Many industrial incidents have started with something ordinary: a contractor plugs in a laptop to update a controller, an engineer uses a thumb drive to move a file, a technician connects a phone to charge. Each of these crosses a boundary between the outside world and your control environment. Without a policy, nobody checks what crossed.
Transient devices and removable media are hard to avoid in industrial settings. Vendors need to service equipment, and air-gapped systems often rely on physical media for updates. The goal is not to ban them. It is to control them.
Why these devices are risky
- Vendor laptops visit many customer sites and may carry malware from any of them
- USB drives can hold malicious files and automatically execute code on some systems
- Personal phones and tablets are often connected without thought
- Old operating systems on control equipment cannot defend themselves
- Staff may feel pressure to get the job done quickly
Principles for a practical policy
- Know what comes in. Every outside device and drive should be identified and approved.
- Scan before use. Check devices and media in a safe place before they touch the control network.
- Limit what is allowed. Fewer approved drives and devices means fewer surprises.
- Record and review. Keep a log of who connected what, when and why.
- Make the right way the easy way. Provide tools and stations so people can comply without delays.
Vendor and contractor laptops
Before the visit
- Require the vendor to state what work they will do and what access they need
- Ask whether their laptop has current updates, endpoint protection and encryption
- Agree on the connection method and the network segment they may use
- Give them the minimum access for the minimum time
On arrival
- Verify the technician's identity and authorization
- Prefer to connect vendor laptops to an isolated network segment rather than directly to controllers
- Consider providing a company-managed laptop or a clean jump host for sensitive work, where the vendor remotes into the environment rather than bringing a device
- Scan the laptop where practical before connection
During and after
- Supervise the work, or at least log it
- Do not allow vendors to leave behind devices or software unless approved
- Collect updated configuration backups after changes
- Disconnect and remove temporary access when the work ends
Removable media
Reduce the need
- Use controlled file transfer tools or a staging server instead of ad hoc drives
- Provide one or two company-owned, labeled and encrypted drives used only for approved transfers
- Disable USB ports on devices that do not need them, where this will not disrupt operations
Control what remains
- Prohibit personal drives on control systems.
- Label approved drives and keep them in a locked location.
- Scan drives on a dedicated, isolated workstation before use.
- Format or wipe drives on a schedule.
- Track drives by serial number and assign responsibility.
Consider a scanning kiosk
A standalone computer that scans media for malware before it enters the control environment is a practical, relatively low-cost safeguard. Keep it updated, isolated from the production network and clearly marked.
Phones, tablets and chargers
Phones plugged into control workstations to charge can transfer data. Provide charging stations separate from computers, and tell staff and visitors not to connect personal devices to control systems.
Handle visitors and shift changes
Add short signage and a verbal reminder in orientation. Operators and technicians should know that asking "what is that device?" is welcome, not rude.
Write a one-page policy
Include:
- Which devices and media are permitted, and who approves them
- Required checks before connection
- Where vendors may connect and how
- Logging and review expectations
- Consequences and a path for reporting accidental violations
Make exceptions explicit and temporary, with documentation.
Train and test
Walk operators and maintenance staff through the policy. Run a simple test: have someone request to connect an unapproved drive and see whether the process holds. Use the result to improve training, not to blame.
A hypothetical example
Consider a hypothetical gas compressor station where an integrator regularly connects a laptop directly to the control network. The laptop has also been used at other customers and has not been updated in months. Introducing a dedicated vendor port on an isolated segment, a quick scan procedure and a log of visits reduces risk without slowing down maintenance.
Putting it into practice
Ironfield Cyber helps operators and energy services companies write practical policies for transient devices, set up scanning stations and design vendor access that is workable for technicians. If you want a policy your operators will follow, we can help you draft and test it.