Practice / 01 Practice · Energy & industry ISO 27001 · IEC · NIS2 · Cyber Resilience Act

Industrial networks & OT security

Connectivity for plants and remote sites, and the boundary between the process network and the office one.

RoleIT and telecommunications lead
ScopeSensors, industrial routers, remote sites, OT/IT boundary
BasisDescribed at a high level under NDA
In brief

A plant network is not a small office network. It inverts the usual priorities: availability first, because a stopped line costs money every minute; equipment that has been in service for a decade and will stay for another; and protocols that were designed when the network was assumed to be physically private, so they authenticate nothing.

You cannot re-architect that away. The engineering is in the boundary you put around it.

Remote industrial sites with sensors and routers connected to an operations core over authenticated tunnels.
Fig. 01 · Remote industrial sites with sensors and routers connected to an operations core over authenticated tunnels. Synthetic.

Where the work actually is

The link between the plant and the office is segmented, authenticated and logged. Segmented so a compromise on one side does not become a compromise on the other. Authenticated so the tunnel knows who is at each end. Logged so that afterwards there is an answer to what happened, rather than a theory.

None of that is exotic. What makes it engineering rather than configuration is deciding what may cross the boundary at all, and being able to justify each exception to somebody who will ask.

Regulation as an input, not a report

NIS2 and the Cyber Resilience Act changed what the sector has to be able to demonstrate, not just what it has to do. Most of the cost is not new equipment: it is evidence, and evidence is only cheap if the system was built to produce it.

Alongside that I am taking the organisation itself to ISO 27001, writing the policies, procedures and evidence single-handedly. The hard part is not the document set. It is writing something the business will actually follow, because a control nobody performs is worse than no control: it is a control you believe you have.

What I will not publish

No topology, no vendor list, no site count, no addressing, no exception list. That is not modesty, it is the point: a description precise enough to be useful to an attacker is a description I should not have written.

Applied
OT / IT segmentationIndustrial routersISO 27001NIS2 · CRAIECEvidence & audit

Work carried out under NDA. This page describes the engineering, not the employer. No employer names, internal architectures, client details or proprietary systems appear anywhere on this site, and none will be added.

Next

A normative RAG for engineers

Read it →
← SANIX Professional experience is described at a high level to protect confidentiality