Phi Tech Solutions

Engineering for process plants since 2005

phitech.com.pk (opens in a new tab)

Process engineering, process control and OT security, in one company.

Phi Tech Solutions has worked in process plants since 2005. PhiSecure is its OT cybersecurity practice, working alongside the company's process engineering, process control and reliability teams.

Visit phitech.com.pk (opens in a new tab)
A plant equipment room: cable trays crossing the ceiling and running down the wall into a mounted rack of switches, patch panels and servers, with a card reader on a stand beside it

L3.5

Zone Boundary Protection

In most plants, the control network and the office network are connected by a single link that was added years ago to send reports to the business. Often no one owns it, its rules have only ever been added to, and a threat on the office network can reach the process.

Where this sits

  1. L4Enterprise network
  2. L3.5DMZ
  3. L3Operations
  4. L2Supervisory
  5. L1Control
  6. L0Process
1.0

What we install

We install an industrial firewall at the boundary, configured to allow only the traffic your process needs. Where data should only flow out of the plant, we install a data diode. It has no return path in hardware, so the restriction cannot be relaxed later.

What is included

  • A zone and conduit design, documented and agreed before anything is purchased
  • An industrial firewall that understands the protocols your plant uses
  • Hardware data diodes wherever data should flow in one direction only
  • Firewall rules based on a recording of your own traffic
  • Testing to demonstrate that the return path is closed
2.0

Where it sits

  1. L4Enterprise networkBusiness systems, email, the internet
  2. L3.5DMZWhere this sits
  3. L3OperationsHistorians, domain services, engineering
  4. L2SupervisorySCADA servers and operator stations
  5. L1ControlPLC and DCS controllers, safety systems
  6. L0ProcessInstruments and final elements

This solution sits at L3.5, between the plant and the business network. Nothing below it is changed or restarted.

3.0

How it is installed

The steps we follow

  1. 01

    We record the traffic that currently crosses the boundary, using a copy of the traffic. Nothing is blocked during this stage.

  2. 02

    Zones and conduits are designed and agreed with your team before anything is ordered.

  3. 03

    The new boundary is built and tested alongside the existing link.

  4. 04

    Traffic is moved across at a time chosen by your operations team, with the old path still available.

  5. 05

    We demonstrate that the return path is closed and provide the test evidence.

4.0

What this solution is not

  • Not an office firewall.

    Office firewalls do not understand industrial protocols, so they either block process traffic or allow all of it through. Neither provides protection.

  • Not a replacement for an asset inventory.

    A boundary controls what crosses it. It cannot show what is already on the network behind it, which requires a separate service.