that consolidate and use plant-wide data. The plant historian collects process history from the control systems and serves it for trending, analysis, and reporting. A manufacturing execution system manages production orders, tracks batches, and coordinates operations across units. Engineering workstations, domain controllers, patch and antivirus servers, and reporting and dashboard servers also commonly sit here. What these have in common is that they need broad access to plant data and to each other, but they do not participate in real-time control.
Placing these systems on their own tier keeps their traffic and their trust boundary separate from both control and corporate. The historian can pull from many controllers, the MES can coordinate across units, and reporting servers can serve dashboards, all within Level 3, without any of that activity reaching down into the time-critical control network or reaching up into the corporate network unfiltered. The plant information network is, in effect, the place where the operational data of the site is brought together and made useful.
The separation between the plant information network and the control network below it is one of the most important boundaries in an industrial architecture. The control network carries the real-time traffic that keeps the process running safely, and it must be protected from anything that could disrupt its timing or compromise its integrity. The information network, by contrast, connects to systems that are more general-purpose, more frequently patched, more likely to be touched by users, and more exposed to the corporate world. Letting those two worlds mix freely would put the control systems at risk, so a firewall enforces the boundary.
In good practice this boundary is not a single firewall but a controlled zone, often built as a demilitarised zone between the levels, where data is handed across through specific, inspected paths rather than open connectivity. Systems on the information network do not reach directly into the controllers; instead, defined data flows, such as a historian collector pulling values or a system pushing setpoint targets, pass through the boundary under strict rules. The intent is that information can cross while the attack surface stays small and the control network remains isolated from general traffic.
This firewalling is central to industrial cybersecurity frameworks, which treat the control network as a zone to be defended and the information network as a separate zone with its own protections, with tightly controlled conduits between them. The plant information network therefore plays a dual role: it is where plant data is aggregated and made available, and it is also a buffer that keeps the control systems one clear step away from both the users and the wider network. The value it delivers upward depends on the discipline of the boundary it maintains downward.
Above the plant information network sits the enterprise or business network, and the information tier is what feeds it. Reports, production figures, key performance indicators, and historical data that the business needs are prepared on Level 3 and passed up to corporate systems, again through a controlled boundary rather than open access. This is how a plant's operational reality becomes visible to planners, managers, and enterprise applications: the raw signals from the process are collected and refined on the information network, and only the resulting information crosses into the business world.
This layered arrangement developed in an on-premises world where every level was a physical network in the plant. Cloud SCADA reshapes the picture without discarding its logic. In a cloud model, much of the aggregation, historian, and reporting role that Level 3 provides is delivered from a central platform rather than a rack of on-site servers, while the discipline of separating control from information and controlling what crosses each boundary remains just as important. The functions of the information tier persist; where they physically run changes.
For distributed operations this shift is especially useful. A platform such as Merobix collects data from many remote sites and provides the historian, trending, reporting, and dashboards that a per-site plant information network would otherwise provide locally, all from one place and accessible to the wider team. Rather than each site maintaining its own information tier, the aggregation happens centrally, while the connection from each site is kept controlled and the control equipment stays protected behind its own boundary. The Purdue thinking about separating levels and controlling data flow still guides the design; the plant information tier simply becomes a shared, cloud-hosted service that spans the whole footprint.
It corresponds to Level 3, the site or plant operations level in the Purdue model. It sits above the process control network levels, where controllers and instruments run the process in real time, and below the enterprise level, where corporate business systems run. Level 3 is the aggregation tier where operational data is collected and made useful before any of it crosses up to the business.
Typical systems include the plant historian that collects and serves process history, a manufacturing execution system that manages production and batches, engineering workstations, and reporting, dashboard, and infrastructure servers. What they share is a need for broad access to plant data without participating in real-time control, which is why they sit on their own tier between the control network and the corporate network.
The control network carries time-critical traffic that keeps the process running safely and must be protected from disruption, while the information network connects to more general, user-facing, and internet-adjacent systems. Mixing them would expose control systems to risk, so a firewall or controlled boundary zone separates them, allowing defined data flows to cross while keeping the control network isolated and its attack surface small.
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.