Vendor Laptops and HMIs: Keeping Plant Systems Clean

Engineering laptops and operator stations are often the weakest link in industrial networks. Learn simple rules to keep them clean and under control.

3 min readBy Ironfield Cyber Team

In most industrial environments, the most sensitive computers are not the controllers. They are the laptops, operator stations and engineering workstations that talk to them. A vendor's programming laptop that visited a dozen customer sites last month may carry malware from any of them. An operator station used to check email and browse the web is a standard foothold for attackers. Good control system security depends heavily on how these ordinary machines are handled.

Why these machines matter

Controllers generally do what they are told. The software on an engineering workstation can tell them to do almost anything, including changing logic and settings. An attacker who controls that workstation inherits that authority. Operator stations, often called HMIs, show the process and send commands, so they deserve similar care.

Many of these systems run older versions of Windows because the application requires it, and updates are not always easy. That makes disciplined handling of what touches them even more important.

Rules for vendor and contractor laptops

Outside parties are often essential. Set clear expectations before they arrive.

  1. Advance notice: vendors schedule visits and identify who is coming and what work will be performed.
  2. Approved devices only: a vendor laptop connects only after meeting your minimum requirements.
  3. Scan before connecting: use a dedicated scanning station or documented procedure to check laptops and removable media for malware before they join the control network.
  4. Supervision: a company employee accompanies the work or approves each connection.
  5. Limited connection points: use designated ports or isolated segments for vendor access instead of plugging into any available switch.
  6. Records: log who connected, when, to what and what changed.
  7. After the visit: verify that temporary accounts and settings are removed, and compare controller programs against known-good backups.

Put these rules in contracts and purchase orders so they are not a surprise.

Rules for your own engineering workstations

Dedicate them to their job

Do not use engineering workstations for email, general web browsing, personal use or entertainment. Each additional use adds risk.

Control accounts

Use named user accounts, not a single shared administrator login. Remove or disable accounts for people who no longer need access. Store credentials in a password vault.

Manage software

Maintain a list of approved software and versions. Remove unneeded programs. Where vendor guidance allows, apply security updates on a regular schedule after testing, and document exceptions where a patch cannot be applied.

Protect the data

Keep current backups of project files, controller programs and workstation images, stored offline or in a protected location. Test that the workstation can be rebuilt from the image.

Secure the physical device

Laptops should be encrypted when the application allows it, stored in a locked place and not left unattended in vehicles.

Rules for operator stations

  • Remove or disable email, web browsers and file sharing that are not required for operations.
  • Restrict removable media. Use a controlled, scanned drive for transfers, and disable automatic running of files.
  • Lock screens and use named logins where operations can support it, with a plan for emergencies and shift changes.
  • Limit remote connections to approved methods with multi-factor authentication.
  • Place a firewall between the stations and the corporate network.

Handle removable media with care

USB drives have been a classic route for malware into isolated networks. Ban personal drives. Use labeled, company-owned drives for specific purposes, scan them before and after use and keep them in a controlled location. Consider disabling unused ports where it does not affect operations.

Document and review

Maintain a register of every workstation and HMI: location, purpose, operating system, key software, owner and last backup date. Review it twice a year. Look for systems that no one can account for, since forgotten machines are common weak points.

Prepare for the bad day

If a workstation is suspected of compromise, decide in advance who is called, whether the machine is disconnected from the network and how operations proceed manually if needed. Practice this in a tabletop exercise with operations present.

Frameworks to lean on

General guidance from CISA on industrial systems and concepts from ISA/IEC 62443 emphasize controlling access, hardening systems and managing change. If you are subject to NERC CIP or pipeline security directives, similar topics, such as transient devices and removable media, appear in those requirements in general terms.

Next step

Ironfield Cyber helps operators write simple vendor access rules, harden workstations and set up scanning procedures that crews will actually follow. If you would like a checklist tailored to your site, we can build one with your controls staff.