For the past decade, industrial control system professionals have wanted to believe that ‘air gaps’ truly exist between their systems and the rest of the world. They have also hoped that ‘security by obscurity’ would keep them safe.

Those days are over. Recent security incidents such as the game-changing Stuxnet worm are a wakeup call for the industrial automation industry. While the risk of cyber attacks and malware are no longer in doubt, the question remains, “Exactly how can an engineer reliably secure his or her control system?”

OPC is one of the most widely used industrial integration technologies for SCADA and ICS systems so it is vital that controls and network professionals understand how to deploy it securely. A new White Paper discusses how different defensive layers can be used to provide high security when using OPC technology.

An effective way to manage the conflict between the demands of efficient access and the demands of effective security is to minimise the variety of interfaces and protocols operating between the control system and external networks. Having one approved connectivity solution serving multiple corporate requirements not only reduces administration costs, but also reduces the opportunities open to an attacker or worm. This is known as ‘reducing the attack surface’ of a system.

OPC is said to be one of the easiest and most widespread standards to address the demands of universal data access in the industrial automation world. By layering defenses that are OPC-aware, high security solutions can be created that meet both the security and access expectations of a company, all without administrative overload on the network or controls team. To read the white paper in full, visit www.tofinosecurity.com/effective-OPC-solutions