Security is now the question that decides SCADA purchases. The systems that monitor water plants, pipelines, and production lines are targets, insurers and regulators know it, and a buying decision made on features alone can leave you owning a risk you never priced. This hub organizes all sixty of our SCADA and OT security guides into six groups - buyer's guides, certification explainers, industry compliance, security practice, protocol hardening, and operations governance - each with a one-line summary of what it answers, so you can go straight to the guide that matches the question in front of you.
SCADA security is the practice of protecting supervisory control and data acquisition systems - the software, servers, gateways, and field devices that monitor and control industrial processes - from unauthorized access, data tampering, and disruption, with availability and physical safety as the first priorities. It now sits at the center of every serious platform evaluation.
For most of SCADA's history, security was a paragraph in the RFP. That era is over, for three reasons that every buyer now feels directly. First, the threat is real and documented: publicly reported incidents from the Ukraine grid attacks to Colonial Pipeline and the Oldsmar water intrusion have shown that industrial control systems are attacked, that attacks reach physical operations, and that the entry point is usually mundane - a credential, a VPN, an exposed remote-access service. Second, the compliance floor keeps rising: TSA security directives for pipelines, AWIA for water utilities, NERC CIP for power, 21 CFR Part 11 for pharma, and cyber insurance questionnaires for everyone else have turned security posture into a condition of operating, not a preference. Third, the deployment model changed: cloud SCADA moves part of the security burden onto the vendor, which is only good news if you can verify what the vendor actually does.
That verification is what this hub is for. The guides below teach you what tenant isolation, signed telemetry, and immutable audit trails mean; how SOC 2, ISO 27001, and IEC 62443 actually work and how much each costs to earn; what your specific industry's regulators demand; and how practitioners run patching, access reviews, and incident response in environments where availability and safety come first. The substance is deliberately vendor-neutral - every checklist and question bank works against any platform you evaluate. Where Merobix appears, we state our own controls plainly and you can inspect the full picture on the Merobix security architecture page. If you want a single narrative walkthrough before diving into the directory, start with our foundational guide to securing a SCADA and OT network, then come back here and go deep wherever your risk lives.
Use these when you are evaluating platforms. Each one takes a single control family - identity, isolation, telemetry integrity, encryption, APIs, recovery - and turns it into questions you can put to a vendor and evidence you should expect back. Together they amount to a complete security due-diligence program for a cloud SCADA purchase.
The pillar of the whole series: twelve non-negotiable control families - identity, isolation, telemetry integrity, control safeguards, audit, recovery, and more - with the evidence to demand for each. If you read one guide before an RFP, read this one.
A ready-to-use question bank organized by category, with what a good answer looks like and the red flags that should end the conversation. Bring it to every vendor call.
How shared platforms keep customers apart - row-level security, signed request context, cross-tenant testing - and how to verify isolation instead of taking the vendor's word for it.
TOTP versus FIDO2 passkeys, session expiry and revocation, brute-force lockout, and step-up authentication for high-risk actions - the identity layer done properly.
Why tamper-evident, chained audit records matter, what auditors actually ask to see, and how operational evidence holds up in an investigation.
Signed telemetry envelopes, payload digests, sequence numbers, and replay detection - and why unsigned sensor data is a decision-integrity risk, not just a security one.
Writable-tag allowlists, setpoint bounds, idempotent commands, read-back verification, and management-of-change gates - the safeguards that make remote writes defensible.
TLS in transit, field-level encryption at rest, blind indexes for searching encrypted data, and modern password hashing - what each layer protects and what it does not.
Device registration, per-device credentials, signed update artifacts, store-and-forward buffering, and why outbound-only gateways remove the inbound attack surface entirely.
Scoped API keys with lifecycle and revocation, rate limits, SSRF defenses, and pinned-IP webhook delivery - the integration surface most buyers forget to evaluate.
Runtime threat detection, durable notification delivery with retry and dead-letter handling, and how to get SCADA security events into the SIEM your team already watches.
Signed builds, SBOMs, dependency scanning, and release assurance - the SolarWinds lesson applied to the software that runs your operations.
Backup validation, restore drills, RPO and RTO targets, and retention - the difference between a ransomware incident and a ransomware disaster.
Identity-first access, least privilege, and microsegmentation mapped against the Purdue model - a zero-trust path that works with industrial constraints rather than against them.
How to read a penetration test report, what scope actually means, and the signals that separate vendors who validate continuously from vendors who bought a logo.
Incident response playbooks adapted for OT: roles, tabletop exercises, evidence handling, and where the vendor's responsibilities end and yours begin.
The layer-by-layer comparison: responsibility split, certification differences, patching velocity, exposure trade-offs, staffing reality, and when each model genuinely wins.
SOC 2, ISO 27001, IEC 62443, NIST 800-82, API 1164, TSA directives - the alphabet soup that dominates security conversations, decoded. These explainers cover what each framework actually attests, how a vendor earns it, realistic cost and timeline ranges, and the scope games to watch for when someone hands you a certificate.
The pillar explainer: what each framework covers, how a vendor earns each one, realistic timelines and cost ranges, and what "readiness" versus "certified" actually means in practice.
The industrial standard in depth: the parts of the standard, security levels SL1 through SL4, ISASecure-style certification schemes, and honest cost and timeline ranges.
SOC 2 demystified: why it is an attestation rather than a certification, Type I versus Type II, the Trust Services Criteria, and how to actually read the report a vendor hands you.
The ISMS concept, the 2022 Annex A controls, stage 1 and stage 2 audits, surveillance cycles - and the certificate-scope gaming every buyer should check for.
NIST's control-system security playbook: what revision 3 covers, how it maps to IEC 62443 and the CSF, and how to use it when evaluating vendors.
The pipeline directives from 2021 to today: who is covered, what cybersecurity implementation plans require, and the practical steps to compliance.
The pipeline industry's own SCADA security standard: its scope, the profile-based approach, its relationship to IEC 62443, and the vendor questions it implies.
When you host the platform, the compliance burden shifts to you: which certifications the software vendor should hold versus which programs the operator must build, plus a hardening checklist.
Every regulated industry stacks its own rules on top of the general security frameworks. These guides walk through the specific regulatory drivers for seven sectors - what applies, why, the process to comply, and what to look for in a SCADA vendor serving that industry - so you can hand the right one to your compliance lead and skip the ones that do not apply.
API 1164, TSA security directives, NIST 800-82, and IEC 62443 mapped to upstream, midstream, and downstream operations - with the audit process explained step by step.
Part 11 electronic records and signatures, ALCOA+ data integrity, GAMP 5 validation, and what compliant SCADA actually looks like inside a regulated plant.
AWIA risk assessments and emergency response plans, EPA cybersecurity guidance, state rules - and the small-utility reality of meeting them with a three-person team.
NERC CIP from CIP-002 to CIP-014: BES cyber system categorization, audits and fines, and what actually applies to smaller generators and renewables.
CFATS status, OSHA PSM and management of change, and where safety instrumented systems under IEC 61511 meet cybersecurity under IEC 62443.
FSMA and food defense, HACCP records, SQF and BRC audit expectations, and electronic records in food production environments.
Choosing between ISO 27001, NIST CSF, and IEC 62443 for discrete manufacturing - plus cyber insurance questionnaires, customer flow-down requirements, and CMMC for defense suppliers.
How security actually gets done - and undone - in industrial environments. This is the practitioner tier: the threats that hit real plants, the defenses that survive contact with an availability-first operation, and the architecture patterns for remote access, segmentation, shared responsibility, and air-gapped sites. Start with the OT-versus-IT piece; it is the mindset the rest builds on.
Why availability-first operations break IT security playbooks: patching reality, protocol constraints, and safety consequences - the foundational mindset piece for the whole series.
How industrial ransomware actually unfolds, and the segmentation, backup, and response measures that limit the blast radius when it reaches your network.
Stuxnet, the Ukraine grid attacks, Triton, Colonial Pipeline, and Oldsmar - the public lessons from each, mapped to concrete items on a buyer's checklist.
CVE triage when you cannot reboot the plant: compensating controls, vendor patch cadence, and virtual patching that buys time safely.
The shared-login problem, modern password hashing, the truth about rotation policies, and secrets management for the devices themselves.
Operator-targeted phishing, vendor impersonation, and MFA fatigue - how social attacks reach the control room, and the training that blunts them.
Least privilege, access reviews, clean offboarding, and separation of duties - the controls that address the threat already inside the fence.
The VPN CVE problem, jump hosts, vendor access management, and why outbound-only architectures are steadily displacing inbound remote access.
Private APNs, SIM security, and outbound-only connections over cellular - securing the 4G/5G gateways that link remote sites to the platform.
The Shodan reality of internet-facing HMIs: how exposure happens, why VNC and RDP keep showing up, and the safe remote-access patterns that replace them.
Zones and conduits, firewall rule design, data diodes, and the common DMZ mistakes that quietly undo an otherwise sound segmentation plan.
Right-sized security for a three-person team: the handful of controls that matter most, and how managed cloud platforms carry the rest of the load.
Who secures what, layer by layer - and why the dividing line belongs in the contract, with concrete examples for every layer of the stack.
Data ownership, retention workflows, export rights, and offboarding portability - the questions that protect you at the end of a vendor relationship, asked at the beginning.
What machine learning genuinely catches in telemetry and authentication patterns, what it cannot, and how to see through the marketing around both.
A 30-point self-assessment across identity, network, device, data, and detection - score your current posture in an afternoon, before an auditor does it for you.
Joiner-mover-leaver discipline for control systems: quarterly reviews, role sprawl, competency checks, and the contractor-access problem.
When regulation genuinely requires an air gap, why the gap alone is not security, and how updates, monitoring, and compliance actually work offline.
Industrial protocols were designed for reliability on trusted wires, decades before anyone imagined them under attack - and most offer little or no built-in authentication or encryption. These five guides cover what each major protocol can and cannot protect on its own, and the hardening patterns that make each one survivable in a modern network.
Broker authentication, per-device credentials, topic ACLs, signed message envelopes, and Sparkplug considerations for industrial MQTT deployments.
SignAndEncrypt modes, the certificate-management pain nobody warns you about, user tokens, and the deployment mistakes that quietly undo OPC UA's security model.
A protocol with no authentication and no encryption still runs much of the world's industry - the network isolation, gateway pattern, and detection that make it survivable.
Secure Authentication v5 explained: what it protects, where it applies in water and power, and the practical state of adoption in the field.
Default passwords, firmware currency, open ports and services, physical access, and program protection - a hardening checklist for the controllers themselves.
Security that lives in documents fails; security that lives in daily operations holds. This final group covers the governance layer - alarm delivery you can prove, mobile access you can defend, RFP language that forces honest vendor answers, the budget case that gets the program funded, and a plain-language glossary for everyone else in the room.
Delivery assurance for critical alerts: retry and dead-letter handling, provider canaries, and escalation chains that survive a notification-provider outage.
Mobile sessions, device loss, push-notification safety, and read-only-by-default patterns for operators who monitor from the road.
Copy-paste-ready security requirement language for your RFP, plus scoring methods and the specific proof to demand alongside each vendor answer.
Breach cost data with honest ranges, cyber insurance pressure, and how to make the OT security case to a board in the board's own language.
Sixty terms from row-level security to zones and conduits, defined in plain language - the quick reference to hand everyone else on the project team.
Merobix appears in many of the guides above, so here is our position stated once, plainly. The platform is built security-first: TOTP and FIDO2 passkey MFA with role-based, site-level authorization; PostgreSQL row-level security and signed database request context isolating every tenant; Ed25519-signed telemetry envelopes with sequence numbers, payload digests, and replay detection; explicit writable-tag configuration with setpoint bounds, idempotent commands, and read-back verification for control writes; immutable chained audit records; and runtime threat detection with SIEM, email, SMS, and webhook delivery. The gateway architecture is outbound-only - no inbound firewall ports, no VPN - and the same platform deploys cloud-hosted or fully on-premise, including air-gapped networks. The complete control-by-control breakdown is on the Merobix security architecture page.
On certifications, we hold ourselves to the same honesty these guides demand from every vendor: Merobix runs a SOC 2 readiness program and maps its controls to IEC 62443 - we do not claim certifications we have not earned, and independent penetration testing is part of our ongoing validation program rather than a finished checkbox. No vendor should call any system unhackable, and we never will; what a serious vendor can do is show you the controls, the evidence, and the roadmap, and let you probe all three. If you want to do exactly that against a live system, request a demo and bring the question bank from this hub with you.
The one-question shortcut: ask every vendor to walk you through their most recent security assessment - what was tested, what was found, and what was fixed. Vendors with real programs answer specifically and comfortably, including the uncomfortable parts. Vendors without one change the subject to features. The shape of the answer tells you more than any brochure.
SCADA security is the practice of protecting supervisory control and data acquisition systems - the software, servers, gateways, and field devices that monitor and control industrial processes - from unauthorized access, data tampering, and disruption. It spans identity and access control, network architecture, telemetry integrity, encryption, audit trails, and incident response. Unlike IT security, SCADA security must put availability and physical safety first: a control system that trips offline during an attack response can be as dangerous as the attack itself. Standards such as ISA/IEC 62443 and NIST SP 800-82 define the reference practices most operators and auditors work from.
Not inherently - the two models distribute risk differently rather than one being categorically safer. A cloud SCADA vendor patches continuously, monitors around the clock, and can afford security engineering most operators cannot staff, but you must verify tenant isolation, encryption, and the vendor's audit evidence. On-premise deployment gives you full physical control and suits air-gapped requirements, but shifts the entire security program - patching, monitoring, backup, hardening - onto your team. The honest comparison is between the vendor's demonstrated security program and your own, layer by layer, which is exactly what the shared-responsibility and cloud-versus-on-premise guides in this hub walk through.
Look for evidence across three frameworks: SOC 2 (an attestation of operational controls, reported as Type I or Type II by a licensed CPA firm), ISO 27001 (a certified information security management system), and ISA/IEC 62443 (the industrial-specific standard, with certifiable security levels for products and processes). Just as important is honesty about status: a vendor with a SOC 2 readiness program and controls mapped to IEC 62443 that says so plainly is a better sign than vague certified-sounding language you cannot verify. Always ask for the actual report or certificate, check its scope, and confirm the dates - certifications and attestations cover specific systems over specific periods, not the company forever.
Twelve control families cover most of the risk: multi-factor authentication and session management, role-based least-privilege access, tenant isolation, encryption in transit and at rest, signed telemetry with replay protection, an outbound-only gateway architecture with no inbound firewall ports, control-write safeguards such as setpoint bounds and command verification, immutable audit trails, security monitoring with SIEM export, tested backup and restore, supply chain assurance on the vendor's software, and an incident response plan that covers both vendor and operator roles. The buyer's checklist guide at the top of this hub expands each family into specific questions and the evidence a vendor should be able to produce.
Both, split by layer under a shared responsibility model. The vendor secures the platform: application code, cloud infrastructure, tenant isolation, encryption, patching, and monitoring of its own stack. The operator secures everything the vendor cannot see: field devices and PLCs, the local network, who is granted accounts and roles, credential hygiene, physical access, and the operational procedures around control actions. The dividing line must be written down - in the contract, not implied - because gaps between the two lists are where incidents happen. The shared responsibility guide in this hub gives a layer-by-layer table you can adapt to any vendor.
Safety & engineering notice. This article is general educational information, not site-specific engineering, safety, or legal advice, and it does not reflect any particular facility. Standards and regulations (for example OSHA, API, IEC, ISO, NFPA, NIST, and NERC CIP requirements) change and vary by edition, jurisdiction, and application. SCADA and remote monitoring cannot verify physical isolation, atmosphere, lockout/tagout, permit status, or a safe go/no-go decision. Qualified personnel must perform site-specific engineering, hazard analysis, and safety review, and confirm current requirements with the authority having jurisdiction, before acting.
Outbound-only gateways, signed telemetry, tenant isolation, immutable audit trails - bring the question bank from this hub and test the answers yourself.