Lesson 21 is where students find out power and networks aren't the electrician's problem or the IT department's problem, they're design decisions a solutions engineer has to catch. Two things must land: the two voltage worlds with the four electrical awareness points, and the exact network naming (EtherNet/IP and CIP Safety) with the case for segmenting the OT network and controlling who touches it. Don't let it drift into an electrician's lecture. Keep driving back to the one discipline: understand each layer well enough to catch the decision that will hurt the project.
| Segment | Min | What happens |
|---|---|---|
| The two invisible things | 6 | Open on the hook: power and a network, both boring until they fail. Ask the room for a time bad power or a bad network took something down. Land the frame: you're not the contractor or the network engineer, but you catch the decision that hurts the project. |
| Two voltage worlds and the four awareness points | 13 | Draw the 480-volt world and the 24-volt world; have students sort components into each. Then the four awareness points: panel standards (NFPA 70), short-circuit and current capacity, power quality, grounding. Stress that you carry the load picture, you don't size the electrical equipment. |
| One industrial network, naming drilled | 12 | Drill the exact names and ownership: EtherNet/IP built on CIP, CIP Safety an extension of CIP, both trademarks of ODVA, Inc. Make the point stick: one network carries ordinary and safety-rated control at once, and the safety traffic keeps its integrity on the shared wire. |
| Segmentation, remote access, and OT cybersecurity | 17 | Run the flat-network war-game (see key teaching moment). Segment the OT network from the business network. Controlled remote access, not an always-open door. Patching cadence, incident-response basics, and the ownership question run live. This is the heart of the lesson. |
| Riverside power-and-network note | 8 | Students assign Riverside's components to the two voltage worlds and the EtherNet/IP and CIP Safety segments, then debate who owns Riverside's OT network given Ray owns IT and the WMS. Make them name a person and defend it. |
| Forest and close | 4 | Powered, connected, and defended. Tie back to the driving question and the three lessons of controls that ride on this layer. Close on the ownership question they still can't fully answer. |
| Total | 60 | Baseline session. Expand with the stretch options below if you have 90 minutes. |
Put the flat-network temptation on the board: one switch, everything on it, office and floor and safety together. It looks cheaper. Ask the room to war-game a peak wave when the office side saturates the link. Walk it: a backup job fills the link, routing messages arrive late, the sorter starts missing diverts, and nobody looks at the network because it doesn't present as a controls problem. The moment a student traces that late message back to a network nobody segmented is the moment power and networks stop feeling like someone else's job.
Then run the ownership question live: who owns the OT network? Watch the room work through IT, the controls team, and the space in between, and realize nobody in the scenario owns it. That realization is the lesson.
Drive each one back to the discovery principle: understand it well enough to catch the decision that will hurt the project.
Have students assign every Riverside component to a voltage world, then to a network segment. The 480-volt three-phase feeds the two panels (northwest mechanical room and southeast corner) and the sorter drive; the 24-volt DC domain runs the MDR zones, the Lesson 19 sensing, and the Lesson 20 safety devices. EtherNet/IP carries the PLC-to-WCS traffic and Ray's WMS-response query; CIP Safety carries the pull-cord e-stop and the forklift-crossing messaging from the safety PLC.
Then the debate: who owns Riverside's OT network? Ray owns IT and the WMS, so the room reaches for Ray by default. Make them name a person and defend it, and make them separate the business network Ray already owns from the OT network that has no owner yet. There isn't one clean answer; the discipline is that the question gets named and a name gets written down.
Instructor-only note: the OT-network owner and the remote-access path never get closed unless the engineer forces it in design. That's the L21 discipline. If students leave the OT owner blank and shrug, they've reproduced the failure the lesson warns about. Make them feel the blank.
1. The IT director wants control, safety, and office on one flat network.
A strong answer separates two ideas the director is running together. What one industrial network is designed to allow: standard control traffic and safety-rated CIP Safety traffic riding the same EtherNet/IP infrastructure, with CIP Safety holding its own integrity guarantee on the shared wire. What it isn't designed to allow: the machine-control network flattened onto the business and office network. Sharing one industrial network is control and safety sharing infrastructure inside the OT boundary; it says nothing about merging that OT network with email and file shares. The case for separation: the OT network prioritizes uptime and deterministic timing and runs equipment that can't take a surprise reboot, so segmenting it keeps an office outage or a broadcast storm from starving the sorter of routing messages, and lets it be patched on terms the machines tolerate. Full credit doesn't confuse "one industrial network for control and safety" with "one flat network for everything."
2. Six months in, nobody can say who owns the OT network or how the vendor gets in.
Both are design failures because both are decisions that had to be settled during design and were left open. Ownership: IT owns the business network and the controls team owns the machine logic, but the OT network in between needs a named owner, and leaving it unnamed means nobody is accountable for patching, monitoring, or incident response. Access: remote access is necessary, but an uncontrolled or forgotten path is a gap nobody can account for. What should have been in place: a named OT-network owner agreed between IT and the controls team before go-live, a controlled remote-access path that can be closed, a patching cadence the OT network can tolerate, and incident-response basics. Full credit ties both gaps back to the discovery principle: the engineer has to force these items closed in design, because nobody else will until the network breaks.
The power-and-network note students produce in the Riverside beat is another page of the capstone controls package. It carries the voltage domains, the network segments, the EtherNet/IP and CIP Safety assignment, the remote-access owner, and the named OT-network owner into the controls architecture summary they've built since Lesson 18. Keep reinforcing the project-note habit without explaining where it leads.
Watch for students who write down a name for the OT-network owner even though the scenario doesn't hand them one. Those are the students building the right instinct, that the blank is theirs to close. Never tell the room why the note matters; the payoff is theirs to find at the capstone.