Securing SCADA means protecting central systems, remote telemetry units and the communications paths between them

There has been a sharp rise in cyberattacks targeting energy, transport and water infrastructure since 2024, according to Industrial Cyber. Supervisory Control and Data Acquisition (SCADA) technologies form the backbone of these critical systems, making remote telemetry units (RTUs) essential to both operational performance and cybersecurity. Here, Julian Booth, SCADA service delivery manager at Ovarro, the remote telemetry specialist, explains why water and gas SCADA systems are attractive targets for cyberattackers, and why securing the edge is now central to protecting critical infrastructure.

In water and gas networks, SCADA systems allow operators to monitor assets, track alarms, collect data and support decisions across large, dispersed sites. However, SCADA is not just one central software platform. It also depends on field devices that connect remote assets to the central system.

RTUs sit at this critical edge layer, collecting data from remote sites and communicating it back to central SCADA systems. If they are not properly secured, they can become weak points in an otherwise protected architecture.

The consequences can extend far beyond data loss. In 2021, the BBC reported that a hacker accessed the water system of Oldsmar, Florida, and attempted to increase sodium hydroxide levels in the water treatment process. The incident was spotted and reversed by an operator, but it showed how cyber compromise can move quickly from digital access to physical process manipulation.

In water and gas networks, the rise in cyberattacks reported by Industrial Cyber could mean attempted interference with pumping stations, valves, pressure management systems or dosing processes. Even where built-in safeguards prevent a dangerous outcome, the operational, reputational and regulatory impact of an incident can be significant.

A wider attack surface

Power grids are often seen as the highest-profile cyber targets in critical infrastructure. However, water and gas networks present a different kind of risk.

These systems are highly distributed. They often include remote, unmanned assets, legacy equipment, communications links and field devices spread across large operating areas. Many assets are difficult to access, expected to remain in service for many years and connected back to central systems through telemetry infrastructure.

The attack surface is therefore not limited to the control room. It extends across the network.

For many years, cybersecurity activity in SCADA environments focused heavily on central systems. That remains vital. Servers, software platforms, user access and control-room infrastructure all need to be protected. However, operators are now paying closer attention to the wider telemetry chain.

A practical approach to securing distributed SCADA networks must cover three areas: the central SCADA system, the RTU devices themselves and the communications paths between them. This means hardening central systems and servers, hardening RTUs at the edge and protecting the routes that connect remote sites to the wider operational environment.

OVA62620 20Image20two

Ovarro’s TBox LT2 remote telemetry unit helps utilities connect remote assets to central SCADA systems, supporting secure data access, real-time monitoring and resilient telemetry infrastructure

Moving from reactive to proactive security

A common weakness in OT environments is legacy infrastructure. Many organisations have historically been willing to run older systems for long periods, sometimes using operating systems that are no longer supported by suppliers.

This creates risk. As new vulnerabilities are discovered, patches may not be available for unsupported systems. Even where patches do exist, operators must carefully manage how and when updates are deployed, because SCADA and telemetry systemsoften support essential live operations.

A more proactive approach starts with visibility. Operators must understand where assets are, what software and firmware they run on, how they communicate and which vulnerabilities present the greatest risk.

Vulnerability scanning, patching and pre-production environments can all help. Pre-production environments are particularly important because they allow teams to test updates, patches and configuration changes before deploying them into live operational environments.

This is where adaptive security becomes important. Rather than relying on static controls, operators need systems and processes that can respond as risks change.

Securing the edge

Ovarro’s work with Greater Western Water in Victoria, Australia, shows this resilience objective in practice. The utility needed to replace legacy RTUs at more than 100 critical sites, selecting Ovarro’s TBox LT2 for its protocol compliance, low power operation and easy installation.

The TBox LT2 provided real-time data access, robust cybersecurity and seamless integration with existing systems. Integration with existing SCADA templates required no changes, helping minimise disruption while improving real-time monitoring across operational infrastructure.

This kind of project demonstrates why RTUs matter to cyber resilience. They are not simply data collection devices. They are part of the secure connection that connects critical assets to central decision-making.

To find out more about Ovarro’s SCADA telemetry solutions and RTUs, visit its website.