What sits in the supervisory layer
SCADA covers the systems operators and engineers work with rather than the controllers themselves. Human-machine interfaces render the process and accept operator input. Historians record time-series process data and are frequently the single system permitted to talk to both the plant and the corporate network. Engineering workstations carry the vendor programming software that can rewrite controller logic. Wide-area telemetry links connect dispersed sites over links that were never intended to be reachable from anywhere else.
Every one of those is a general-purpose computer or a routable network path, which makes the supervisory layer far more familiar to an attacker than a controller is. It runs an operating system they know, software with published vulnerabilities, and accounts that can be phished.
Remote access is the dominant entry path
Industrial estates accumulate remote access. Vendors need it for support, integrators need it during commissioning, and on-call engineers need it at three in the morning. It arrives as VPN, as jump hosts, and frequently as commercial remote desktop tools installed to solve an immediate problem and never removed.
Signal reconstructs remote access sessions from network traffic and host telemetry rather than relying on an inventory that is always out of date. SSH, RDP, VNC, vendor VPN and tools such as TeamViewer and AnyDesk are all identified from what is actually on the wire, which surfaces the access paths nobody documented alongside the ones that were approved.
- Sessions reconstructed from observed traffic rather than from a declared inventory
- Authentication events collected from workstations, HMIs, jump hosts and firewalls
- Impossible-travel and first-seen-geography patterns applied to vendor accounts
- Off-hours engineering activity flagged against declared change windows
- Privileged-account session shape scored against its own history
Authentication telemetry, and what it reveals
The supervisory layer produces the kind of authentication telemetry an IT security team would recognise: logon successes and failures, account lockouts, privilege changes, account creation. Signal collects it from Windows Event Log, Syslog and SNMP alongside the network view, so an account created on an engineering workstation outside a change window is visible next to the traffic that account subsequently generated.
That pairing matters more in OT than in IT. A new account on a corporate laptop is routine. A new account on the machine that programs a safety controller is a finding, and it becomes an urgent one if the next thing it does is open a programming session.
Wide-area telemetry and the protocols that carry it
Dispersed operations, pipelines, water networks, distribution grids, depend on telemetry protocols carrying supervisory traffic over long distances: DNP3 and IEC 60870-5-104 above all. These were designed for constrained, private links and inherit the same absence of authentication as their plant-floor counterparts.
Signal decodes both, so a command carried across a telemetry link is visible as a command rather than as a byte count, and so unusual sequences are detectable against a learned baseline of what the link normally carries.
The historian is a bridge, and bridges are targets
A historian typically has a legitimate reason to communicate with both domains, which makes it the most valuable single foothold in many estates. Compromising it offers a path from the enterprise network towards the plant that does not require defeating segmentation, because the segmentation already permits the traffic.
This is where observed topology matters more than designed topology. Signal builds the conversation map from traffic actually seen, so what the historian genuinely talks to is visible rather than what the network diagram says it should. Zone-to-zone flow is then assessed against the segmentation policy, and crossings that were never authorised surface as findings.
Where supervisory findings meet the wider SOC
The supervisory layer is where IT and OT security genuinely converge, because the assets are IT assets sitting in an OT context. Signal feeds its findings into Spharaka Sphere so a phishing campaign against corporate users and an anomalous engineering workstation session are visible to the same team, in the same console, correlated rather than compared by hand across two tools.
Frequently asked questions
What is SCADA security?
SCADA security protects the supervisory layer of an industrial environment: human-machine interfaces, historians, engineering workstations and the wide-area telemetry links connecting dispersed sites. It sits above the control layer, and because those systems are general-purpose computers on routable networks, it is where most industrial intrusions begin.
Why is the engineering workstation such a high-value target?
Because it combines an ordinary attackable operating system with the vendor software and credentials needed to rewrite controller logic. Compromising one gives an attacker a legitimate path to change what the process does, without needing to defeat any industrial protocol.
How do you find undocumented remote access into an OT network?
By reconstructing sessions from observed traffic rather than trusting an inventory. Signal identifies SSH, RDP, VNC, vendor VPN and commercial remote desktop tools from what is actually on the wire, which surfaces the access paths installed to solve a problem years ago and never removed.
What makes a historian a security concern?
A historian usually has an approved reason to talk to both the plant network and the corporate network, so compromising it offers a path across the boundary that the segmentation policy already permits. That is why observed topology, what the historian actually communicates with, matters more than the designed diagram.
Are DNP3 and IEC 60870-5-104 secure?
Not inherently. Both were designed for constrained private telemetry links and carry supervisory commands without proving who sent them. Secure variants exist but the installed base largely does not use them, so monitoring the traffic and baselining what each link normally carries is what provides the assurance.
How does SCADA monitoring connect to enterprise security operations?
Signal passes its findings into Spharaka Sphere, so supervisory-layer activity is correlated with corporate telemetry in one console. That matters because the supervisory layer is precisely where an IT intrusion becomes an OT problem, and reviewing the two in separate tools is how the connection gets missed.
Part of the cluster
OT Cybersecurity
The pillar page for operational technology security.