Phi Tech Solutions

Engineering for process plants since 2005

phitech.com.pk (opens in a new tab)

Process engineering, process control and OT security, in one company.

Phi Tech Solutions has worked in process plants since 2005. PhiSecure is its OT cybersecurity practice, working alongside the company's process engineering, process control and reliability teams.

Visit phitech.com.pk (opens in a new tab)
A control room where three process screens stand on a wooden console desk in front of a curved wall of older hard wired instruments and gauges

L3 and L2

Endpoint Security

HMIs and engineering workstations are standard computers doing critical work. They often run older operating systems approved by the control system vendor, and standard office antivirus can disrupt them and stop the process.

Where this sits

  1. L4Enterprise network
  2. L3.5DMZ
  3. L3Operations
  4. L2Supervisory
  5. L1Control
  6. L0Process
1.0

What we install

We install protection designed for control systems and check it against your control system vendor’s support terms before it is installed on any live computer. Where a computer cannot run protection software, we control what is allowed to connect to it.

What is included

  • Endpoint protection designed for control systems
  • Application allow listing, so each computer runs only approved software
  • Device control, so unknown USB drives and devices are blocked
  • A written check against your control system vendor’s support terms before installation
  • A tested rollback procedure, so any computer can be restored to its previous state
2.0

Where it sits

  1. L4Enterprise networkBusiness systems, email, the internet
  2. L3.5DMZBetween the plant and the business
  3. L3OperationsWhere this sits
  4. L2SupervisoryWhere this sits
  5. L1ControlPLC and DCS controllers, safety systems
  6. L0ProcessInstruments and final elements

This solution is installed on the computers themselves, at L2 and L3. Because of this, we do not install it until your control system vendor has approved it.

3.0

How it is installed

The steps we follow

  1. 01

    We list the computers, the software on each one and what your control system vendor supports.

  2. 02

    The protection policy is written and agreed, including the approach for computers that cannot run protection software.

  3. 03

    The software is first installed on a computer that is not in service and monitored until it has proven stable.

  4. 04

    It is then rolled out one computer at a time, at times chosen by your operations team.

  5. 05

    Each computer is checked after installation and the result is recorded.

4.0

What this solution is not

  • Not office antivirus.

    Office antivirus updates and quarantines files without warning, which is not acceptable on a computer running a process.

  • Not a risk to your vendor support.

    If your control system vendor will not support a computer with the protection installed, we do not install it. This is confirmed in writing beforehand.