Industrial cybersecurity: IEC 62443, the Purdue model, firewalls, DMZ, zero trust, and OT threats. 27 terms in this topic - each defined in plain English on its own page.
Industrial cybersecurity: IEC 62443, the Purdue model, firewalls, DMZ, zero trust, and OT threats.
An SAv5 variant that bundles the HMAC into the request to skip the challenge round-trip, kept safe by a sequence number.
Read → GlossaryThe documented known-good hardened settings a device is measured against, and how drift is caught.
Read → GlossaryThe layered strategy of stacking independent controls so one failure never exposes the industrial process.
Read → GlossaryConfiguring OT firewalls to block everything and permit only named, justified flows so segmentation actually holds.
Read → GlossaryA tamper-resistant appliance that generates and stores CA and signing keys so they never exist in software.
Read → GlossaryGPS-driven optimization that assigns mining trucks to shovels and dumps to cut queue and idle time.
Read → GlossaryLinking a phishing hit in IT with new OT traffic to reconstruct the lateral-movement timeline a silo would miss.
Read → GlossaryWhy a second factor matters most on OT remote-access paths, and the hurdles of shared consoles and offline sites.
Read → GlossaryFine-grained per-device isolation that stops east-west lateral movement between assets inside a zone.
Read → GlossaryWhy carrier-grade NAT hides remote sites and how telemetry reaches devices behind it - explained.
Read → GlossaryThe controlled communication pathway between zones, the security controls that sit on it, and how to document its flows.
Read → GlossaryDividing an OT network into isolated segments so a problem in one part cannot spread across the whole plant.
Read → GlossaryReceive-only sensing that fingerprints assets and catches intrusions without sending a packet that could crash a PLC.
Read → GlossaryWhy control systems cannot follow IT's monthly cadence, and how validation and downtime windows shape patching.
Read → GlossaryHow OT mirrors cumulative rollups, tests them on a staging replica, and follows approved-patch lists before the plant.
Read → GlossaryA scheduled, approved slot to update a live plant, aligned with production and bracketed by backup and verification.
Read → GlossaryPhysical separation uses its own switches and cabling; logical uses VLANs and firewall zones. Compare and layer them.
Read → GlossaryThe layered reference architecture that segments industrial networks from field devices to enterprise IT.
Read → GlossaryThe approved secure configuration a device must match, derived from vendor and benchmark guidance.
Read → GlossaryThe SL 1-4 rating scale and how target, achieved, and capability levels drive per-zone controls.
Read → GlossaryA named bundle of signing, encryption, and key-exchange algorithms - current ones vs deprecated SHA-1-based policies.
Read → GlossarySign gives integrity and authenticity in the clear; SignAndEncrypt adds confidentiality - a separate choice from policy.
Read → GlossarySending only SCADA host traffic through the tunnel while other traffic breaks out locally, saving cellular bandwidth.
Read → GlossaryA protocol-replicating one-way device that exports SCADA data to IT while blocking any return path.
Read → GlossaryShielding an unpatchable device at the network layer so a known exploit is blocked without touching it.
Read → GlossaryThe encrypted, encapsulated connection that secures remote telemetry across public networks - IPsec and outbound designs.
Read → GlossaryThe IEC 62443 model of grouping OT assets into security zones and controlling traffic between them through conduits.
Read →Merobix is cloud SCADA for oil & gas - it reads the instruments and protocols defined here into one dashboard.
We respond within 1 business day.