Industrial sites rely heavily on wireless: radios linking remote wells or pump stations, Wi-Fi in control buildings and yards, Bluetooth on instruments, cellular modems on tanks and meters. Wireless solves real problems where trenching cable is impractical, but it also removes the physical barrier that once protected many industrial networks. Anyone within range, sometimes miles away, can attempt to listen or connect.
Securing wireless starts with knowing what you have and ends with controlling who can join.
Why wireless is a special concern
- Signals travel beyond fences and property lines
- Older industrial radios and protocols may lack encryption or authentication
- Default settings and shared passwords are common
- Devices installed years ago may have been forgotten
- Contractors and vendors may add wireless equipment without telling operations
Step 1: Find what is out there
You cannot secure unknown devices. Build an inventory:
- Walk the site and note antennas, access points, modems and wireless instruments.
- Review purchasing and project records for wireless equipment installed over the years.
- Use a wireless survey to detect access points and other transmitters. Operators should coordinate with operations staff to avoid interference with sensitive equipment.
- Ask vendors and integrators what they installed and what remote access they maintain.
- Record details: location, model, frequency or type, owner, encryption settings and what it connects to.
Look especially for unauthorized devices, such as a personal hotspot or a wireless bridge someone added for convenience.
Step 2: Secure Wi-Fi
- Use modern encryption, such as WPA3 where supported, or WPA2 with a strong passphrase
- Avoid shared passwords for large groups, and change them when people leave
- Prefer enterprise authentication with individual credentials, where practical
- Disable older, weak protocols and features such as WPS
- Separate guest and contractor Wi-Fi from control networks
- Hide nothing behind obscurity alone, since hidden network names offer little protection
Do not extend Wi-Fi from the control network to areas where it is not needed. Coverage in a parking lot is exposure.
Step 3: Secure industrial radios and links
Check encryption and authentication
Ask the manufacturer whether your radio systems support encryption and authentication, and whether you have enabled them. Older equipment may need firmware updates or replacement.
Change defaults
Replace default passwords and keys. Remove default network names that identify the manufacturer or location.
Limit what a link can reach
A radio link to a remote site should connect only to the equipment it needs. Use firewalls or access controls so a compromised link does not open the entire control network.
Plan for aging equipment
If a radio cannot be secured, plan to replace it, and in the meantime, add compensating controls such as network segmentation and monitoring.
Step 4: Handle Bluetooth and short-range wireless
Technicians often use Bluetooth or similar links to configure instruments in the field. Treat these as administrative access:
- Disable wireless configuration when not needed
- Require pairing codes or authentication
- Keep firmware current
- Restrict who may configure devices, and log the work if possible
Step 5: Cellular modems and remote terminals
Cellular connections reach critical equipment from anywhere. Make sure:
- Devices do not have public internet addresses that anyone can scan.
- Private networking or VPN-style connections are used where available.
- Default credentials are changed.
- Firmware is updated according to vendor guidance.
- SIM cards are tracked, and lost devices can be disabled.
Step 6: Monitor and review
- Review wireless logs and alerts for unknown devices or repeated failed connections
- Repeat wireless surveys periodically
- Include wireless in change management so new equipment is approved and documented
- Remove devices that are no longer needed
Governance
Assign someone to own wireless on the site. Set a policy that no wireless device may be added to the control environment without approval. Require vendors to disclose any wireless equipment they install. Include wireless findings in your risk reviews and incident response plans.
A hypothetical example
Consider a hypothetical oilfield services yard with a Wi-Fi network installed years ago by an integrator. It uses a shared passphrase known to dozens of people, including former contractors, and it connects directly to the control network. Replacing the passphrase, adding individual authentication and separating the wireless network from controls reduces the exposure without major cost.
Getting started
Begin with a site walk and an inventory, then fix the highest-risk items: default credentials, unencrypted links and Wi-Fi that reaches into the control network. Ironfield Cyber helps operators and energy services companies survey wireless environments, prioritize fixes and design secure connectivity that respects operational needs. If you are not sure what is broadcasting from your sites, we can help you find out.