Skip to main content
Call Eric:863-698-8266
CURRYCONTROLS.COMControls & Automation Knowledge Hub

Cybersecurity Articles

Longer-form technical writing, published as it is finished and revised as field experience corrects it. Every entry carries its published and updated dates.

85 entries

ReferencePLCDesign

Modicon M580

Field notes on the Schneider Electric Modicon M580, the Ethernet-backplane controller at the top of the range: remote I/O drops on a ring, hot standby CPUs, built-in security features, the networks it defines, Quantum migration, and what to check on site.

9 min readUpdated Sep 5, 2026

ReferencePLCDesign

Legacy Systems

Keeping older controllers running and planning a migration: the families still found in water plants, the risks that grow each year, software to keep alive, batteries and memory, tested spares, the security problem, and a migration the plant can survive.

9 min readUpdated Sep 5, 2026

ReferenceCommunicationsSCADA

OPC UA

What OPC UA is for, how its information model, security, and transports differ from OPC Classic, where it belongs in a plant, and what to check before relying on it.

8 min readUpdated Sep 5, 2026

ReferenceSCADADesign

SCADA Servers

What the servers in a SCADA system do and what a utility should expect of them: the I/O, alarm, historian, and client roles, physical versus virtual, redundancy, sizing, placement, backup, patching, licensing, and monitoring.

10 min readUpdated Sep 5, 2026

ReferenceSCADAHMI

SCADA Clients

The workstations, browsers, and mobile devices operators use to see and control the system: thick, thin, web, and mobile clients, roles and permissions, where control is allowed from, workstation design, session policy, licensing, and failover behavior.

9 min readUpdated Sep 5, 2026

ReferenceSCADATroubleshooting

Server Failure

How SCADA servers fail and what to do when one does: failure modes from a full disk to a dead hypervisor host, what the plant experiences with and without redundancy, the recovery sequence from restore to alarm verification, and the monitoring that warns.

9 min readUpdated Sep 5, 2026

ReferenceSCADANetworking

Time Synchronization

Why every clock in a control system must agree and what happens when they do not: out-of-order events, historian gaps at daylight saving, authentication failures, wrong totals. The time source and hierarchy, how each device is synchronized, and the checks.

9 min readUpdated Sep 5, 2026

ReferenceSCADADocumentation

SQL Integration

Connecting SCADA and historian data to relational databases: why a utility does it, the methods, a schema that handles time series, the query patterns for totals and reports, the mistakes that flood a database or stall a server, and security.

10 min readUpdated Sep 5, 2026

ReferenceSCADAHMI

Other Platforms

The SCADA and HMI products a water utility may meet beyond the common ones: Siemens WinCC, distributed control systems, independent SCADA products, hosted lift station monitoring, and open-source tools, and the questions that decide whether one belongs.

8 min readUpdated Sep 5, 2026

ReferencePanelsNetworking

Network Switches

Selecting and installing the Ethernet switch in a control panel: managed against unmanaged, industrial ratings and DIN rail mounting, ports and media including fiber, ring protocols, power and grounding, and the configuration documented with the panel.

8 min readUpdated Sep 5, 2026

ReferenceCybersecurityStandards

IEC 62443

The international standard series for industrial automation and control system security: how it is organized, what security levels and foundational requirements mean, and how a utility or integrator actually uses it.

11 min readUpdated Sep 5, 2026

ReferenceCybersecurityNetworking

Zones and Conduits

The IEC 62443 way to segment a control system: grouping assets into zones with a shared security level, inventorying every conduit between them, and turning the drawing into firewall rules. With a worked water utility example.

12 min readUpdated Sep 5, 2026

ReferenceCybersecuritySCADA

Vendor Remote Access

Integrators and equipment vendors need to get in. How to let them without leaving a permanent door open: utility-controlled sessions, named accounts, MFA, a jump host, session recording, and what to do about the modem you did not know was there.

11 min readUpdated Sep 5, 2026

ReferenceCybersecurityPLC

Controller Hardening

What can be locked down on a PLC or RTU: keyswitch and mode, credentials, unused services, access lists, firmware, and the engineering workstation that is the real target.

12 min readUpdated Sep 5, 2026

ReferenceCybersecurityNetworking

Industrial DMZ Design

The buffer zone between the business network and the control system: what goes in it, the no-direct-path rule, push-not-pull data flows, the firewall pair, and the services a utility actually needs to place there.

10 min readUpdated Sep 5, 2026

ReferenceCybersecurityNetworking

Jump Hosts

The one machine every remote session must pass through: what a jump host is, how it is hardened, what it may reach, session recording, the tools it carries, and why a vendor laptop never gets past it.

9 min readUpdated Sep 5, 2026

ReferenceCybersecurityPLC

PLC Program Backups

What a complete controller backup contains, how often to take one, where to keep it, why the upload from the running controller is not the master, and the verification that turns a folder of files into a recovery plan.

9 min readUpdated Sep 5, 2026

ReferenceCybersecurityNetworking

Default Credentials

The passwords printed in the manual: where they hide in a control system, why they are the first thing an attacker tries, how to find every one on site, and the procedure for changing them without locking yourself out.

8 min readUpdated Sep 5, 2026

ReferenceCybersecurityWater

Small Utility Cybersecurity Priorities

What a utility with a few operators and no IT department should do first: the ten measures that remove most of the risk for the least money and time, in the order to do them, with what each one costs, what it prevents, and how to know it is done.

10 min readUpdated Sep 5, 2026

ReferenceCybersecurityStandards

OT Risk Assessment

Ranking what could go wrong in a control system and what it would cost: the consequence-first method for utilities, the assets and scenarios to list, likelihood without pretending to know it, the risk matrix, and turning the ranked list into a work plan.

10 min readUpdated Sep 5, 2026

ReferenceCybersecurityDocumentation

What to Back Up in a Control System

What a utility must be able to restore after a failure or attack: controller programs and firmware, SCADA and historian, HMI panels, drive and instrument parameters, network configurations, licenses, installers, and documentation, and how often each changes.

10 min readUpdated Sep 5, 2026

ReferenceCybersecurityWater

OT Incident Response Plan

The plan for the day the control system is not trusted: who decides, the triggers, the first hour, isolating without stopping treatment, running by hand, preserving evidence, who to notify and when, recovery from backups, and the exercise that makes it real.

10 min readUpdated Sep 5, 2026

ReferenceCybersecurityNetworking

Industrial Firewalls

Firewalls built for control networks: how they differ from office firewalls, where they belong in a utility network, transparent versus routed modes, Modbus and DNP3 awareness, logging, and the ruggedized units that protect one controller or a remote site.

9 min readUpdated Sep 5, 2026

ReferenceCybersecurityNetworking

Firewall Rule Design

Writing the rule set for a control network boundary: default deny, one rule per conduit with its reason, hosts not subnets, protocol and port and function, direction and initiator, logging on every rule, and the review that removes forgotten rules.

9 min readUpdated Sep 5, 2026

ReferenceCybersecurityPLC

Controller Mode Switch and Keyswitch

The physical switch on the front of a controller: what RUN, REMOTE, and PROGRAM mean, why most controllers are left in REMOTE and why that matters, a policy for a utility, how mode is monitored and alarmed, and what to do on platforms with no keyswitch.

8 min readUpdated Sep 5, 2026

ReferenceCybersecurityPLC

Controller Program Integrity

Knowing that the program in the controller is the one that was approved: checksums and change counters, the scheduled compare against the trusted backup, signed and protected projects, what an unexplained difference means, and making the check routine.

8 min readUpdated Sep 5, 2026

ReferenceCybersecuritySCADA

Server Hardening

Reducing what an attacker can do with a SCADA server: a baseline from the vendor guide and a benchmark, unused services removed, the host firewall on, application allowlisting, controlled media, separate administrator accounts, and logs sent off the box.

10 min readUpdated Sep 5, 2026

ReferenceCybersecuritySCADA

User Accounts and Roles

Who can do what on the SCADA and how it is enforced: roles from view-only to administrator and their permission matrix, individual accounts including the operator console, service and vendor accounts, same-day offboarding, and the quarterly review.

9 min readUpdated Sep 5, 2026

ReferenceCybersecuritySCADA

Patch Management

Applying updates to SCADA servers and clients without breaking the plant: vendor qualification, a monthly cycle with a test system, priority from the exposed edge inward, backups and rollback, emergency patches, and handling software that cannot be patched.

9 min readUpdated Sep 5, 2026

ReferenceCybersecuritySCADA

Historian Security

The historian is the most connected server in a control system and the most exposed: giving the office, reports, and the cloud the data they need without a path to the plant, with a collector in the control zone, a replica in the DMZ, and one-way flow.

9 min readUpdated Sep 5, 2026

ReferenceCybersecuritySCADA

Third-Party Software

Everything on a control system machine that is not the SCADA: drivers, databases, runtimes, reporting tools, agents, remote support utilities. Why each is an attack surface, the inventory and approved list, rules for installs, and removing what is unused.

8 min readUpdated Sep 5, 2026

ReferenceCybersecuritySCADA

Shared Account Problems

Why the shared operator login, the vendor account everyone knows, and the single PLC password are the weakest point in most utilities: no accountability, no offboarding, no detection. Containing what cannot be avoided and migrating the rest.

8 min readUpdated Sep 5, 2026

ReferenceCybersecurityStandards

Password Policy for OT

A password policy that fits a control system rather than an office: length over complexity, rotation on events, screening against breached lists, multi-factor authentication, no lockouts that take control from an operator, and unique vaulted device passwords.

8 min readUpdated Sep 5, 2026

ReferenceCybersecurityDocumentation

Credential Storage

Where the passwords and keys of a control system are kept: a vault with individual access and a log, break-glass copies in a safe, platform credential stores for service accounts, and the places they must not be, from spreadsheets to project files.

8 min readUpdated Sep 5, 2026

ReferenceCybersecurityStandards

Security Program Basics

What a control system security program is for a utility that has never had one: a named owner, an inventory, a risk assessment, a few policies, baseline controls, training, vendor rules, an exercised incident plan, and a first-year plan for a small staff.

10 min readUpdated Sep 5, 2026

ReferenceCybersecuritySCADA

SCADA Backups

What a SCADA backup must contain to bring a system back: the project export, an image of each server, the databases, historian archives, licenses, certificates, scripts, and network device configurations, with frequency, retention, and the restore procedure.

9 min readUpdated Sep 5, 2026

ReferenceCybersecuritySCADA

Backup Testing

Why backups that have never been restored fail when needed, and how to find out: spot restores, full restores of a server to an isolated machine, controller program restores to a spare, archive reads, timing each one, and the findings and record that follow.

8 min readUpdated Sep 5, 2026

ReferenceCybersecuritySCADA

Offline Copies

The backup copy that survives ransomware: why anything reachable over the network will be encrypted too, what offline and immutable mean, options from rotated drives to immutable storage, what goes in the offline set, and the restore test that uses it.

8 min readUpdated Sep 5, 2026

ReferenceCybersecurityDocumentation

Configuration Baselines

A known-good record of how every part of the control system is configured, captured at acceptance and kept current through change management: what to baseline, how to capture and store it, how to compare on a schedule, and what an unexplained difference means.

8 min readUpdated Sep 5, 2026

ReferenceCybersecurityPLC

Program Change Detection

Knowing when a controller program changed and whether it was supposed to: change counters and signatures the SCADA can alarm on, scheduled compares, audit logs, mode and network monitoring, what each catches, and what to do when one fires.

9 min readUpdated Sep 5, 2026

ReferenceCybersecurityDocumentation

Change Management for OT

A change process sized for a utility control system: what counts as a change, the request with risk and rollback, owner approval, the window, backup before and verification after, the baseline update, the emergency path, and the record.

9 min readUpdated Sep 5, 2026

ReferenceCybersecurityNetworking

Isolating a Compromised System

Cutting a compromised machine, segment, or site off from the control system without stopping the process: who may decide, isolation points planned in advance, disconnecting the network rather than the power, running on manual control, and preserving evidence.

9 min readUpdated Sep 5, 2026

ReferenceCybersecurityWater

Manual Operation Procedures

Written procedures for running the plant and the remote sites without the SCADA or the controllers: what to read and set by hand, how often to check, what to log, chemical dosing from a flow reading, when to stop, staffing, and the drill that proves them.

9 min readUpdated Sep 5, 2026

ReferenceCybersecuritySCADA

Recovery and Restoration

Bringing a control system back after a compromise without reintroducing it: controllers verified against baselines first, servers rebuilt from clean media and project exports, every credential changed, hardening, staged reconnection, and end-to-end tests.

9 min readUpdated Sep 5, 2026

ReferenceCybersecurityStandards

Reporting Requirements

Who a water or wastewater utility must tell about a cyber incident, how fast, and what to say: the federal critical infrastructure reporting rule, state laws, the drinking water regulator, public notification, law enforcement, the sector center, and insurers.

9 min readUpdated Sep 5, 2026

ReferenceCybersecurityDocumentation

Building an OT Asset Inventory

The list of everything in the control system with a network interface or a program, and how to build one that is right: what counts, the fields to record, the site walk, the switch tables and passive listening that find the rest, and keeping it current.

9 min readUpdated Sep 5, 2026

ReferenceCybersecurityNetworking

Passive Discovery

Finding out what is on a control network by listening rather than probing: why active scans are risky around older controllers, how a mirror port feeds a sensor, what the traffic reveals, the blind spots, and how the sensor becomes continuous monitoring.

8 min readUpdated Sep 5, 2026

ReferenceCybersecurityDocumentation

Documenting Firmware Versions

Why the firmware version of every controller, module, drive, switch, radio, and instrument belongs in the inventory with the date it was read: advisories are issued by version. Where to read each one, the several versions one controller has, and the cadence.

8 min readUpdated Sep 5, 2026

ReferenceCybersecurityStandards

Advisories and Alerts

Where a utility learns its equipment has a known vulnerability and what to do with the news: the government and vendor advisory feeds, the sector center, the exploited catalog, subscribing by product, a weekly triage on exposure and consequence, and records.

8 min readUpdated Sep 5, 2026

ReferenceCybersecurityStandards

Risk-Based Patching

Deciding what to patch first when everything cannot be patched at once: priority from exposure, exploitation, and consequence rather than scores, tiers with timelines, different rules for servers, network gear, and controllers, and the written accept decision.

8 min readUpdated Sep 5, 2026

ReferenceCybersecurityNetworking

Compensating Controls

What to do about a vulnerability that cannot be patched now or ever: restricting who can reach it, disabling the service, blocking dangerous protocol functions, allowlisting, monitoring, physical and procedural controls, matched to the attack path.

8 min readUpdated Sep 5, 2026

ReferenceCybersecurityWater

AWIA Requirements

What the 2018 water infrastructure act requires of community water systems: a risk and resilience assessment and an emergency response plan, certified on a schedule by size and repeated every five years, with cybersecurity named in both, and who is covered.

9 min readUpdated Sep 5, 2026

ReferenceCybersecurityWater

EPA Guidance

What the federal environmental agency provides to water and wastewater utilities on cybersecurity and what it expects: the free assessment, the checklist aligned with federal goals, joint incident response guidance, the enforcement position, and how to use it.

8 min readUpdated Sep 5, 2026

ReferenceCybersecurityWater

CISA Resources

What the federal cybersecurity agency provides to utilities without charge: the performance goals, regional advisors, external vulnerability scanning, control system advisories, the exploited catalog, a self-assessment tool, exercises, and incident reporting.

8 min readUpdated Sep 5, 2026

ReferenceCybersecurityNetworking

VLAN Segmentation

Using VLANs to build the zones of a control network on shared switches: what a VLAN separates and what it does not, the zone-to-VLAN mapping, trunks and the native VLAN, routing only through a firewall, and where separate hardware begins.

9 min readUpdated Sep 5, 2026

ReferenceCybersecurityNetworking

Data Diodes

Hardware that lets data flow one way only, from the control network outward, with no physical return path: what a data diode and a unidirectional gateway are, where they belong, what they can and cannot carry, and when a firewall is enough instead.

8 min readUpdated Sep 5, 2026

ReferenceCybersecurityTelemetry

Segmenting a Remote Site

A lift station, a well, or a tank site as its own zone: the site firewall and what it permits, the modem as transport with no public address, cameras and extras off the control segment, engineering access through the plant, and local control without the link.

9 min readUpdated Sep 5, 2026

ReferenceCybersecurityNetworking

VPN Design

How a VPN fits remote access for a control system: it terminates in the DMZ and lands on a jump host, never the control network; site-to-site tunnels carry telemetry; user tunnels require multi-factor and individual accounts; the concentrator is patched fast.

9 min readUpdated Sep 5, 2026

ReferenceCybersecurityStandards

Multi-Factor Authentication

Requiring a second proof of identity beyond a password, where it matters most in a control system and how to do it without locking an operator out: the factor types, where it is mandatory, where it does not fit, enrollment and recovery, and vendor accounts.

8 min readUpdated Sep 5, 2026

ReferenceCybersecurityDocumentation

Session Logging

Recording every remote session into the control system: who connected, from where, when, to what, and what they did, from the VPN log through jump host session recording to the SCADA audit trail and controller change log, stored off the systems and reviewed.

8 min readUpdated Sep 5, 2026

ReferenceCybersecurityNetworking

Deep Packet Inspection

What a firewall can do when it understands the control protocols: allowing reads and blocking writes, permitting programming only from one workstation in a window, rejecting malformed messages, and alerting on function codes that should never appear.

8 min readUpdated Sep 5, 2026

ReferenceCybersecurityNetworking

Firewall Logging and Review

Making the firewall log useful: logging on every rule including sensitive permits, sending logs to a collector off the firewall, what denials and unexpected permits mean, a weekly review a small utility can sustain, and the alerts worth waking someone for.

8 min readUpdated Sep 5, 2026

ReferenceCybersecurityPLC

Firmware Management

Updating the firmware of controllers, modules, drives, HMIs, switches, and radios without breaking the plant: why firmware lags and why it still matters, tracking versions, deciding what to update and when, and the update as a planned outage with a rollback.

9 min readUpdated Sep 5, 2026

ReferenceCybersecurityPLC

Disabling Unused Services

Every service a device runs is a way in, and most ship with more running than the plant uses: web servers, file transfer, shells, discovery, management protocols, unused ports. Finding what is listening, deciding what the plant needs, and turning off the rest.

8 min readUpdated Sep 5, 2026

How-ToNetworkingEthernet

How to Configure VLANs on a Control Network

Turn a zone plan into switch configuration: a VLAN per zone with its own subnet, access ports for devices, tagged trunks between switches, a native VLAN that carries nothing, a separate management VLAN, and routing between VLANs only through the firewall.

10 min readUpdated Sep 5, 2026

How-ToHow-ToCybersecurity

How to Configure Remote Access

Give operators and engineers a way into the SCADA system from outside that does not give it to anyone else: a virtual private network with multi-factor authentication terminating in a demilitarized zone, and a test that proves the path works and that the.

8 min readUpdated Sep 5, 2026

TroubleshootingTroubleshootingTelemetry

Cellular Modem Will Not Register

A modem that never attaches to the network: a module not activated, provisioned, or suspended; unsupported bands or a network shutdown; no antenna or coverage; a wrong access point name; or a reset modem. Reading the registration state and asking the carrier.

8 min readUpdated Sep 5, 2026

TroubleshootingTroubleshootingTelemetry

Frequent Reconnects

A cellular site that connects, drops, and reconnects: a weak signal at the cell edge, tower handoffs, idle session teardown, a NAT timeout that needs a keepalive, a firmware fault, a sagging supply, or an antenna problem. Settings that keep sessions up.

8 min readUpdated Sep 5, 2026

TroubleshootingTroubleshootingTelemetry

VPN Tunnel Drops

The modem is up and the tunnel keeps dropping: a changing cellular address, keepalive longer than the carrier timeout, mismatched rekey lifetimes, an oversized MTU, a modem reconnecting under the tunnel, a full concentrator, or a clock or certificate fault.

9 min readUpdated Sep 5, 2026

TroubleshootingTroubleshootingNetworking

Cannot Ping Across VLANs

Two devices that work on their own networks but cannot reach each other across a VLAN boundary: no route, a wrong or missing gateway, a mask that puts the target on the wrong side, a trunk missing the VLAN, or a firewall rule. Testing each in order.

8 min readUpdated Sep 5, 2026

TroubleshootingTroubleshootingSCADA

Client Cannot Connect

A workstation, web, or mobile client that cannot reach the SCADA server: the service down, a firewall path closed, a license or session limit, a certificate or name failure, a version mismatch after an update, or expired credentials. Testing each layer.

8 min readUpdated Sep 5, 2026

ReferenceStandardsPLC

IEC Standards for Controls

The International Electrotechnical Commission standards a controls practitioner meets: IEC 61131 for programmable controllers and their languages, IEC 62443 for security, IEC 61511 for safety instrumented systems, IEC 60529 ingress protection ratings, the telemetry protocols, and how IEC and North American standards fit together.

8 min readUpdated Sep 5, 2026

ReferenceDocumentationNetworking

Network Drawings

The two drawings every control network needs: a logical drawing of zones, subnets, VLANs, firewalls, and conduits, and a physical drawing of switches, ports, cables, fiber, radios, and sites. What each shows and why they are sensitive.

9 min readUpdated Sep 5, 2026

ReferenceDocumentationNetworking

Network Schedules

The tables behind the network drawings: the address schedule of every device, the switch port schedule of every port, the VLAN table, and the conduit list of what the firewalls permit. How they are built, kept as the single source of truth, and protected.

8 min readUpdated Sep 5, 2026

ReferenceStandardsCybersecurity

NIST Publications for Control Systems

The National Institute of Standards and Technology documents a control engineer will meet: the Cybersecurity Framework, the operational technology security guide, the control catalog, the digital identity guideline, and the incident handling guide.

9 min readUpdated Sep 5, 2026

ReferenceStandardsCybersecurity

CISA Guidance as a Reference

How the federal cybersecurity agency publications serve as reference standards for a utility: the performance goals as a baseline for policy and procurement, the water sector goals, secure-by-design principles for vendors, and the advisories.

8 min readUpdated Sep 5, 2026

ReferenceStandardsWater

AWWA Standards and Manuals

What the American Water Works Association publishes that a control engineer uses: the instrumentation and control manual, the risk and resilience standard behind the act assessments, the security and emergency standards, and the cybersecurity tool.

8 min readUpdated Sep 5, 2026

ArticleSCADADesign

What a Small Utility Should Ask Before Buying SCADA

A utility with a plant, a few dozen remote sites, and two operators on call is buying a system it will live with for twenty years. The questions that decide whether it works out, and they are not about features: licensing, staffing, and the exit.

9 min readUpdated Sep 5, 2026

ArticleCybersecurityTelemetry

The Cellular Router Is the Front Door

The most common way into a small utility control system is not a sophisticated attack on the plant firewall. It is a cellular router at a lift station with a public address and the password it shipped with. How these get installed, and the short list of.

8 min readUpdated Sep 5, 2026

ArticlePLCDocumentation

The Backup That Would Not Restore

A controller failed on a Friday, the spare was on the shelf, and the saved program would not go in. What a PLC backup has to contain to actually put a system back, why the program file alone is not enough, and how a small utility keeps backups that work.

9 min readUpdated Sep 5, 2026

ArticleNetworkingEthernet

One Flat Network Is One Big Fault Domain

A looped patch cable in an office closet took down every PLC at the plant, because the office and the plant were one network. Why a flat network makes every fault a plant-wide fault, and how to get there one switch at a time.

9 min readUpdated Sep 5, 2026

ArticleCybersecurityNetworking

The Vendor Laptop Is on Your Network Now

Every service call ends with a laptop plugged into the control network, and most utilities have no rule about it. What can go wrong when a vendor connects, and how to have the conversation without losing the vendor.

9 min readUpdated Sep 5, 2026

ReferenceCybersecurityWater

Water and Wastewater Utility Threat Landscape

What has actually happened at water utilities, what those incidents had in common, and the small number of controls that would have prevented most of them.

8 min readUpdated Aug 28, 2026

ReferenceCybersecurity

OT Security vs IT Security

Why the familiar security priorities invert on a plant floor, and what that changes about patching, scanning, authentication, and incident response.

8 min readUpdated Aug 26, 2026

ReferenceCybersecurityFundamentals

The Purdue Model

The reference architecture most segmentation designs still start from: what each level contains, where the DMZ goes, and how it maps to a water utility.

8 min readUpdated Aug 20, 2026

Direct contact

Have a controls question?

Reach Eric Sullivan directly about anything on this site, a controls or automation topic, or one of his personal projects.

Content on CurryControls.com is general technical reference information provided for educational and reference purposes only. It is not engineering advice for a specific installation. All information must be independently verified against current codes, standards, manufacturer documentation, project requirements, and qualified professional judgment before it is relied upon or applied.