Architecture

Architecture: From the Field to the Enterprise Cloud

A digital transformation strategy is only as strong as the architecture underneath it. Without a clear, layered structure connecting field devices to enterprise systems, plants end up with disconnected dashboards, duplicated data, and security gaps between operational technology (OT) and information technology (IT). This page sets out the reference architecture INGSOL’s DigitalX vertical builds for factories and manufacturing plants of any kind, from the individual sensor on the shopfloor to the enterprise cloud, and the security boundary that protects everything in between.

A Layered Architecture, Built Deliberately

INGSOL structures DigitalX deployments around a layered model aligned with established industrial architecture practice, commonly referred to using Layer 0 to Layer 4 terminology. Each layer has a specific role, and each depends on the layer beneath it being reliable. This is not a theoretical framework; it is the practical structure INGSOL implements on real plant floors, spanning discrete assembly, continuous process, and every production environment in between.

Layer 0
LAYER 0

The Field Layer

At the base of the architecture sits the equipment itself: extrusion lines, printing and converting equipment, utility systems, or whichever production areas make up your specific process. Each area’s machines, drives, sensors and PLCs generate the raw signals that the rest of the architecture depends on, whether that is a temperature reading, a motor status, or a start and stop command from an operator panel.

INGSOL treats this layer as the foundation of the entire architecture, since inaccurate or missing data at this level cannot be corrected further up the stack. Where instrumentation is missing, INGSOL specifies and retrofits the sensors needed to close the gap, as detailed on our Hardware & Edge page.

LAYER 1

The Access Layer

Field devices connect into the architecture through the access layer, typically industrial network switches positioned close to each production area. This layer provides the physical and network connectivity between individual machines and instruments and the aggregation infrastructure above them, kept separate by area so that a fault in one part of the plant does not disrupt visibility elsewhere.

Layer 1
Layer 2
LAYER 2

The Aggregation Layer

Each production area’s access-layer switches connect to an aggregation point, typically an edge server running Ignition Edge. This layer collects and locally processes data from its associated area, whether that is extrusion, printing, converting, utilities, or any other zone, before passing it up to the plant’s core systems. Running this aggregation at the edge, close to the equipment it serves, keeps monitoring responsive even if the wider network experiences disruption.

LAYER 3

The Core Layer

At the plant level, the core layer brings together the systems that give a site its central visibility and control: a historian for long-term data storage, an MES server managing production orders, quality and traceability, an Ignition server providing plant-wide SCADA and supervisory control, and the INGSOL Intelligence Server, which consolidates this data for dashboards and analysis. This layer is where a plant gains a genuine single point of reference for what is happening across every production area, rather than a collection of separate area-level views.

Layer 3
Layer 3.5
LAYER 3.5

The Firewall and DMZ

Between the plant’s OT systems and the wider IT network and cloud, INGSOL places a dedicated firewall and demilitarised zone (DMZ). This boundary controls exactly what data and traffic can pass between operational technology and information technology, preventing external threats from reaching plant-floor systems directly. It is a deliberate architectural layer, not an afterthought, and it is where INGSOL applies network segmentation and access control as standard practice.

LAYER 4

IT and the Path to the Enterprise

Beyond the firewall sits the organisation’s IT network and, ultimately, the enterprise cloud. Traffic reaching this layer has already passed through controlled, monitored access points, reducing the exposure of plant-floor systems to threats originating from the wider corporate network or the internet. This separation is what allows a plant to benefit from cloud-based analytics and enterprise applications without exposing safety-critical control systems to unnecessary risk.

Layer 4

The Enterprise Unified Namespace: The Architecture's Central Hub

At the centre of the cloud side of the architecture sits an Enterprise Unified Namespace, built around an MQTT broker such as EMQX, HiveMQ or Mosquitto. Rather than every enterprise system connecting directly to plant systems through separate, custom integrations, each application publishes to and subscribes from this shared namespace, exactly as described on INGSOL’s Unified Namespace page. The applications connected to this hub each play a distinct role:

Security Built Into the Architecture, Not Added Afterwards

The firewall and DMZ boundary between OT and IT is a deliberate design choice, not a compliance checkbox. External threats attempting to reach plant-floor systems directly are intended to be stopped at this boundary, well before they could reach an Ignition server, an MES system, or the machines themselves. INGSOL designs this segmentation as a core part of every DigitalX architecture, so that the benefits of cloud connectivity, analytics and enterprise integration do not come at the cost of exposing safety-critical control systems.

Security Built Into the Architecture, Not Added Afterwards​
Why This Architecture Matters

Consistency from field to enterprise:

Data flows through a consistent, layered structure rather than a tangle of point-to-point connections between systems that were never designed to talk to each other.

Resilience:

Aggregation at the edge and supervisory control at the plant level continue to operate even if connectivity to the wider IT network or cloud is temporarily lost.

Security by design:

Because OPC UA carries structured, meaningful data rather than raw tag values, downstream systems like MES and analytics platforms can use it with far less manual mapping.

Scalability

New production areas, sites or cloud applications connect into the same layered structure and Unified Namespace, rather than requiring a redesign each time.

Openness:

Open technologies including Ignition, MQTT, PostgreSQL and TimescaleDB avoid dependence on a single proprietary platform at any layer.

How INGSOL Delivers This Architecture

INGSOL builds this architecture in stages, starting with a Digital Transformation Maturity Assessment (DTMA) to establish the current state of your OT infrastructure, systems and security posture. From there, we design and implement each layer in sequence: securing and instrumenting the field and access layers through our Hardware & Edge and Communication & Integration capability, establishing the aggregation and core layers with Ignition Edge, historian, MES and SCADA systems, and building the Unified Namespace and enterprise cloud layer that ties everything together for analytics, AI and enterprise applications.

INGSOL designs and implements DigitalX architecture that connects your field devices to your enterprise cloud through a secure, layered structure, built to scale as your factory and your digital transformation grow. Get in touch to discuss your architecture requirements or a Digital Transformation Maturity Assessment for your plant.

Our Clients

membership