OT Cybersecurity for Industrial Control Systems: Why Your SCADA Network Is Not as Protected as You Think
When it comes to industrial OT cybersecurity, oT vs IT Security: Why They Are Different Problems
Operational Technology (OT) cybersecurity, protecting SCADA systems, PLCs, HMIs, and industrial networks, is fundamentally different from IT security. Understanding the differences is the starting point for appropriate protection:
Dimension
IT Network Security
OT/ICS Security
Primary concern
Confidentiality of data
Availability and integrity of physical process
Patch management
Regular updates acceptable
OS patches often impossible (no certified patch for 10yearold SCADA HMI)
Downtime tolerance
Planned downtime acceptable
Unplanned shutdown may cost crores per hour
Asset lifecycle
3–5 years typical
15–25 years for PLC and SCADA infrastructure
Security testing
Penetration testing standard practice
Pen testing of live PLC/SCADA too risky , process disruption possible
Endpoint protection
Centrally managed and routinely updated
Use validated antimalware, application allowlisting, and controlled update procedures compatible with the OT application
The Purdue Reference Model: Organizing OT Security in Layers
The Purdue model is a widely used reference for organizing industrial systems by functional level. IEC 62443 complements this view with risk based zones and conduits. Security strategy should control and monitor communications across each trust boundary:
| Level | Description |
|---|---|
| Level 4 , Enterprise IT | Corporate network: ERP, email, internet access |
| Level 3 , Site Operations (MES/Historian) | Plant data servers, production databases, OPCUA data aggregators |
| DMZ , Demilitarised Zone | Isolated buffer zone between OT and IT: data diodes, unidirectional gateways, mirrored historians |
| Level 2 , SCADA / HMI | Supervisor workstations, WinCC servers, operator consoles |
| Level 1 , PLC / DCS | S71500, S71200 controllers, field device interfaces |
| Level 0 , Field | Sensors, actuators, drives, instruments, physical process equipment |
| A critical boundary is Level 3 / DMZ / Level 2. Direct, uncontrolled connectivity between corporate IT and the SCADA network increases risk and should be replaced by segmented, monitored conduits. | IEC 62443: The Industrial Cybersecurity Standard |
| IEC 62443 (Industrial Communication Networks, Network and System Security) is the primary international standard for OT cybersecurity. It defines security requirements for three stakeholder groups: | • Asset owners (plant operators): responsible for defining security policy and risk management |
- System integrators (ACS Engitech): responsible for designing and implementing secure OT architectures
- Product suppliers (Siemens): responsible for manufacturing cybersecurity hardened products
IEC 62443 defines security levels for zones, conduits, systems, and components. These levels describe resistance to different attacker capability and motivation assumptions; they should not be treated as equivalent to functional safety SIL ratings. The target level must be established through a documented cybersecurity risk assessment.
Common OT Security Vulnerabilities in Industrial Plants
Vulnerability
Risk Level
Remediation
SCADA HMI directly connected to corporate LAN
Critical
DMZ architecture, industrial firewall, network segmentation
Unmanaged remote access or open RDP
Critical
Industrial VPN router (Siemens SCALANCE S615); role based access control
Default passwords on PLC and SCADA software
High
Change all default credentials; implement password policy
Unpatched Windows on HMI/SCADA PC (XP/7 common)
High
Application whitelisting where patch not possible; network isolation
USB ports open on HMI PC
High
USB port blocking via endpoint control or physical locks
No backup of PLC program and SCADA project
High
Weekly automated backup to secured, offline storage
Single SCADA server with no backup
Medium
Hot standby server; UPS; offsite program backup
Siemens SCALANCE: Industrial Network and Security Hardware
Siemens SCALANCE is the product family for industrial network infrastructure and OT security. Key products relevant to plant security architecture:
- SCALANCE S615 Industrial Security Router: VPN gateway (IPsec, OpenVPN); stateful packet inspection firewall; NAT; HTTPS web interface. Provides secure remote access to PLC/SCADA network for maintenance engineers.
- SCALANCE XM400 Managed Switches: VLAN segmentation, port security, MAC address filtering, IEEE 802.1X authentication, enables network segmentation within the OT zone.
- SCALANCE W (Industrial WLAN): IEC 62443certified wireless access points for industrial environments , supports WPA3 and IEEE 802.1X for Wi-Fi device authentication.
Practical OT Security: The Five Things to Do First
1. Network inventory and segmentation: Document every device on your OT network. Separate OT from corporate IT using a hardware firewall. This single step eliminates the most common attack vector.
2. Replace all default credentials: PLC web servers, WinCC SCADA, HMI operator accounts, and network switches all ship with default passwords. These are publicly documented by the manufacturers and exploited by attackers.
3. Close all unnecessary remote access: Disable any remote access tool (TeamViewer, Any Desk, open RDP) and replace with a managed industrial VPN with MFA (Multifactor Authentication).
4. Program and configuration backup: Every PLC program, SCADA project, and drive parameter set should be backed up weekly to offline storage. An unrecoverable plant shutdown is far more damaging than the initial attack.
5. Change management for USB and portable media: All USB access to HMI/SCADA PCs should be controlled. Removable media remains a recognized path for malware introduction and should be governed through approved devices, scanning, logging, and physical or technical controls.
Conclusion: OT Security Is Now Operational Risk Management
A decade ago, OT cybersecurity was the concern of critical national infrastructure operators. Today, it is a relevant risk for any industrial plant with a networked SCADA system, remote access capability, or ITOT integration, which includes the majority of modern Indian manufacturing facilities.
The good news: the highest risk vulnerabilities are addressable with practical, cost-effective measures. Network segmentation, credential management, and controlled remote access resolve the most likely attack vectors without requiring a plant shutdown or complete infrastructure replacement.
Suggested social hashtags: #OTSecurity #ICS #SCADA #IEC62443 #Cybersecurity #Siemens #SCALANCE #IndustrialNetworks #PurdueModel #ACSEngitech
About ACS Engitech Pvt. Ltd.
Since 2009, ACS Engitech has delivered automation solutions across manufacturing sectors. As a Siemens Channel Partner, we provide comprehensive automation systems including PLC panels, SCADA implementation, and remote monitoring solutions. Our 6000 sq. ft. manufacturing facility in Ahmedabad serves clients across India with ISO 9001-certified control panel solutions.
Take Action Today
Ready to optimize your facility? Connect with us to discuss how automation can improve your operations and address critical demands.
Connect With Us