Control systems don’t need more complexity. They need systems that are easier to secure, maintain, and understand. Recent attacks on water infrastructure have shown that unauthorized access to a controller can affect the physical process — not just business data. Choosing equipment that is straightforward to secure and maintain is now an operational requirement.
Horner OCS controllers combine control, visualization, I/O, and communications in a streamlined platform, designed to reduce complexity and help operators maintain a defensible automation environment.
Horner OCS Benefits
- An integrated OCS architecture with fewer separate devices, software packages, interfaces, and vendor dependencies.
- Password protection for controller programming and network access.
- User-level permissions and protected application access.
- A focused product ecosystem that is easier to inventory, update, and maintain.
Protect the Process — Not Just the Network
Cybersecurity is not a single feature or a vulnerability count. It is the ability to understand your system, limit access, maintain it, and recover when something goes wrong. Horner helps make that job manageable.
Secure Remote Access Without Exposing the PLC
Horner’s OCS360 Cloud Platform provides a controlled, encrypted path for authorized access instead of exposing controllers directly to the public internet or relying on improvised remote-access solutions. OCS360 Remote connects Cscape for troubleshooting, program upgrades, and WebMI visualization through the cloud. Connections use end-to-end encryption, and only certified devices can connect to the server.
Horner offers a more manageable controller environment and a safer way to provide remote access. Integrated PLCs (with and without HMI), I/O, data logging, and communications — backed by a single software platform — make system inventory, maintenance, and lifecycle management easier. There is no need to expose the PLC directly to the internet.
Traditional Remote Access
Potential concerns:
- Internet-facing equipment
- Open inbound ports
- Shared VPN credentials
- Multiple third-party remote-access tools
- Limited control over who connects
- Difficult-to-manage access paths
The Horner Approach
Benefits:
- Managed cloud connection with mTLS X.509 certificates
- End-to-end encryption
- Certified devices only
- No direct public PLC exposure
- One platform for visibility and support
- Reduced need for on-site service calls
- Robust audit logs
Cybersecurity does not mean disconnecting your facility. It means connecting it securely.
Horner OCS and OCS360 assist automation users in maintaining remote visibility and support while reducing direct controller exposure. Through encrypted cloud connectivity, certified devices, integrated automation, and controlled programming access, Horner provides security that is practical for real-world operations.
Control Systems Security Checklist
Use this checklist to reduce exposure, control remote access, and improve your ability to recover from a cybersecurity incident.
1. Protect Controller Access
- □ Change all default passwords before commissioning the system.
- □ Use unique passwords for each facility, system, and user.
- □ Limit programming access to authorized personnel only.
- □ Apply user-level permissions based on job responsibilities.
- □ Protect controller programs from unauthorized viewing or modification.
- □ Remove or disable unused user accounts.
- □ Review access permissions whenever an employee or contractor changes roles.
2. Avoid Direct Internet Exposure
- □ Do not connect PLCs or HMIs directly to the public internet.
- □ Remove unnecessary port-forwarding rules from facility routers.
- □ Verify that controller programming ports are not publicly accessible.
- □ Use a managed, encrypted remote-access platform rather than an exposed web server or open inbound connection.
- □ Periodically scan the facility’s public IP addresses for unintentionally exposed devices.
3. Use Secure Remote Access
- □ Route remote visualization, troubleshooting, and programming through an approved secure-access platform.
- □ Use encrypted connections for all remote sessions.
- □ Allow only authorized users and approved devices to connect.
- □ Provide each remote user with an individual account rather than shared credentials.
- □ Require multifactor authentication when supported.
- □ Review and remove temporary contractor or service accounts after work is completed.
- □ Log remote sessions and periodically review access activity.
4. Segment the Automation Network
- □ Separate the operational technology network from the office and business network.
- □ Use industrial firewalls between network zones.
- □ Restrict communication to only the ports, protocols, and devices required for operation.
- □ Place remote-access gateways and cloud-connected devices in an appropriate security zone.
- □ Prevent general-purpose office computers from directly accessing controllers.
- □ Use separate networks or VLANs for control, visualization, maintenance, and guest access.
5. Reduce the Attack Surface
- □ Disable unused Ethernet services, protocols, and communications ports.
- □ Remove obsolete devices and unsupported software.
- □ Avoid installing unnecessary third-party remote-access tools on control-system computers.
- □ Maintain an inventory of every PLC, HMI, computer, network device, and firmware version.
- □ Review the inventory at least annually and whenever the system changes.
- □ Favor integrated automation architectures that reduce the number of separate devices and connections that must be maintained.
6. Maintain Software and Firmware
- □ Subscribe to security notifications from automation and network-equipment suppliers.
- □ Review vendor security advisories regularly.
- □ Keep controller firmware, programming software, operating systems, firewalls, and routers at supported versions.
- □ Test updates before deploying them to an operating facility.
- □ Document approved firmware and software versions for each system.
- □ Replace equipment that can no longer receive security updates.
7. Back Up Critical Systems
- □ Maintain current backups of all controller programs and configurations.
- □ Back up HMI applications, recipes, data-logging configurations, and network settings.
- □ Store at least one backup offline or in a protected location.
- □ Label backups with the controller model, firmware version, date, and facility location.
- □ Verify that backups can be restored successfully.
- □ Update backups after every approved system change.
8. Control System Changes
- □ Require authorization before controller programs or network settings are changed.
- □ Record who made each change, what was changed, and why.
- □ Compare running controller programs with approved master copies when suspicious activity is detected.
- □ Investigate unexpected logic, setpoint, timer, alarm, or communications changes.
- □ Restrict the use of removable media and scan approved devices before use.
9. Monitor for Warning Signs
- □ Watch for unexpected controller resets, mode changes, or firmware updates.
- □ Investigate unexplained process changes or abnormal equipment operation.
- □ Monitor repeated login failures and unusual remote-access activity.
- □ Review firewall and network logs for unexpected connections.
- □ Train operators to report unfamiliar screens, alarms, messages, or behavior immediately.
10. Prepare an Incident-Response Plan
- □ Identify who has authority to disconnect remote access or isolate the automation network.
- □ Maintain current contact information for operations, engineering, IT, management, and equipment suppliers.
- □ Document how to place the process in a safe manual or local-control state.
- □ Define how compromised equipment will be isolated without creating a safety or environmental hazard.
- □ Practice restoring controller programs and system configurations.
- □ Report significant incidents to the appropriate authorities and cybersecurity agencies.
A note on defense in depth: No single controller, network, or cloud service can independently secure an entire facility. Effective protection depends on proper system design, configuration, password management, network segmentation, monitoring, maintenance, employee training, and incident-response planning.
Ready to secure your control systems?
Process Solutions Corp. can help you specify Horner OCS controllers and OCS360 secure remote access for your facility.
Call (281) 491-3833 Request a QuoteDownload the Full White Paper (PDF)
Source: Horner Automation Group white paper HA-463, “Secure by Design. Simple to Defend.” Shared by Process Solutions Corp., a certified Horner distributor. Content and images are the property of Horner Automation Group and are subject to change.