Modern industrial efficiency requires the convergence of information technology (IT) and operational technology (OT). However, integrating IoT solutions into legacy SCADA environments poses challenges for cybersecurity and business continuity due to fundamental differences between these domains.
Conflicting priorities and architectural features
According to the NIST SP 800-82 guideline, system availability in operational technology is more critical than data confidentiality. Any industrial controller downtime due to updates or network failures can disrupt the manufacturing process. Since legacy hardware has limited resources, the security of such systems must be addressed at the architectural level rather than solely through patching.
An Edge-to-Cloud architecture is recommended for reliable integration. The local level (Edge) handles critical real-time operations, while the cloud is used for long-term data storage and analytics. This ensures production autonomy even in the event of a connectivity loss.
Standardization and security with OPC UA and ISA/IEC 62443
To overcome the incompatibility of proprietary protocols, the platform-independent OPC UA architecture is used. It normalizes data from legacy sensors before transmitting it to SCADA or MES systems, creating a universal bridge to cloud platforms.
Control loop protection is achieved through strict network segmentation in compliance with the ISA/IEC 62443 standard. This completely isolates OT control traffic from general corporate IT networks, preventing direct external access to industrial controllers.
How this affects the sector
Successful IT and OT integration enables businesses to unlock advanced cloud analytics and optimize production efficiency. However, neglecting architectural security during this convergence risks exposing legacy industrial control systems to external cyber threats, which can result in costly operational downtime and compromised physical safety.
Recommendations
To build a reliable and secure telemetry layer, organizations should take the following practical steps:
- Asset auditing and identifying legacy hardware limitations.
- Data normalization via edge nodes and the OPC UA protocol.
- Strict network segmentation in compliance with ISA/IEC 62443.
- Lifecycle management and monitoring of the IoT device fleet.
Implementing such scenarios requires specialized expertise. In particular, Softengi (a member of the Intecracy Group consortium), certified under the ISO/IEC 42001:2023 standard, helps design reliable telemetry layers to securely connect industrial data with cloud analytics.
Prepared by a Software Ukraine member. Original publication.