Editor's Choice


Futureproof your industrial network security with OT-centric cyber security

February 2025 Editor's Choice

Today, industrial organisations are embracing digital transformation to gain a competitive edge and boost business revenue. To achieve digital transformation, industrial operators must first address the daunting task of merging their information technology (IT) and operational technology (OT) infrastructure. Businesses trying to streamline data connectivity for integrated IT/OT systems often encounter challenges such as lacking performance, limited network visibility and lower network security from existing OT network infrastructure. Building a robust, high-performance network for daily operations that is easy to maintain requires thorough planning.

Why ramping up OT network security is a must

Nowadays, industrial applications are facing more and unprecedented cyberthreats. These threats often target critical infrastructure in different industries all across the world, including energy, transportation and water and wastewater services. If successful, such attacks can cause significant damage to industrial organisations in the form of high recovery costs or production delays.

Before building IT/OT converged networks, asset owners must define the target security level of the entire network and strengthen measures to minimise the impact of potential intrusions. Poor network security exposes critical field assets to unwanted access and allows malicious actors to breach integrated systems.

However, strengthening OT network security is not that straightforward. IT security solutions require constant updates to ensure they can protect against the latest cyberthreats. Applying these necessary updates often means interrupting network services and systems, which is something OT operations cannot afford. Operators need an OT-centric cybersecurity approach to protect their industrial networks without sacrificing network or operational uptime.

Three major stages in building OT cybersecurity

Building a secure industrial network can be done with the right approach. The key to strong cybersecurity is implementing a multi-layered defense strategy in several stages.

Stage one : Build a solid foundation with secure networking devices

When developing secure networking infrastructure, start with choosing secure building blocks. The increasing number of cyberthreats has also led to the development of comprehensive OT network security standards. Industrial cybersecurity standards such as NIST CSF and IEC 62443 provide security guidelines for critical assets, systems and components. Implementing industrial cybersecurity standards and using networking devices designed around these standards provides asset owners with a solid foundation for building secure network infrastructure.

Stage two: Deploy OT-centric layered protection

The idea of defense-in-depth is to provide multi-layered protection by implementing cybersecurity measures at every level to minimise security risks. In the event of an intrusion, if one layer of protection is compromised another layer prevents the threat from further affecting the network. In addition, instant notifications for security events allow users to respond quickly to potential threats and mitigate any risk.

When deploying multi-layered network protection for OT networks and infrastructure, there are two key OT cybersecurity solutions to consider, namely industrial firewalls and secure routers.

An efficient way to protect critical field assets is using industrial firewalls to create secure network zones and defend against potential threats across the network. With every connected device being the potential target of cyberthreats, it’s important to deploy firewalls with robust traffic filtering that allow administrators to set up secure conduits throughout the network. Next generation firewalls feature advanced security functions such as Intrusion Detection/Prevention Systems (IDS/IPS) and Deep Packet Inspection (DPI) to strengthen network protection against intrusion by proactively detecting and blocking threats.

Advanced security functions tailored for OT environments help ensure seamless communications and maximum uptime for industrial operations. For example, OT-centered DPI technology that supports industrial protocols can detect and block unwanted traffic, ensuring secure industrial protocol communications. In addition, industrial-grade IPS can support virtual patching to protect critical assets and legacy devices from the latest known threats without affecting network uptime. Designed for industrial applications, IPS provides pattern-based detection for PLCs, HMIs and other common field site equipment.

IT/OT converged networks require a multi-layered and complex industrial network infrastructure to transmit large amounts of data from field sites to the control centre. Deploying powerful industrial secure routers between different networks can both fortify network boundaries and maintain solid network performance. Featuring built-in advanced security functions such as firewall and NAT, secure routers allow administrators to establish secure network segments and enable data routing between segments. For optimal network performance, a powerful industrial secure router features both switching and routing functions with gigabit speeds, alongside redundancy measures for smooth intra- and inter-network communication.

The demand for remote access to maintain critical assets and networks has also been on the rise. Industrial secure routers with VPN support allow maintenance engineers and network administrators to access private networks remotely through a secure tunnel, enabling more efficient remote management.

Stage three: Monitor the network status and identify cyberthreats

Deploying a secure industrial network is just the start of the journey towards robust cybersecurity. During daily operations, it takes a lot of time and effort for network administrators to have full network visibility, monitor traffic and manage the countless networking devices. Implementing a centralised network management platform can provide a huge boost to operational efficiency by visualising the entire network and simplifying device management. It also allows network administrators to focus more resources on ramping up network and device security.

In addition, a centralised network security management platform for cybersecurity solutions can boost efficiency even more. Such software allows administrators to perform mass deployments for firewall policies, monitor cyberthreats and configure notifications for when threats occur. The right combination of cybersecurity solutions and management software offers administrators an invaluable way to monitor and identify cyberthreats with a holistic view.

Futureproof your network security with our solutions

Network security is imperative for industrial network infrastructure. Moxa has translated over 35 years of industrial networking experience into a comprehensive OT-centric cybersecurity portfolio that offers enhanced security with maximum network uptime. Moxa is an IEC 62443-4-1 certified industrial connectivity and networking solutions provider. When developing our products, we adhere to the security principles of the IEC 62443-4-2 standard to ensure secure product development. Our goal is to provide our users with the tools necessary to build robust device security for their industrial applications.

To defend against increasing cyber threats, our OT-focused cybersecurity solutions maximise uptime while protecting industrial networks from intruders. Our network management software simplifies management for networking devices and OT cybersecurity solutions, allowing administrators to monitor the network security status and manage cyberthreats with ease.


Credit(s)



Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

Time-sensitive networking
RJ Connect Editor's Choice Fieldbus & Industrial Networking
In this article, we will explore what is driving the rise of time-sensitive networking, how it is reshaping industrial efficiency, the challenges when deploying this technology, and ways to tackle these challenges.

Read more...
Loop Signature 30: Nonlinearity in control loops (Part 1)
Michael Brown Control Engineering Editor's Choice Fieldbus & Industrial Networking
If nonlinearity occurs it means that if one is to carry on controlling with the same response to changes in load or setpoint, then the tuning of the controller will also need to be adjusted to meet the new conditions.

Read more...
Precision in paper processing
VEGA Controls SA Editor's Choice Level Measurement & Control
Paper manufacturing is a demanding process that relies on consistency, precision and control at every stage. The VEGABAR 82 pressure transmitter is well-suited to these harsh environments.

Read more...
Ensuring clean and safe water
Endress+Hauser South Africa Editor's Choice Analytical Instrumentation & Environmental Monitoring
Endress+Hauser’s comprehensive range of disinfection sensors is designed to monitor and control disinfectant levels in water treatment processes.

Read more...
A South African legacy in telemetry
Interlynx-SA Editor's Choice Industrial Wireless
Telemetry is becoming a vital component of industrial strategy, allowing companies to harness real-time data to optimise processes and reduce waste. One company leading this technological shift is Interlynx.

Read more...
Case History 199: Another example of the effectiveness of cascade control
Michael Brown Control Engineering Editor's Choice Fieldbus & Industrial Networking
In my last article I wrote about how cascade control systems can effectively overcome valve problems. This article gives another example of how a temperature control was able to perform well, in spite of really severe valve problems.

Read more...
Upgrading legacy automation
Omron Electronics Editor's Choice Fieldbus & Industrial Networking
Legacy automation is characterised by technology in the later stages of its useful life. As new automation technologies continue to emerge and interconnect at an exponential rate, failing to integrate these technologies can widen the gap between the competitive and the obsolete.

Read more...
The silent risk inside data centres
RJ Connect IT in Manufacturing
In recent years, data centres have become prime targets for cybercriminals. While most attention is often placed on protecting IT infrastructure such as servers, routers and cloud connections, there is a hidden vulnerability that many organisations overlook, the operational technology inside their facilities.

Read more...
Planetary gear units for high torque requirements
SEW-EURODRIVE Editor's Choice Motion Control & Drives
Packing a compact design, along with high torque and low-speed outputs, the new SEW PPK and SEW P2.e planetary gear units from SEW-EURODRIVE offer new capabilities in continuous heavy-duty applications where space is at a premium.

Read more...
These robots crawl into every nook and cranny
DNH Tradeserve t/a DNH Technologies Editor's Choice Motion Control & Drives
Inuktun's small crawler robot magnetically sticks to metal walls and is able to move in all directions. It carries cameras, sensors and tools for inspection or maintenance work in tight pipes and on the outer hulls of tanks or ships. All crawler modules and cameras are equipped with brushed DC motors from Swiss drive specialist, maxon using various motor-gearhead combinations.

Read more...









While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd | All Rights Reserved