In most industrial environments, the most sensitive computers are not the controllers. They are the laptops, operator stations and engineering workstations that talk to them. A vendor's programming laptop that visited a dozen customer sites last month may carry malware from any of them. An operator station used to check email and browse the web is a standard foothold for attackers. Good control system security depends heavily on how these ordinary machines are handled.
Why these machines matter
Controllers generally do what they are told. The software on an engineering workstation can tell them to do almost anything, including changing logic and settings. An attacker who controls that workstation inherits that authority. Operator stations, often called HMIs, show the process and send commands, so they deserve similar care.
Many of these systems run older versions of Windows because the application requires it, and updates are not always easy. That makes disciplined handling of what touches them even more important.
Rules for vendor and contractor laptops
Outside parties are often essential. Set clear expectations before they arrive.
- Advance notice: vendors schedule visits and identify who is coming and what work will be performed.
- Approved devices only: a vendor laptop connects only after meeting your minimum requirements.
- Scan before connecting: use a dedicated scanning station or documented procedure to check laptops and removable media for malware before they join the control network.
- Supervision: a company employee accompanies the work or approves each connection.
- Limited connection points: use designated ports or isolated segments for vendor access instead of plugging into any available switch.
- Records: log who connected, when, to what and what changed.
- After the visit: verify that temporary accounts and settings are removed, and compare controller programs against known-good backups.
Put these rules in contracts and purchase orders so they are not a surprise.
Rules for your own engineering workstations
Dedicate them to their job
Do not use engineering workstations for email, general web browsing, personal use or entertainment. Each additional use adds risk.
Control accounts
Use named user accounts, not a single shared administrator login. Remove or disable accounts for people who no longer need access. Store credentials in a password vault.
Manage software
Maintain a list of approved software and versions. Remove unneeded programs. Where vendor guidance allows, apply security updates on a regular schedule after testing, and document exceptions where a patch cannot be applied.
Protect the data
Keep current backups of project files, controller programs and workstation images, stored offline or in a protected location. Test that the workstation can be rebuilt from the image.
Secure the physical device
Laptops should be encrypted when the application allows it, stored in a locked place and not left unattended in vehicles.
Rules for operator stations
- Remove or disable email, web browsers and file sharing that are not required for operations.
- Restrict removable media. Use a controlled, scanned drive for transfers, and disable automatic running of files.
- Lock screens and use named logins where operations can support it, with a plan for emergencies and shift changes.
- Limit remote connections to approved methods with multi-factor authentication.
- Place a firewall between the stations and the corporate network.
Handle removable media with care
USB drives have been a classic route for malware into isolated networks. Ban personal drives. Use labeled, company-owned drives for specific purposes, scan them before and after use and keep them in a controlled location. Consider disabling unused ports where it does not affect operations.
Document and review
Maintain a register of every workstation and HMI: location, purpose, operating system, key software, owner and last backup date. Review it twice a year. Look for systems that no one can account for, since forgotten machines are common weak points.
Prepare for the bad day
If a workstation is suspected of compromise, decide in advance who is called, whether the machine is disconnected from the network and how operations proceed manually if needed. Practice this in a tabletop exercise with operations present.
Frameworks to lean on
General guidance from CISA on industrial systems and concepts from ISA/IEC 62443 emphasize controlling access, hardening systems and managing change. If you are subject to NERC CIP or pipeline security directives, similar topics, such as transient devices and removable media, appear in those requirements in general terms.
Next step
Ironfield Cyber helps operators write simple vendor access rules, harden workstations and set up scanning procedures that crews will actually follow. If you would like a checklist tailored to your site, we can build one with your controls staff.