Emerging Consensus on ICS Security

Whitepaper on Expert Recommendations on Industrial/SCADA Security Best Practice

An increasing body of experience with industrial control system (ICS)/SCADA network security, as well as the emerging Industrial Internet of Things (IIoT) are driving a new consensus as to the difference between information technology (IT) and operations technology (OT)/ICS security programs. NIST, ANSSI, the ARC, the Gartner Group and others all recognize that preventing mis-operation of industrial systems in order to preserve safe and reliable operations is a fundamental priority for industrial sites, while the priority on IT networks is one variation or another of “data protection.”

In this whitepaper we break it down to following chapters:

  • What is ICS Security
  • How ICS security is different from IT security
  • Perimeter security – preventing vs. detecting attacks
  • Controlling information flows
  • Industrial Internet of Things (IIoT)


A wide variety of experts, standards and guidance are going on the record regarding firewalled connectivity, recommending that Unidirectional Security Gateways and related technology be used instead of firewalls in many industrial contexts. In particular, Unidirectional Gateways are seen as important enablers of IIoT deployments. Unlike firewalls, Unidirectional Gateways can connect industrial networks directly to IT, Internet and cloud systems without risk of attacks leaking back into protected industrial networks.

