Automation Glossary • Removable Media Control

What Is Removable Media Control in OT?

Merobix Engineering • • 7 min read

Removable media control is the set of measures that govern how USB drives, memory cards, and other portable storage are allowed to touch OT systems - because a physical drive is one of the few ways malware can cross into a network that has no internet connection. It addresses a threat that segmentation and firewalls cannot: the infected USB stick a technician carries in the door. This page explains why removable media is such a potent OT threat vector, and how sanitization stations and port lockdown close it.

Back to Blog

Removable Media Control in one line: Removable media control is the practice of restricting and vetting the portable storage devices - USB drives, memory cards, external disks - that connect to OT systems, so an infected drive cannot introduce malware into the control environment. It combines physical measures like disabling or blocking USB ports with a process of scanning and sanitizing any media that must be used, typically at a dedicated sanitization station, so that removable media becomes a controlled, inspected channel rather than an open door that bypasses every network defense.

Why Removable Media Is Such a Dangerous Vector

Much of OT security is built on limiting network connectivity - segmenting networks, filtering traffic, and in the strongest cases air-gapping systems so they have no connection to the outside world at all. Those defenses assume the danger arrives over the network. Removable media sidesteps all of them. A USB drive does not travel over any network the firewalls watch; it travels in a person's pocket and plugs directly into a system, delivering whatever it carries straight past every network control. For an air-gapped site, a drive is often the only way in - which makes it the way in that attackers and malware exploit.

The threat is potent partly because it rides on legitimate, everyday activity. Technicians genuinely need to move files: firmware updates, configuration files, logic backups, vendor software, diagnostic data. USB drives are the natural tool, so they are in constant use, carried between machines, taken home, plugged into personal computers, and brought back to the plant. Any one of those out-of-plant contacts can pick up an infection that the drive then carries into the control system on its next use, entirely innocently, with no one intending any harm.

History has made this concrete: some of the most serious industrial malware incidents are understood to have spread into isolated control environments via removable drives rather than over networks. The lesson is that isolating a network from the internet does not isolate it from infected media, and that a site can be diligent about firewalls and segmentation while leaving wide open the one channel that actually reaches its most protected systems. Removable media control exists to close that channel deliberately rather than leaving it to chance and good intentions.

Sanitization Stations and Port Lockdown

The two halves of removable media control are inspecting the media that must be used and blocking the ports that should not be used. The first is handled by a sanitization station, sometimes called a scanning kiosk: a dedicated, isolated machine that any drive must pass through before it is allowed near a control system. The station scans the media for malware, and in stronger implementations extracts only the specific legitimate files that are needed onto a clean, trusted drive, leaving anything suspicious or unnecessary behind. Media goes in potentially dirty and comes out verified, so only vetted content ever reaches the OT systems.

The second half is locking down the ports themselves, because the safest USB port is one that cannot be used at all. On systems that have no legitimate need for removable media, ports can be disabled - in software, or physically blocked - so a drive simply does not function when plugged in. Where media is occasionally needed, controls can restrict use to specific approved drives, or require that a port be deliberately enabled for a task and disabled again afterward. The principle is that connecting a drive is an authorized, exceptional action rather than something anyone can do to any machine at any time.

Underpinning both is a clear policy about what is allowed. Effective removable media control defines which drives may be used - often only issued, tracked, corporate devices rather than whatever someone brought from home - and requires that all media pass through sanitization before touching OT. Personal and unknown drives are prohibited outright. The technical controls enforce a policy that people understand: there is a right way to move files into the control environment, it runs through the sanitization station on approved media, and every other path is closed. Without that clarity, the kiosk and the port locks are easy to work around.

Removable Media at Remote and Field Sites

Remote oil and gas sites intensify the removable-media problem in two ways. First, many field sites are genuinely disconnected or barely connected, so moving files by drive is not a bad habit but a practical necessity - firmware, configurations, and backups often travel to a wellsite on a USB stick because there is no convenient network path. Second, those sites are unmanned and visited by a rotating cast of technicians and contractors, each with their own equipment and drives, and no one is standing by to watch what gets plugged in. The vector is both more used and less supervised than at a staffed plant.

This is where the air-gap advantage can quietly turn into a liability. A site kept off the network for safety is well protected against remote attack, but if drives flow freely into it, the isolation that was supposed to protect it becomes the reason no network defense is watching when an infected drive arrives. Removable media control is what keeps the air gap honest: sanitizing every drive that crosses it, and blocking casual USB use, so the isolation is not silently undone by the one channel that reaches the isolated systems.

Reducing the need for drives in the first place also helps, and this is where remote monitoring contributes. A cloud SCADA platform such as Merobix moves a great deal of routine data - readings, trends, alarms - off the site over a controlled connection rather than on a technician's drive, which shrinks how often removable media has to be used at all. Fewer drive transfers mean fewer opportunities for an infected drive to arrive. Removable media control handles the transfers that genuinely must still happen physically, while continuous monitoring reduces how many of those there are, and together they narrow the vector on sites that are hardest to supervise in person.

Frequently Asked Questions

Why is a USB drive a bigger threat to OT than to office IT?

Because OT often relies on network isolation - segmentation or a full air gap - as a primary defense, and a USB drive bypasses all of it by delivering its contents directly to a system without crossing any network the firewalls watch. On an isolated control system, a drive may be the only way in, which makes it the way malware exploits. Some of the most serious industrial malware incidents are understood to have spread into isolated environments through removable media.

What does a media sanitization station do?

A sanitization station, or scanning kiosk, is a dedicated isolated machine that every drive must pass through before going near a control system. It scans the media for malware, and in stronger setups extracts only the specific legitimate files needed onto a clean, trusted drive, leaving anything suspicious behind. Media goes in potentially dirty and comes out verified, so only vetted content reaches the OT systems.

Should USB ports on OT systems just be disabled?

Where a system has no legitimate need for removable media, disabling the ports - in software or by physically blocking them - is the strongest control, because the safest port is one that cannot be used. Where media is occasionally needed, use is instead restricted to specific approved drives and gated through a sanitization station. The goal either way is that connecting a drive is a deliberate, authorized exception rather than something anyone can do to any machine at any time.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
Out-of-Band Management  •  Deny-by-Default Firewalling  •  Log Aggregation  •  VFD Carrier Frequency  •  dV/dt & Reflected Wave  •  VFD Bearing Currents  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →