Phi Tech Solutions

Engineering for process plants since 2005

phitech.com.pk (opens in a new tab)

Process engineering, process control and OT security, in one company.

Phi Tech Solutions has worked in process plants since 2005. PhiSecure is its OT cybersecurity practice, working alongside the company's process engineering, process control and reliability teams.

Visit phitech.com.pk (opens in a new tab)

Network architecture

Common routes into a control network and how to secure them

Most control networks are reached in a small number of ways. Four of them can be closed, and the fifth is managed with monitoring.

IEC 62443

When asked how an attacker could reach their control network, many plant managers give one of two answers: that the network is air gapped, or that they are not sure.

The second answer is more often accurate. Most plants are connected to the office network by a link that was added years ago so that production reports could reach the business. The link is in use, it carries traffic, and it is often missing from the network drawings.

This article describes the routes by which control networks are most commonly reached, in the order we usually find them. Four of them can be closed. The fifth cannot be listed in advance, so it has to be monitored.


This is usually the first finding in an assessment.

Most plants have a connection between the process network and the office network. It was added for a valid reason, such as sending production figures to the business, giving the maintenance system access to equipment data or allowing a vendor to collect logs. It was often set up as a temporary measure by an engineer who has since left, and it has not been reviewed since.

The link itself is not the problem, because plants need to send data out. The problem is that it usually allows far more traffic than it was created for, in both directions, and no one is responsible for it.

How to secure it. Place a boundary at the link that allows only the traffic the process needs. Where data should only flow out of the plant, a data diode can enforce this in hardware. A diode has no physical return path, so the restriction cannot be relaxed later.

What it involves. Someone has to decide which traffic the process needs, which requires input from operations as well as configuration work. This review often identifies data flows that no one knew about.


Remote access for vendors

Your control system vendor needs remote access from time to time, as do integrators, analyser suppliers and the company that supports the historian.

We often find a single shared VPN account that is always switched on. Everyone uses it, it has been in place for years, the password has been passed around, and there is no record of which company, or which person, connected on a given day.

That account gives permanent access to your plant to an unknown number of people at organizations outside your control.

How to secure it. Give each person their own account, open access only when the work has been approved, and close it automatically when the work ends.

What it involves. Urgent connections outside working hours take slightly more effort, so an emergency procedure should be agreed in advance. In return, you can always see who accessed your systems and when.


USB drives and removable media

USB drives remain one of the most common ways malware reaches a control network. They do not arrive over the network. They are carried in by people.

In most cases the intentions are good: a contractor with a firmware update, an engineer with a configuration backup, or a vendor with a patch on a USB drive because the site has no other way to receive it.

An air gap does not protect against this route. In fact, an air gap is what makes USB drives necessary.

How to secure it. Install a scanning station at each entrance, so that every drive is checked before it reaches plant equipment, and issue clean media after scanning. Typical locations are plant entrances, contractor gates and control room doors.

What it involves. Staff and contractors have an extra step to follow. A station works best at the entrances people already use, and is often bypassed if it is placed somewhere inconvenient.


Plant workstations and servers

This route covers the HMIs in the control room, engineering workstations, historians and operator stations.

These are standard computers, but their software is often several versions behind, because updating them means changing a system that is running the process. Many cannot run modern security software, and older ones may fail if it is installed.

The most common problem is not neglect. It is standard office antivirus installed on an HMI with good intentions, which then quarantines a file the control system needs and stops production.

How to secure it. Use protection designed for control systems, and check it against your control system vendor’s support requirements before installation. On older computers, use application allow listing, which permits only approved software to run and blocks everything else.

What it involves. Checking vendor support takes longer than installing software directly, but it prevents the protection from causing an outage.


Routes that have not been identified

The four routes above are the ones we find most often, but they are not the only ones. No list of routes is complete.

Plants change over time. Contractors add equipment. A vendor installs a new analyser with its own cellular modem for remote support. Two networks are connected temporarily during a shutdown, and the connection is never removed. None of this is negligence. It is part of running a plant.

How to manage it. Monitor the network. Passive monitoring reads a copy of the traffic on the control network, builds an inventory of the connected devices, learns the normal pattern of traffic and alerts you when it changes.

Because the monitoring is passive, the sensor sits on a mirror port and is not in the path of any traffic. It cannot stop your process, which is why it can be installed in a plant that is already running.

Monitoring also produces an asset inventory based on the devices that are connected, which is often more accurate than the existing network drawings.


What this means in practice

Four of these routes can be closed, and the fifth must be monitored because it cannot be listed in advance.

You do not need to address all five at once. The most important route differs from site to site, and it can only be identified by looking at your plant. A site with a strong boundary and no monitoring has different needs from a site with good monitoring and a shared VPN account.

For this reason, the work starts with finding out which routes are open at your site and how exposed they are. This is the purpose of a SCADA and DCS health check. It records what is connected to the network, not only what the drawings show, and ranks the findings by potential impact.

The approach described here is aligned with IEC 62443, the standard most auditors use. The main reason to follow it is practical: four of these routes can be closed, and many plants have not yet closed them.

Next step

A health check shows which of these issues apply to your plant.