Ask most small operators for a network diagram of their control systems and you get one of three answers: a drawing from the original installation, a sketch on a whiteboard, or a shrug. Yet the diagram is where security starts. You cannot protect connections you do not know exist.
This post walks through how to read a diagram critically, what to look for in the connections, and how to keep it accurate without a dedicated engineer.
What a Useful Diagram Shows
A useful OT network diagram does not need to be pretty. It needs to show:
- Every controller, PLC, RTU, HMI and engineering workstation.
- The switches, routers, firewalls and radios that connect them.
- Every connection to the corporate network, the internet, a cellular modem or a vendor.
- Which devices are on which network segment.
- The direction of data flow, such as from field devices to a historian or to an operations center.
Most importantly, it should be dated. A diagram with no date should be assumed wrong.
Questions to Ask of Every Connection
Walk the drawing line by line and ask these questions.
Where does this connection leave the control network?
Every path out is a path in. List them all: corporate links, remote access for engineers, vendor modems, cellular gateways, and any link to the cloud for reporting. Each should have an owner and a reason to exist.
Is there a firewall at this boundary, and who manages it?
A router is not a firewall. At each boundary there should be a device that can restrict traffic to only what is needed, with rules someone has reviewed recently.
Could a device on the corporate side reach a controller directly?
If a laptop on the office Wi-Fi can open a connection to a PLC, a stolen password or a phishing infection can become a process problem. Direct paths should be closed or tightly limited to specific systems and ports.
Which devices have more than one network card?
A workstation connected to both the office network and the control network quietly defeats segmentation. These dual-homed machines are among the most common surprises.
What is plugged in that should not be?
Cellular modems installed years ago for convenience, vendor laptops left on site, and personal access points are all frequent discoveries.
Verifying the Diagram Against Reality
A diagram is a claim. Check it.
- Walk the site or the cabinets and compare the physical devices to the drawing.
- Review switch port lists and identify unknown connections.
- Ask operators and vendors which remote access methods they actually use. Informal methods often exist.
- Where tooling allows, run a passive discovery scan, which listens without sending probes that could disturb sensitive equipment. Do not run aggressive scans on live control networks without engineering approval.
Record differences, fix the diagram, and note the questions that need follow-up.
Marking the Risk Areas
Once the drawing is accurate, mark it up.
- Highlight any internet-facing path.
- Circle unsupported or very old devices that cannot be patched.
- Flag shared accounts and default credentials you know exist.
- Note the systems that, if lost, would stop production or create a safety issue.
That marked-up drawing becomes your priority list. Closing a stray modem or adding a firewall rule is often inexpensive and removes a real exposure.
Keeping It Current
The easiest way to keep a diagram honest is to tie it to change. Any time a device is added, replaced or reconfigured, someone updates the drawing as part of the job. Add a line to your work order or change checklist. Review the whole diagram at least once a year, or after any significant project.
Store it somewhere safe and keep a printed copy in the control room. In an incident, a current diagram saves hours.
Who Should See It
Treat the diagram as sensitive. It is a map of your weak points. Share it with people who need it, such as engineers, trusted integrators and your IT or security partner, and avoid emailing it widely or posting it in shared folders without access controls.
Where We Can Help
Ironfield Cyber can help small energy and industrial operators build or refresh network diagrams, identify unmanaged connections and prioritize practical fixes that respect uptime and safety. If you have a drawing you are not sure you trust, we are happy to review it with you.