SCADA
SCADA systems supervise and control distributed processes such as power grids, water networks and pipelines. Architecture, protocols and the security issues they bring.
Updated This page as Markdown
In short
SCADA (Supervisory Control and Data Acquisition) is a control system architecture for monitoring and controlling geographically distributed processes from a central control room: power grids, water and wastewater networks, pipelines, rail. It consists of a central SCADA server, HMIs, a historian, and remote terminal units or PLCs at the outstations, connected by protocols such as IEC 60870-5-104, DNP3 and Modbus that were designed without authentication.
What is SCADA?
SCADA stands for Supervisory Control and Data Acquisition: a control system architecture for monitoring and controlling processes that are spread over a large area from a central control room. Power grids, water and wastewater networks, gas pipelines, district heating and railway infrastructure run on SCADA. Operators see the state of the whole network on their screens, receive alarms and send commands such as opening a breaker or starting a pump.
A SCADA system has a central SCADA server (often called master or MTU), HMIs for the operators, a historian that stores process data, and field devices at the outstations: remote terminal units (RTUs) and PLCs that read sensors and drive actuators. Control room and outstations are connected over leased lines, radio, cellular and increasingly plain IP networks. The typical protocols are IEC 60870-5-104 in European energy and water utilities, DNP3 (IEEE 1815) in North America, Modbus everywhere, IEC 61850 inside substations and OPC UA towards enterprise systems.
Where is it defined?
SCADA is an architecture, not a standard. NIST SP 800-82 Rev. 3 describes SCADA, DCS and PLC-based systems and their security; IEC 62443-1-1 provides the terminology and places SCADA in the industrial automation and control system model. The protocols have their own standards: IEC 60870-5-104 for telecontrol over TCP/IP, IEEE 1815 for DNP3, and the IEC 62351 series for securing power-system protocols with TLS and application-layer authentication. For operators, SCADA falls under NIS2 Article 21 and, in Germany, under the KRITIS rules of the BSIG; the SCADA products themselves fall under the Cyber Resilience Act.
What it means in practice
Typical findings in SCADA environments, from utilities to industrial sites:
- Control room on the office domain. SCADA servers and HMIs are joined to the corporate Active Directory, so a phishing mail in the office is one hop from the control room.
- Shared operator accounts. HMIs run with one account that has never been changed because a logout would blank the screens.
- Unauthenticated telecontrol. IEC 60870-5-104 and DNP3 accept commands from any host that reaches port 2404 or 20000; the secure authentication extensions are not enabled because the RTUs do not support them.
- Outstations on the internet. Cellular modems and routers at remote sites with default passwords, reachable from the internet and visible in search engines for connected devices.
- Web HMIs with web vulnerabilities. Modern SCADA products ship browser-based HMIs, and they have the same injection, authentication and session problems as any web application. We test them as web applications, in a test environment.
- Historian as bridge. The historian database is reachable from the office network for reporting and, from there, from the control network.
Testing a SCADA system follows OT rules: passive capture of the telecontrol traffic first, configuration review of servers and firewalls, active tests only against test or staging systems, and no write commands to live outstations. Zyberum tests SCADA environments and the web and backend components around them, analyses RTU and PLC firmware in the lab, and monitors control networks with the Zyberdome managed SOC.
Common misunderstandings
SCADA is not a synonym for all industrial control; it is the supervisory layer. “Proprietary protocols protect us” is false: Wireshark dissectors and open-source clients exist for every common telecontrol protocol. And a SCADA network is not isolated because the diagram says so; the maintenance connection, the historian link and the cellular routers are the paths that attackers actually use.
FAQ
Frequently asked questions
What is the difference between SCADA and a DCS?
Geography and control style. A distributed control system (DCS) runs the closed-loop control of one plant, for example a refinery or a power station, with controllers close to the process. SCADA supervises many distant sites, such as substations or pumping stations, from one control room and sends setpoints and commands over wide-area links. In practice the two converge: modern SCADA products control plants, and DCS products supervise remote sites.
Is SCADA the same as a PLC?
No. A PLC is the controller at the process; SCADA is the layer above that collects data from many controllers and remote terminal units and lets operators supervise and intervene. A SCADA system typically talks to dozens or thousands of PLCs and RTUs.
Why are SCADA systems considered insecure?
Because the protocols that connect control room and outstations, such as IEC 60870-5-104, DNP3 and Modbus, carry commands without authentication, and because SCADA servers and HMIs run on Windows versions that stay in service for many years. Secure variants of the protocols exist (IEC 62351, DNP3 Secure Authentication) but are rarely enabled. The remedy is architecture: segmentation, protocol-aware filtering, hardened access paths and monitoring.
Sources
Related pages
- GlossaryOT SecurityOT security protects the operational technology that controls physical processes: PLCs, SCADA, HMIs, drives. How it differs from IT security and what typically fails.
- GlossaryPLC (Programmable Logic Controller)A PLC is the industrial computer that runs the control logic of a machine or process. How PLCs work, which standards apply and where their security typically fails.
- GlossaryModbusModbus is the simplest and most widespread industrial protocol: RTU over serial lines, TCP on port 502. How it works, why it has no security and how to protect it anyway.
- GlossaryKRITISKRITIS means critical infrastructures: facilities in Germany whose failure would cause supply shortages. Who counts, what the BSIG requires and what changed with NIS2.
- For your industryCybersecurity for Utilities and Critical Infrastructure: NIS2, KRITIS and OTWhat municipal utilities and KRITIS operators must do: BSIG duties after NIS2, BSI-KritisV thresholds, the OT attack surface and a first project without downtime.
- ServicesKeep production running when IT and OT converge.Security assessments, pentests and IEC 62443 consulting for PLC, SCADA and DCS. Protect production and critical infrastructure against cyberattacks.
