Loading

Designing a Secure, Efficient OT Network Infrastructure

Key to success: Getting full lifecycle visibility of physical and electronic security systems
Engineering industry concept with a laptop and drawings on a desk and a petrochemical plant in the background
Designing a Secure, Efficient OT Network Infrastructure
Key to success: Getting full lifecycle visibility of physical and electronic security systems
Cybersecurity
    • Overview
    • Overview
    • Overview
    • Zero Trust
    • Zero Trust
    • Identity & Access Management
    • Identity & Access Management
    • IT / OT Convergence
    • IT / OT Convergence
    • CIP Security
    • CIP Security
    • Technology & Certification
    • Technology & Certification
    • Security & LifecycleIQ
    • Security & LifecycleIQ
    • Secure Digital Transformation
    • Secure Digital Transformation
    • NIST Cybersecurity Framework
    • NIST Cybersecurity Framework
    • Overview
    • Overview
    • Overview
    • Managed Services
    • Managed Services
    • Threat Detection
    • Threat Detection
    • Incident Response
    • Incident Response
    • SOC as a Service
    • SOC as a Service
    • IT Cybersecurity Services
    • IT Cybersecurity Services
    • Endpoint Protection
    • Endpoint Protection
    • Overview
    • Overview
    • Overview
    • Critical Infrastructure
    • Critical Infrastructure
    • Life Sciences
    • Life Sciences
    • Automotive
    • Automotive
    • Manufacturing
    • Manufacturing
    • Food & Beverage
    • Food & Beverage
    • Mining
    • Mining
    • Overview
    • Overview
    • Overview
    • Advisories & Support
    • Advisories & Support
    • Design & Planning
    • Design & Planning
    • Network Security
    • Network Security
    • Penetration Testing
    • Penetration Testing
    • Respond & Recover
    • Respond & Recover
    • Risk Assessment
    • Risk Assessment
    • Vulnerability Assessment
    • Vulnerability Assessment
  • World Class Partners
    • Blogs
    • Blogs
    • Press Releases
    • Press Releases
    • Webinars
    • Webinars
    • Whitepapers
    • Whitepapers

A holistic, secure and resilient plant-wide or site-wide network architecture consists of multiple technologies, software-based or physical, deployed at different levels within the plant or site. Selecting the right technology for security and resilience requires various plant and site application factors to be evaluated, including the physical layout or geographic dispersion of Industrial Automation and Control System (IACS) devices, as well as recovery time performance, uplink media type, tolerance to data latency and jitter, and future-ready requirements.

Taken together, these design elements can be designed into a highly secure network infrastruture, delivering full lifecycle visibility and control.


Achieving Effective Industrial Network Security

Rockwell Automation plus the Network Industry Giant

Business practices, corporate standards, policies, industry standards and tolerance to risk are key factors in determining the degree of resiliency and application availability required within an IACS plant-wide or site-wide architecture. Alternatives can include non-resilient LAN, resilient LAN, or redundant LANs for example.

A secure and resilient network architecture within an IACS application plays a pivotal role in helping to minimize the risk of IACS application shutdowns in the event of cyberattack, while helping to maximize overall plant and site uptime. Resilient architectures also accommodate future requirements more flexibly.

Elements to incorporate in resilient physical infrastructure designs include:

  • Topologies and protocols
  • Switching and routing
  • Wireless LAN Controllers (WLC)
  • Firewalls
  • Network and device management

The Converged Plantwide Ethernet (CPwE) design guides from Rockwell Automation and Cisco provide guidance and best practices to help IT and OT teams collaboratively deploy scalable, robust, resilient and secure industrial network architectures.

Effcient And Resilient Network Security From Rockwell Automation And Cisco
Co-workers discuss IT and OT convergence while viewing a handheld device that uses industrial network solutions for connectivity
PartnerNetwork
Effcient And Resilient Network Security From Rockwell Automation And Cisco

The Rockwell Automation and Cisco partnership lets you create a strong, protected network infrastructure for a secure digital transformation.

Learn More

Integrating Worker Safety and Plant Security at Lower Cost
Key hole in a cloud
Magazine
Integrating Worker Safety and Plant Security at Lower Cost

Move away from the seemingly impossible task of balancing safety and security goals in environments with limited capital for aging plant automation infrastructure.

Read Now

Full Resilience, Safety and Security: How to Design Them In CPWE

Protecting people, environment and critical infrastructure

The CPwE key tenets include:

  • Smart IIoT devices — Controllers, I/O, drives, instrumentation, actuators, analytics, and a single IIoT network technology (Ethernet/IP), facilitating both technology coexistence and IACS device Interoperability
  • Zoning or Segmentation — Smaller connected LANs, functional areas, and security groups
  • Resiliency — Robust physical layer and resilient or redundant topologies with resiliency protocols
  • Time-critical data — Data prioritization and time synchronization via CIP Sync™ and IEEE-1588 Precision Time Protocol (PTP)
  • Holistic defense-in-depth security — Multiple layers of diverse technologies for threat detection and prevention, implemented by different personas (for example, OT and IT) and applied at different levels of the plant-wide or site-wide IACS architecture. CPwE helps protect against cybersecurity threats including Man-in-the-Middle (MitM) attacks, ransomware and other drivers of downtime and loss
  • Convergence-ready—Seamless plant-wide CPwE are relevant to both OT and IT disciplines

Creating a Modernized Plant That Works for Everyone

The ease of integration with modernized tools will surprise you

An IACS is deployed in a wide variety of industries such as automotive, pharmaceuticals, con-sumer packaged goods, pulp and paper, oil and gas, mining, and energy. IACS applications are composed of multiple control and information disciplines such as continuous process, batch, discrete and hybrid combinations.

One of the challenges facing industrial operations is the hardening of standard Ethernet and IP-converged IACS networking technologies to take advantage of the business benefits associ-ated with IIoT. A resilient LAN architecture can help to increase the overall equipment effec-tiveness (OEE) of the IACS by reducing the impact of a failure while speeding recovery outages – such as cyberattack – which in turn lowers Mean-Time-to-Repair (MTTR).

Modernizing aging automation equipment has far-reaching benefits. Updating can help im-prove productivity and access to plant-wide information, extend product lifecycle and make product development more agile by offering increased system flexibility. Find out how Rock-well Automation does it through planning and design.

Plant Floor Modernization
Two engineers using a tablet and standing in front of a oil and gas transport pipeline with sparks flying
Blog
Plant Floor Modernization

Modernizing aging equipment has far-reaching benefits. Wondering where to start? Rockwell Automation and our team of experts have you covered from start to finish.

Read Now

A View Into Design Guidance And Best Practices
Female hand using a switch in a manufacturing environment
Whitepapers
A View Into Design Guidance And Best Practices

We continuously publish whitepapers to provide awareness on network security capabilities, and CPwE architectures that are validated as part of the best practice design guides available here.

Learn More

Design Guidance and Best Practices

Deployments of Network Convergence

Industry adoption of Ethernet/IP™ for control and managed data transit enables the conver-gence of industrial and enterprise networks. We collaborate with our premium partners to de-ploy scalable, robust, secure, safe, and future-ready industrial network architectures. We have addressed topics relevant to both operations technology (OT) and information technology (IT) teams.

Contact a Rockwell Automation Cybersecurity Specialist
Contact Us
Recommended for You
Loading
  • Sales
  • Customer Care
  • TechConnect Support
  • General Questions
  1. Chevron LeftChevron Left Home Chevron RightChevron Right
  2. Chevron LeftChevron Left Cap... Chevron RightChevron Right
  3. Chevron LeftChevron Left Industrial Cybersecurity Solutions Chevron RightChevron Right
  4. Chevron LeftChevron Left Cybersecurity Products and Services Chevron RightChevron Right
  5. Chevron LeftChevron Left Industrial Network Security Design Planning Chevron RightChevron Right