SECURING OT NETWORKS FOR POWER GENERATION SITES Whitepaper

A Unidirectional Reference Architecture

Traditional IT-style security advice fails to address the threats facing the control systems of modern power plants. Because OT networks in power plants operate large, complex, and dangerous physical processes and equipment, there is a need for a preventative and disciplined approach to protecting the network perimeter of power generation sites. Damaged turbines and transformers cannot be “restored from backups”, and intrusion detection, response and remediation can interrupt the reliable continuity of services.

Such compromise to power generation networks is unacceptable.

In this paper, we discuss modern reference architecture for defense-in-depth network protection of OT networks at power plants, eliminating external cyber risks and enabling disciplined control to protected, reliability-critical networks, including 4 use cases:

  • Safe IT/OT integration
  • Turbine vendor monitoring
  • Protecting relay and safety networks
  • Control Center Communications

SECURING OT NETWORKS FOR POWER GENERATION SITES Whitepaper

A Unidirectional Reference Architecture

Traditional IT-style security advice fails to address the threats facing the control systems of modern power plants. Because OT networks in power plants operate large, complex, and dangerous physical processes and equipment, there is a need for a preventative and disciplined approach to protecting the network perimeter of power generation sites. Damaged turbines and transformers cannot be “restored from backups”, and intrusion detection, response and remediation can interrupt the reliable continuity of services.

Such compromise to power generation networks is unacceptable.

In this paper, we discuss modern reference architecture for defense-in-depth network protection of OT networks at power plants, eliminating external cyber risks and enabling disciplined control to protected, reliability-critical networks, including 4 use cases:

  • Safe IT/OT integration
  • Turbine vendor monitoring
  • Protecting relay and safety networks
  • Control Center Communications

About The Author

Andrew Ginter

Andrew Ginter

Andrew Ginter is the VP Industrial Security at Waterfall Security Solutions

At Waterfall, Andrew leads a team of experts who work with the world’s most secure industrial sites. He is author of two books on industrial security, a co-author of the Industrial Internet Consortium’s Security Framework, and the co-host of the Industrial Security Podcast. Andrew spent 35 years designing SCADA system products for Hewlett Packard, IT/OT connectivity products for Agilent Technologies, and OT/ICS security products for Industrial Defender and Waterfall Security Solutions.

Fill out this form to access the whitepaper