USB Drives and Laptops in Control Rooms: Rules Operators Can Follow

Removable media and maintenance laptops are a classic path into control systems. These practical rules help operators keep them in check without slowing work.

3 min readBy Ironfield Cyber Team

Control rooms and plant floors rely on a steady stream of small, ordinary actions: a technician plugs in a USB drive to load a configuration, a vendor connects a laptop to update a controller, an engineer carries files to an isolated machine. Each is routine, and each is a potential way for malware to reach systems that were never meant to touch the internet.

The aim is not to ban these tasks, which would stop work, but to give operators clear and practical rules.

Why this path matters

Many control networks are separated from business networks and the internet, and people assume that makes them safe. But removable media and portable computers cross that boundary every day. A drive used on a home computer, then on a laptop at another site, then on a workstation in the control room can carry whatever it picked up along the way.

The same applies to vendor laptops. They may have been connected to many customers' networks, and you have little visibility into their condition.

Rule 1: Know what is allowed

Write a one-page policy, in plain language, stating:

  • Which removable media may be used
  • Who may use it
  • Which systems may accept it
  • What must happen before it is connected

Make the policy short enough that someone will read it. Post it where the work happens.

Rule 2: Use company-owned, labeled media

Employees should not use personal flash drives in control systems. Instead:

  1. Purchase a small number of dedicated drives for control system use.
  2. Label them clearly with an ID and the system they serve.
  3. Keep them in a locked drawer or cabinet.
  4. Keep a simple checkout log.

Do not use these drives on ordinary office or home computers.

Rule 3: Scan before use

Set up a dedicated scanning station, an isolated computer with up-to-date security software, where every drive is checked before it goes into a control system. Consider having a kiosk-style tool that can check media and report results. The scan does not guarantee safety, but it blocks a lot of known threats.

For files received from vendors, prefer a controlled transfer method over loose media where practical, with checks done on a separate machine first.

Rule 4: Control maintenance laptops

A laptop used to program and maintain controllers deserves special treatment.

  • Dedicate laptops to control system work, with no email or general browsing
  • Keep operating systems and software updated according to your tested patch process
  • Use disk encryption in case the device is lost
  • Require strong, unique logins
  • Keep the engineering software and project files under change control
  • Store laptops securely when not in use

Rule 5: Vendor devices need a checkpoint

When a vendor arrives with their own equipment:

  1. Confirm the visit was scheduled and who approved it.
  2. Ask whether their laptop has current security software and whether it is used for other customers.
  3. Where possible, connect it to an isolated test network first, or scan it.
  4. Have an employee supervise the work.
  5. Record what was connected, when, and what changed.

Do not let a rushed schedule remove these steps. A vendor who refuses reasonable precautions is a risk to disclose to management.

Rule 6: Disable what you do not need

Many workstations and controllers have USB ports enabled by default. Where operations permit, disable unused ports through system settings, or use port locks or blockers. Restrict autorun so that a drive does not execute software automatically.

Rule 7: Train for judgment

Rules fail when staff do not understand why they exist. Include in training:

  • A found drive in the parking lot should never be plugged in
  • Report any odd behavior after connecting media
  • It is acceptable to say no to a request that bypasses procedure
  • Whom to call when unsure

Rule 8: Keep records and review

Consider a hypothetical small utility with two control rooms and four technicians. A simple log noting the date, drive ID, person, and system connected would take seconds per event but could be invaluable if a problem later appears. Review the log monthly and check that drives are accounted for.

When something goes wrong

If you suspect that media or a laptop introduced malware, disconnect the affected system from the network if that is safe to do, notify operations leadership and your IT security contact, preserve the device rather than wiping it, and follow your incident response plan. Coordinate with operations before shutting anything down, since safety and process stability come first.

Where Ironfield Cyber helps

Ironfield Cyber works with industrial and energy operators on practical OT security awareness, including policies for media, maintenance laptops, and vendor access. If you want help turning these ideas into a short procedure your technicians will use, we can work with your operations and IT teams.