Securing Engineering Workstations and Laptops in OT Environments

The laptop used to program controllers is one of the most powerful devices in your plant. Learn how to harden, control and monitor engineering workstations.

3 min readBy Ironfield Cyber Team

Control systems are only as secure as the machines that configure them. The engineering workstation, or the laptop a technician carries to program controllers and tune drives, can change logic, download firmware, and see nearly everything on the network. That makes it both indispensable and one of the most attractive targets in an operational environment.

Yet these machines are often the least disciplined: a laptop used for email and browsing at lunch, plugged into the control network after lunch. A few clear rules reduce that risk significantly.

Why these machines matter

An attacker who controls an engineering workstation can modify controller programs, change setpoints, disable alarms, or pivot into other systems. A workstation infected with malware can carry it directly onto an isolated network. Contractor and vendor laptops add further risk, since you do not control their patching or what else is installed.

Dedicate and separate

The most effective step is separation of purpose.

  • Dedicated engineering workstations used only for control system work, not general browsing or email.
  • Dedicated accounts for administrative functions, separate from everyday accounts.
  • Where practical, separate machines for different security zones.

If a dedicated machine is not possible, at least restrict internet access and email on any device that connects to the control network.

Harden the configuration

Apply a baseline to each workstation, in coordination with the control system vendor, who may certify specific configurations.

  1. Remove unneeded software and disable unused services.
  2. Use individual named accounts with least privilege instead of shared administrator logins.
  3. Enable disk encryption on portable machines.
  4. Apply application allowlisting where practical, so only approved software runs.
  5. Turn on logging and forward logs to a central location.
  6. Keep security software current, using approaches compatible with your control systems.
  7. Set screen locks and session timeouts.

Patch with care

Workstations need updates, but patches may affect engineering software. Use a staged process: test on a spare machine, confirm compatibility with vendor guidance, apply during planned windows, and keep a rollback image. Keep a record of versions for every workstation.

Control access paths

  • Place engineering workstations in a protected network zone with firewall rules limiting what they can reach and what can reach them.
  • Require multi-factor authentication for remote access.
  • Do not allow direct internet access from the control network.
  • Review who has accounts and remove those no longer needed.

Manage removable media

USB drives are a classic route for malware into isolated networks. Set rules: use company-approved, scanned media only, prohibit personal drives, consider disabling USB ports where feasible, and use a dedicated scanning station for files entering the control environment.

Treat contractor and vendor laptops carefully

Outside laptops should not plug into the control network by default. Options include:

  • Providing a company-owned loaner laptop for vendor use.
  • Requiring a scan and compliance check before any connection.
  • Letting vendors use a controlled jump host instead of connecting directly.
  • Documenting what each visitor connected and when.

Ask vendors to confirm their laptops are patched, protected, and not used for unrelated personal activity.

Back up projects and configurations

Controller programs, configuration files, and project archives are crown jewels. Keep verified, versioned backups stored securely and separated from the control network. Knowing exactly what the approved program looks like lets you detect unauthorized changes and recover quickly.

Monitor changes

Log downloads to controllers and compare running logic with baselines where tools allow. Alert on unexpected program changes, new devices, and logins outside normal hours. Record who performed each maintenance task, linked to a work order.

Physical security

Portable engineering laptops get lost or stolen. Use encryption, locking cables where appropriate, and secure storage. If a laptop with project files and credentials is lost, treat it as an incident: change passwords and review what the device could access.

Quick checklist

  1. Dedicate machines to engineering use.
  2. Apply a hardened baseline.
  3. Use named accounts and MFA.
  4. Patch in a tested, scheduled way.
  5. Restrict removable media.
  6. Keep vendor laptops out of the control network unless controlled.
  7. Back up programs and compare them to baselines.
  8. Log and review activity.

How Ironfield Cyber helps

Ironfield Cyber helps industrial and energy operators harden engineering workstations, design vendor access, and set up backups and monitoring that respect operational constraints. If your technicians' laptops have free run of the control network, we can help you tighten that carefully.