SCADA Security • The Complete Directory

SCADA Security Hub:
Every Guide in One Place (2026)

Merobix Engineering • • 12 min read

Security is now the question that decides SCADA purchases. The systems that monitor water plants, pipelines, and production lines are targets, insurers and regulators know it, and a buying decision made on features alone can leave you owning a risk you never priced. This hub organizes all sixty of our SCADA and OT security guides into six groups - buyer's guides, certification explainers, industry compliance, security practice, protocol hardening, and operations governance - each with a one-line summary of what it answers, so you can go straight to the guide that matches the question in front of you.

Back to Blog
60Security Guides in This Hub
6Topic Areas, Buyer to Auditor
0Inbound Ports on a Merobix Gateway

Why SCADA Security Decides the Purchase

SCADA security is the practice of protecting supervisory control and data acquisition systems - the software, servers, gateways, and field devices that monitor and control industrial processes - from unauthorized access, data tampering, and disruption, with availability and physical safety as the first priorities. It now sits at the center of every serious platform evaluation.

For most of SCADA's history, security was a paragraph in the RFP. That era is over, for three reasons that every buyer now feels directly. First, the threat is real and documented: publicly reported incidents from the Ukraine grid attacks to Colonial Pipeline and the Oldsmar water intrusion have shown that industrial control systems are attacked, that attacks reach physical operations, and that the entry point is usually mundane - a credential, a VPN, an exposed remote-access service. Second, the compliance floor keeps rising: TSA security directives for pipelines, AWIA for water utilities, NERC CIP for power, 21 CFR Part 11 for pharma, and cyber insurance questionnaires for everyone else have turned security posture into a condition of operating, not a preference. Third, the deployment model changed: cloud SCADA moves part of the security burden onto the vendor, which is only good news if you can verify what the vendor actually does.

That verification is what this hub is for. The guides below teach you what tenant isolation, signed telemetry, and immutable audit trails mean; how SOC 2, ISO 27001, and IEC 62443 actually work and how much each costs to earn; what your specific industry's regulators demand; and how practitioners run patching, access reviews, and incident response in environments where availability and safety come first. The substance is deliberately vendor-neutral - every checklist and question bank works against any platform you evaluate. Where Merobix appears, we state our own controls plainly and you can inspect the full picture on the Merobix security architecture page. If you want a single narrative walkthrough before diving into the directory, start with our foundational guide to securing a SCADA and OT network, then come back here and go deep wherever your risk lives.

Cloud SCADA Security Buyer's Guides

Use these when you are evaluating platforms. Each one takes a single control family - identity, isolation, telemetry integrity, encryption, APIs, recovery - and turns it into questions you can put to a vendor and evidence you should expect back. Together they amount to a complete security due-diligence program for a cloud SCADA purchase.

Cloud SCADA Security Checklist: 12 Controls to Demand (2026)

The pillar of the whole series: twelve non-negotiable control families - identity, isolation, telemetry integrity, control safeguards, audit, recovery, and more - with the evidence to demand for each. If you read one guide before an RFP, read this one.

50 Security Questions to Ask Your Cloud SCADA Vendor

A ready-to-use question bank organized by category, with what a good answer looks like and the red flags that should end the conversation. Bring it to every vendor call.

Multi-Tenant Cloud SCADA: How to Verify Tenant Isolation

How shared platforms keep customers apart - row-level security, signed request context, cross-tenant testing - and how to verify isolation instead of taking the vendor's word for it.

SCADA Authentication: MFA, Passkeys & Session Security Guide

TOTP versus FIDO2 passkeys, session expiry and revocation, brute-force lockout, and step-up authentication for high-risk actions - the identity layer done properly.

SCADA Audit Trails: Immutable Logs & Operational Evidence

Why tamper-evident, chained audit records matter, what auditors actually ask to see, and how operational evidence holds up in an investigation.

Telemetry Integrity in Cloud SCADA: Signed Data & Replay Protection

Signed telemetry envelopes, payload digests, sequence numbers, and replay detection - and why unsigned sensor data is a decision-integrity risk, not just a security one.

Remote Control Security in SCADA: Safe Setpoint Writes

Writable-tag allowlists, setpoint bounds, idempotent commands, read-back verification, and management-of-change gates - the safeguards that make remote writes defensible.

SCADA Encryption Explained: In Transit, At Rest & In Search

TLS in transit, field-level encryption at rest, blind indexes for searching encrypted data, and modern password hashing - what each layer protects and what it does not.

Edge Gateway Security: Device Identity & Signed Updates

Device registration, per-device credentials, signed update artifacts, store-and-forward buffering, and why outbound-only gateways remove the inbound attack surface entirely.

SCADA API Security: Keys, Rate Limits & Webhook Hardening

Scoped API keys with lifecycle and revocation, rate limits, SSRF defenses, and pinned-IP webhook delivery - the integration surface most buyers forget to evaluate.

SCADA Threat Detection: SIEM Integration & Security Alerting

Runtime threat detection, durable notification delivery with retry and dead-letter handling, and how to get SCADA security events into the SIEM your team already watches.

Software Supply Chain Security for SCADA Buyers

Signed builds, SBOMs, dependency scanning, and release assurance - the SolarWinds lesson applied to the software that runs your operations.

SCADA Backup & Disaster Recovery: Ransomware Resilience

Backup validation, restore drills, RPO and RTO targets, and retention - the difference between a ransomware incident and a ransomware disaster.

Zero Trust for SCADA: A Practical Implementation Guide

Identity-first access, least privilege, and microsegmentation mapped against the Purdue model - a zero-trust path that works with industrial constraints rather than against them.

Verifying SCADA Vendor Security: Pen Tests & Continuous Validation

How to read a penetration test report, what scope actually means, and the signals that separate vendors who validate continuously from vendors who bought a logo.

OT Incident Response Plan for Cloud SCADA Operations

Incident response playbooks adapted for OT: roles, tabletop exercises, evidence handling, and where the vendor's responsibilities end and yours begin.

Cloud vs On-Premise SCADA Security: An Honest Comparison

The layer-by-layer comparison: responsibility split, certification differences, patching velocity, exposure trade-offs, staffing reality, and when each model genuinely wins.

Certifications & Standards Explained

SOC 2, ISO 27001, IEC 62443, NIST 800-82, API 1164, TSA directives - the alphabet soup that dominates security conversations, decoded. These explainers cover what each framework actually attests, how a vendor earns it, realistic cost and timeline ranges, and the scope games to watch for when someone hands you a certificate.

SOC 2 vs ISO 27001 vs IEC 62443: SCADA Certifications Explained

The pillar explainer: what each framework covers, how a vendor earns each one, realistic timelines and cost ranges, and what "readiness" versus "certified" actually means in practice.

IEC 62443 Certification: Levels, Process, Cost & Timeline

The industrial standard in depth: the parts of the standard, security levels SL1 through SL4, ISASecure-style certification schemes, and honest cost and timeline ranges.

What Is SOC 2 Certification? Guide for Industrial Buyers

SOC 2 demystified: why it is an attestation rather than a certification, Type I versus Type II, the Trust Services Criteria, and how to actually read the report a vendor hands you.

What Is ISO 27001 Certification? Process, Cost & Timeline

The ISMS concept, the 2022 Annex A controls, stage 1 and stage 2 audits, surveillance cycles - and the certificate-scope gaming every buyer should check for.

NIST SP 800-82: The ICS Security Playbook Explained

NIST's control-system security playbook: what revision 3 covers, how it maps to IEC 62443 and the CSF, and how to use it when evaluating vendors.

TSA Pipeline Security Directives: SCADA Compliance Guide

The pipeline directives from 2021 to today: who is covered, what cybersecurity implementation plans require, and the practical steps to compliance.

API 1164 Third Edition: Pipeline SCADA Security Explained

The pipeline industry's own SCADA security standard: its scope, the profile-based approach, its relationship to IEC 62443, and the vendor questions it implies.

On-Premise SCADA Certifications: What You Need to Run It Yourself

When you host the platform, the compliance burden shifts to you: which certifications the software vendor should hold versus which programs the operator must build, plus a hardening checklist.

Industry Compliance Guides

Every regulated industry stacks its own rules on top of the general security frameworks. These guides walk through the specific regulatory drivers for seven sectors - what applies, why, the process to comply, and what to look for in a SCADA vendor serving that industry - so you can hand the right one to your compliance lead and skip the ones that do not apply.

Oil & Gas SCADA Compliance: API 1164, TSA & IEC 62443

API 1164, TSA security directives, NIST 800-82, and IEC 62443 mapped to upstream, midstream, and downstream operations - with the audit process explained step by step.

Pharma SCADA Compliance: 21 CFR Part 11, GAMP 5 & Annex 11

Part 11 electronic records and signatures, ALCOA+ data integrity, GAMP 5 validation, and what compliant SCADA actually looks like inside a regulated plant.

Water Utility SCADA Compliance: AWIA, EPA & IEC 62443

AWIA risk assessments and emergency response plans, EPA cybersecurity guidance, state rules - and the small-utility reality of meeting them with a three-person team.

Power & Utility SCADA Compliance: NERC CIP Explained

NERC CIP from CIP-002 to CIP-014: BES cyber system categorization, audits and fines, and what actually applies to smaller generators and renewables.

Chemical Plant SCADA Compliance: CFATS, OSHA PSM & IEC 61511

CFATS status, OSHA PSM and management of change, and where safety instrumented systems under IEC 61511 meet cybersecurity under IEC 62443.

Food & Beverage SCADA Compliance: FSMA, HACCP & Part 11

FSMA and food defense, HACCP records, SQF and BRC audit expectations, and electronic records in food production environments.

Manufacturing SCADA Compliance: ISO 27001, NIST CSF & 62443

Choosing between ISO 27001, NIST CSF, and IEC 62443 for discrete manufacturing - plus cyber insurance questionnaires, customer flow-down requirements, and CMMC for defense suppliers.

OT Security Practice & Threats

How security actually gets done - and undone - in industrial environments. This is the practitioner tier: the threats that hit real plants, the defenses that survive contact with an availability-first operation, and the architecture patterns for remote access, segmentation, shared responsibility, and air-gapped sites. Start with the OT-versus-IT piece; it is the mindset the rest builds on.

OT vs IT Security: Why IT Playbooks Break in Industrial Plants

Why availability-first operations break IT security playbooks: patching reality, protocol constraints, and safety consequences - the foundational mindset piece for the whole series.

Ransomware & SCADA: Protecting Industrial Operations

How industrial ransomware actually unfolds, and the segmentation, backup, and response measures that limit the blast radius when it reaches your network.

5 Industrial Cyberattacks and What Buyers Should Learn

Stuxnet, the Ukraine grid attacks, Triton, Colonial Pipeline, and Oldsmar - the public lessons from each, mapped to concrete items on a buyer's checklist.

Vulnerability Management for SCADA: Patching Without Downtime

CVE triage when you cannot reboot the plant: compensating controls, vendor patch cadence, and virtual patching that buys time safely.

Credential Security in SCADA: Passwords, Hashing & Rotation

The shared-login problem, modern password hashing, the truth about rotation policies, and secrets management for the devices themselves.

Phishing & Social Engineering in Industrial Operations

Operator-targeted phishing, vendor impersonation, and MFA fatigue - how social attacks reach the control room, and the training that blunts them.

Insider Threat in Industrial Control Systems

Least privilege, access reviews, clean offboarding, and separation of duties - the controls that address the threat already inside the fence.

Secure Remote Access for SCADA: VPN vs Outbound-Only

The VPN CVE problem, jump hosts, vendor access management, and why outbound-only architectures are steadily displacing inbound remote access.

Cellular SCADA Security: 4G/5G Gateways Done Right

Private APNs, SIM security, and outbound-only connections over cellular - securing the 4G/5G gateways that link remote sites to the platform.

Exposed HMIs: The Internet-Facing SCADA Problem

The Shodan reality of internet-facing HMIs: how exposure happens, why VNC and RDP keep showing up, and the safe remote-access patterns that replace them.

Industrial DMZ & Firewall Design for SCADA

Zones and conduits, firewall rule design, data diodes, and the common DMZ mistakes that quietly undo an otherwise sound segmentation plan.

SCADA Security for Small Operators: No SOC Required

Right-sized security for a three-person team: the handful of controls that matter most, and how managed cloud platforms carry the rest of the load.

The Shared Responsibility Model in Cloud SCADA

Who secures what, layer by layer - and why the dividing line belongs in the contract, with concrete examples for every layer of the stack.

SCADA Data Residency, Retention & Export: Buyer's Guide

Data ownership, retention workflows, export rights, and offboarding portability - the questions that protect you at the end of a vendor relationship, asked at the beginning.

AI & Anomaly Detection in OT Security: Signal vs Hype

What machine learning genuinely catches in telemetry and authentication patterns, what it cannot, and how to see through the marketing around both.

OT Security Self-Audit: A 30-Point Checklist

A 30-point self-assessment across identity, network, device, data, and detection - score your current posture in an afternoon, before an auditor does it for you.

User Access Reviews for SCADA: Joiner, Mover, Leaver

Joiner-mover-leaver discipline for control systems: quarterly reviews, role sprawl, competency checks, and the contractor-access problem.

Air-Gapped SCADA Security: Requirements, Updates & Myths

When regulation genuinely requires an air gap, why the gap alone is not security, and how updates, monitoring, and compliance actually work offline.

Protocol & Device Security

Industrial protocols were designed for reliability on trusted wires, decades before anyone imagined them under attack - and most offer little or no built-in authentication or encryption. These five guides cover what each major protocol can and cannot protect on its own, and the hardening patterns that make each one survivable in a modern network.

MQTT Security for Industrial IoT: TLS, ACLs & Signing

Broker authentication, per-device credentials, topic ACLs, signed message envelopes, and Sparkplug considerations for industrial MQTT deployments.

OPC UA Security: Certificates, Modes & Hardening

SignAndEncrypt modes, the certificate-management pain nobody warns you about, user tokens, and the deployment mistakes that quietly undo OPC UA's security model.

Modbus Security: Risks and Practical Mitigations

A protocol with no authentication and no encryption still runs much of the world's industry - the network isolation, gateway pattern, and detection that make it survivable.

DNP3 Secure Authentication: What It Does and Doesn't Solve

Secure Authentication v5 explained: what it protects, where it applies in water and power, and the practical state of adoption in the field.

PLC Security Hardening: A Practical Checklist

Default passwords, firmware currency, open ports and services, physical access, and program protection - a hardening checklist for the controllers themselves.

Operations & Governance

Security that lives in documents fails; security that lives in daily operations holds. This final group covers the governance layer - alarm delivery you can prove, mobile access you can defend, RFP language that forces honest vendor answers, the budget case that gets the program funded, and a plain-language glossary for everyone else in the room.

Alarm Integrity: Making Sure Critical Alerts Arrive

Delivery assurance for critical alerts: retry and dead-letter handling, provider canaries, and escalation chains that survive a notification-provider outage.

Mobile SCADA Access: Security Without the Risk

Mobile sessions, device loss, push-notification safety, and read-only-by-default patterns for operators who monitor from the road.

Writing Security Requirements Into Your SCADA RFP

Copy-paste-ready security requirement language for your RFP, plus scoring methods and the specific proof to demand alongside each vendor answer.

The Business Case for OT Security: Budget & ROI

Breach cost data with honest ranges, cyber insurance pressure, and how to make the OT security case to a board in the board's own language.

SCADA Security Glossary: 60 Terms Explained

Sixty terms from row-level security to zones and conduits, defined in plain language - the quick reference to hand everyone else on the project team.

Where Merobix Stands on Security

Merobix appears in many of the guides above, so here is our position stated once, plainly. The platform is built security-first: TOTP and FIDO2 passkey MFA with role-based, site-level authorization; PostgreSQL row-level security and signed database request context isolating every tenant; Ed25519-signed telemetry envelopes with sequence numbers, payload digests, and replay detection; explicit writable-tag configuration with setpoint bounds, idempotent commands, and read-back verification for control writes; immutable chained audit records; and runtime threat detection with SIEM, email, SMS, and webhook delivery. The gateway architecture is outbound-only - no inbound firewall ports, no VPN - and the same platform deploys cloud-hosted or fully on-premise, including air-gapped networks. The complete control-by-control breakdown is on the Merobix security architecture page.

On certifications, we hold ourselves to the same honesty these guides demand from every vendor: Merobix runs a SOC 2 readiness program and maps its controls to IEC 62443 - we do not claim certifications we have not earned, and independent penetration testing is part of our ongoing validation program rather than a finished checkbox. No vendor should call any system unhackable, and we never will; what a serious vendor can do is show you the controls, the evidence, and the roadmap, and let you probe all three. If you want to do exactly that against a live system, request a demo and bring the question bank from this hub with you.

The one-question shortcut: ask every vendor to walk you through their most recent security assessment - what was tested, what was found, and what was fixed. Vendors with real programs answer specifically and comfortably, including the uncomfortable parts. Vendors without one change the subject to features. The shape of the answer tells you more than any brochure.

Frequently Asked Questions

What is SCADA security?

SCADA security is the practice of protecting supervisory control and data acquisition systems - the software, servers, gateways, and field devices that monitor and control industrial processes - from unauthorized access, data tampering, and disruption. It spans identity and access control, network architecture, telemetry integrity, encryption, audit trails, and incident response. Unlike IT security, SCADA security must put availability and physical safety first: a control system that trips offline during an attack response can be as dangerous as the attack itself. Standards such as ISA/IEC 62443 and NIST SP 800-82 define the reference practices most operators and auditors work from.

Is cloud SCADA less secure than on-premise SCADA?

Not inherently - the two models distribute risk differently rather than one being categorically safer. A cloud SCADA vendor patches continuously, monitors around the clock, and can afford security engineering most operators cannot staff, but you must verify tenant isolation, encryption, and the vendor's audit evidence. On-premise deployment gives you full physical control and suits air-gapped requirements, but shifts the entire security program - patching, monitoring, backup, hardening - onto your team. The honest comparison is between the vendor's demonstrated security program and your own, layer by layer, which is exactly what the shared-responsibility and cloud-versus-on-premise guides in this hub walk through.

What security certifications should a SCADA vendor have?

Look for evidence across three frameworks: SOC 2 (an attestation of operational controls, reported as Type I or Type II by a licensed CPA firm), ISO 27001 (a certified information security management system), and ISA/IEC 62443 (the industrial-specific standard, with certifiable security levels for products and processes). Just as important is honesty about status: a vendor with a SOC 2 readiness program and controls mapped to IEC 62443 that says so plainly is a better sign than vague certified-sounding language you cannot verify. Always ask for the actual report or certificate, check its scope, and confirm the dates - certifications and attestations cover specific systems over specific periods, not the company forever.

What are the most important cloud SCADA security controls?

Twelve control families cover most of the risk: multi-factor authentication and session management, role-based least-privilege access, tenant isolation, encryption in transit and at rest, signed telemetry with replay protection, an outbound-only gateway architecture with no inbound firewall ports, control-write safeguards such as setpoint bounds and command verification, immutable audit trails, security monitoring with SIEM export, tested backup and restore, supply chain assurance on the vendor's software, and an incident response plan that covers both vendor and operator roles. The buyer's checklist guide at the top of this hub expands each family into specific questions and the evidence a vendor should be able to produce.

Who is responsible for security in cloud SCADA - the vendor or the operator?

Both, split by layer under a shared responsibility model. The vendor secures the platform: application code, cloud infrastructure, tenant isolation, encryption, patching, and monitoring of its own stack. The operator secures everything the vendor cannot see: field devices and PLCs, the local network, who is granted accounts and roles, credential hygiene, physical access, and the operational procedures around control actions. The dividing line must be written down - in the contract, not implied - because gaps between the two lists are where incidents happen. The shared responsibility guide in this hub gives a layer-by-layer table you can adapt to any vendor.

Sources & Further Reading

Safety & engineering notice. This article is general educational information, not site-specific engineering, safety, or legal advice, and it does not reflect any particular facility. Standards and regulations (for example OSHA, API, IEC, ISO, NFPA, NIST, and NERC CIP requirements) change and vary by edition, jurisdiction, and application. SCADA and remote monitoring cannot verify physical isolation, atmosphere, lockout/tagout, permit status, or a safe go/no-go decision. Qualified personnel must perform site-specific engineering, hazard analysis, and safety review, and confirm current requirements with the authority having jurisdiction, before acting.

Probe a Live System, Not a Brochure

Outbound-only gateways, signed telemetry, tenant isolation, immutable audit trails - bring the question bank from this hub and test the answers yourself.

Request a Free Demo See Our Security Architecture
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →