Logging and Monitoring for Small Control System Environments

You do not need a full security operations center to notice trouble in a control environment. Start with a few logs that answer who connected and what changed.

3 min readBy Ironfield Cyber Team

When something strange happens in a control environment, the first question is always the same: what changed? Without logs, nobody can answer. Many small utilities, oilfield service firms, and industrial operators have little or no logging around their operational systems, so an incident is discovered late and understood poorly.

Monitoring does not have to mean a large budget. A modest set of logs and alerts, focused on the places attackers must pass through, provides a large share of the value. This article outlines a practical approach for small teams.

Set a Realistic Goal

Aim to answer a short list of questions:

  • Who connected to the control network, from where, and when?
  • What devices appeared or disappeared?
  • What changed in controller programs or configurations?
  • Did something try to communicate where it should not?
  • Did a remote access session happen outside normal hours?

You can start answering these without logging every device.

Where to Collect Logs

The boundary between IT and OT

Firewalls and gateways between business networks and the control network see all the traffic that crosses. Log accepted and denied connections, administrator logins, and configuration changes.

Remote access systems

VPN gateways, jump servers, and vendor remote access tools should record who signed in, when, from where, and what they accessed. If the tool can record sessions, enable it for third-party access.

Engineering workstations and servers

These Windows systems hold controller programming software and are high-value targets. Enable security event logging, track new accounts and privilege changes, and record the use of programming tools where possible.

Network equipment

Switches and routers can log configuration changes and port events, such as a new device plugged in.

Industrial devices

Some controllers and gateways can log logins, program downloads, and mode changes. Enable these where supported, with care and in coordination with the vendor and operations staff.

Passive Network Monitoring

Specialized industrial monitoring tools listen to traffic and report new devices, unusual commands, and unexpected connections, without interfering with the process. They provide visibility where devices themselves cannot log. Many vendors offer options scaled for smaller sites, and a managed service can keep costs predictable.

Centralize and Protect the Logs

Collect logs in one place so they can be searched and are not lost if a device fails or is tampered with. Keep the logging system itself secure, with limited access and time synchronization across devices so events line up. Decide how long to keep records, balancing storage costs with the need for investigation, and consider any retention requirements that apply to your operations.

Decide What to Alert On

Too many alerts means none get read. Begin with a small set:

  1. A new administrator account or privilege change
  2. A remote access session outside approved hours
  3. A new device on the control network
  4. A change to a controller program or firewall rule
  5. Repeated failed logins
  6. Traffic from the control network to the open internet

Define who receives alerts, what they should do, and when to involve operations. Practice by testing one alert and walking through the response.

Establish a Baseline

Monitoring is most useful when you know what normal looks like. Spend a few weeks observing typical traffic patterns, device lists, and access times. Document them. Deviations then stand out.

Involve Operations

Alerts about control systems often need operational context. A program download might be maintenance or an attack. Create a simple way for operators and engineers to confirm planned changes, such as a change log or a shared calendar, so security staff can distinguish normal work from trouble.

Consider Managed Monitoring

If you lack staff to watch alerts, consider a managed service that can monitor logs and respond or escalate. Ask providers about their experience with industrial environments, how they avoid disrupting operations, and how they handle after-hours escalations.

Common Pitfalls

  • Collecting logs that nobody reads
  • Logging too little at the boundary
  • Failing to synchronize clocks
  • Not preserving logs after an incident
  • Treating monitoring as purely an IT function

Where to Begin

Pick one location, the boundary firewall or remote access gateway, and make sure its logs are collected, protected, and reviewed. Then expand. Ironfield Cyber can help small operators design a right-sized monitoring approach for control environments, coordinating with your operations team so visibility improves without risking the process.