Automation Glossary • VPN vs private APN vs data diode

VPN vs Private APN vs Data Diode for SCADA

Merobix Engineering • • 6 min read

How a remote site connects to a central SCADA system is a security-posture decision with three common answers that sit at very different points on the risk curve. This page compares an encrypted VPN, a carrier private APN, and a one-way data diode, so you can match the posture to what the site actually needs, including the decisive question of whether control commands must ever travel back to the site.

Back to Blog

VPN vs private APN vs data diode in one line: A VPN encrypts a two-way tunnel over the public internet, so it supports control and access but exposes an attack surface that must be hardened. A private APN keeps cellular traffic off the public internet on a carrier-isolated network, reducing exposure while still allowing two-way traffic. A data diode permits data to leave the site but physically prevents anything returning, giving the strongest isolation at the cost of no remote control. Choose by whether control must flow back and how much exposure is tolerable.

Anchor the Choice on Direction and Exposure

Two properties separate these three postures more than any feature list. The first is directionality: can data flow both ways, or only outward? A VPN and a private APN are both bidirectional, so an operator can send a command or a technician can reach a device, which is powerful and also the exact capability an attacker wants. A data diode is physically one-way; data monitoring information leaves the site and nothing can return, so there is no remote-control path to exploit because none exists.

The second property is exposure to the public internet. A VPN tunnel runs over the open internet, so while the traffic inside is encrypted, the VPN endpoint is reachable by anyone and must be patched and hardened against attack. A private APN, built on the concept of an APN that carriers isolate from the public network, keeps the cellular traffic on a carrier-managed private path, which shrinks the exposed surface without giving up two-way communication. The three postures are really three points on a curve trading capability against exposure.

Compare the Three Postures

The table lines up the postures against the properties that decide the choice, with directionality and exposure as the headline rows.

PropertyVPNPrivate APNData diode
Direction of dataTwo-wayTwo-wayOne-way out only
Remote control possibleYesYesNo - by design
Public internet exposureEndpoint is exposedCarrier-isolatedNone inbound - physically blocked
Attack surfaceMust harden and patch the endpointSmaller, carrier-managedEffectively none inbound
Cost and complexityLow to moderateCarrier service feeHigher - dedicated hardware
Right whenRemote access and control needed cheaplyCellular fleet wanting less exposureHighest-assurance, monitoring-only

These postures are not mutually exclusive; they layer. A private APN can carry a VPN, so the tunnel rides a carrier-isolated path rather than the open internet, combining the encryption of the VPN with the reduced exposure of the APN. Tightening a VPN further with a split-tunnel design and restricting the APN with an APN whitelist are complementary hardening steps rather than competing choices.

The diode occupies a genuinely different category because it changes what is possible, not just how hard it is. A one-way path is the enforcement mechanism behind a unidirectional security gateway, and its assurance comes from physics rather than configuration: an attacker cannot send anything inbound because there is no inbound path to misconfigure. That strength is exactly its limitation, since legitimate remote control is impossible too, which is why the diode is a monitoring-only answer.

When Each Posture Wins

A VPN wins when you need two-way access and control at low cost and can commit to hardening the endpoint. Remote support of PLCs, operator commands to the field, and technician access all require a return path, and a well-maintained VPN provides it economically. The obligation that comes with it is real: the exposed endpoint must be patched, its credentials managed, and its access scoped, because a neglected VPN is a standing invitation.

A private APN wins for a cellular fleet that wants two-way traffic with less public exposure than a raw internet VPN. Keeping the SIMs on a carrier-isolated network removes the sites from public scanning and reachability while preserving the control and access a diode forbids. It is the pragmatic middle posture for distributed cellular sites, and it composes well with a VPN layered on top for defense in depth.

A data diode wins where the assurance requirement is highest and remote control is genuinely unnecessary. Safety-critical or high-consequence facilities that must export monitoring data to a business network or historian while guaranteeing nothing can reach back are the classic case. The decision to use a diode is really a decision that this site will never be controlled remotely, and that constraint must be acceptable to operations, not just to security, before the diode is the right answer.

Pitfalls in Choosing a Posture

The most common pitfall is deploying a VPN and then neglecting the endpoint, so an unpatched, over-privileged tunnel becomes the softest way into the control network. A VPN is only as strong as its maintenance; if nobody owns patching and access review, its convenience becomes the primary risk. Scope access tightly, keep the endpoint current, and treat the tunnel as an exposed asset.

A second trap is assuming a data diode is a drop-in for a site that actually needs occasional remote control, then discovering that routine work now requires a truck roll because nothing can be sent back. The diode's one-way nature must be compatible with how the site is operated, or it will be quietly bypassed with a back-channel that destroys its assurance. The final pitfall is treating a private APN as encryption; it isolates the path but does not by itself encrypt the payload end to end, so where confidentiality matters, layer a VPN inside the APN rather than relying on the APN alone.

Frequently Asked Questions

What is the main difference between a VPN and a data diode for SCADA?

Direction. A VPN is a two-way encrypted tunnel that supports remote monitoring and control but exposes an endpoint that must be hardened and patched. A data diode is physically one-way: monitoring data can leave the site but nothing can return, so there is no remote-control path for an attacker to exploit and none for legitimate operators either. Choose a VPN when control must flow back, a diode when the highest inbound assurance matters and remote control is unnecessary.

Does a private APN replace a VPN?

No, they solve different problems and often combine. A private APN keeps cellular traffic on a carrier-isolated network, reducing public-internet exposure, but does not by itself encrypt the payload end to end. A VPN encrypts the traffic but rides an exposed endpoint. Layering a VPN inside a private APN gives both the encryption of the tunnel and the reduced exposure of the isolated path, which is a common defense-in-depth pattern.

Can I control a remote site through a data diode?

No, and that is the point. A data diode physically permits data to flow only outward, so monitoring information reaches your historian or business network while nothing can travel back to the site. That guarantees an attacker has no inbound path, but it also means legitimate remote control is impossible. A diode is a monitoring-only posture, appropriate only where the site will never need to be controlled or accessed remotely.

More in OT Cybersecurity
Verify private-APN connectivity on a SCADA SIM  •  Private APN vs public cellular SCADA  •  Data Diode  •  APN whitelist  •  Private LTE for SCADA  •  All OT Cybersecurity →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →