Skip to main content

IT security

What is SCADA?

SCADA systems monitor and control industrial processes. See why OT security demands a different approach than IT, and what NIS2 requires.

In short

SCADA (Supervisory Control and Data Acquisition) is the type of control system that monitors and controls industrial processes: production lines, waterworks, energy plants, ventilation and everything else where software controls physical equipment.

The system collects measurements from sensors and PLCs out in the plant, displays them in the control room and lets operators control pumps, valves and motors. SCADA belongs to OT (Operational Technology), which differs fundamentally from classic IT: The equipment lives for decades, can rarely be patched continuously, and availability comes before everything else, because an outage stops production or supply.

At the same time, OT environments are increasingly connected to the IT network and thereby exposed to attacks they were never designed to withstand. NIS2 now sets explicit requirements for security in precisely these environments. MI Support IT helps Danish manufacturing and utility companies secure their industrial IT.

Back to the glossary

What is SCADA?

SCADA stands for Supervisory Control and Data Acquisition and is the umbrella term for the systems that monitor and control industrial plants. A SCADA system typically consists of sensors and PLCs (programmable logic controllers) out by the machines, a network that collects the data, and operator screens in the control room where the process is monitored and controlled. SCADA is the backbone of everything from food production and pharmaceuticals to waterworks and district heating.

What does a SCADA system control?

Everything where software meets physical equipment:

  • Production: line speeds, temperatures, pressures, dosing and quality measurements.
  • Utilities: pumps and valves in water, heating and energy plants.
  • Buildings: ventilation, cooling and access systems in larger properties.
  • Logistics: conveyor belts, cranes and automated warehouses.

The common denominator: If the system fails, it is not just data that stops. The physical process stops or runs out of control. That is why security in these environments is about more than confidential data.

IT vs. OT: why does OT security demand a different approach?

Classic IT security prioritises confidentiality first; OT (Operational Technology) prioritises the other way round: Availability is everything. That changes the rules of the game:

  • Lifespan: A production line is depreciated over 15-30 years. The control systems often run on operating systems that went out of support long ago.
  • Patching: You do not simply restart a waterworks to install updates. Maintenance windows are few and expensive.
  • Protocols: OT equipment speaks protocols (Modbus, PROFINET and others) with no built-in encryption or authentication. They trust everyone on the network.
  • Consequence: A compromised spreadsheet is annoying; a compromised valve controller can be dangerous.

The solution is therefore rarely "patch everything", but segmentation: a sharp separation between IT and OT networks with firewalls and controlled crossings, so a ransomware attack on the office network cannot reach production.

SCADA and NIS2

NIS2 covers precisely the sectors where SCADA is everyday reality: energy, water, wastewater, food and the manufacturing of critical products. The directive requires risk management that covers the entire environment, including OT, along with incident reporting and supplier management. For many manufacturing companies, the OT side is the weakest point in their NIS2 work, because responsibility has historically sat with production rather than with IT. The first step is a complete overview: What equipment exists, what is it connected to, and who has access?

Typical vulnerabilities in industrial networks

The same findings recur in security reviews: a flat network with no separation between IT and OT; supplier remote access left open all year round; outdated operating systems with no compensating protection; default passwords on PLCs and HMI panels; and no overview of what is on the network in the first place. None of these require sophisticated attackers to exploit, and all can be remedied with well-known means: segmentation, managed remote access, monitoring and a contingency plan that also covers production.

How MI Support IT can help

MI Support IT specialises in industrial IT security: mapping the OT environment, segmentation, secure remote access and NIS2 readiness for Danish manufacturing and utility companies. Contact us if your production runs on a network no one has looked at critically in years.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.