• Download
  • Products
    • Product Highlights
      • DataHub Smart MQTT Broker
      • DataHub IoT Gateway
      • DataHub OPC Gateway
      • DataHub service for Azure
      • DataHub OPC Bridge
      • OPC DataHub
      • DataHub WebView
      • DataHub Modbus OPC Server
    • Tunnellers
      • DataHub UA Tunneller
      • DataHub DA Tunneller
      • DataHub Tunnel A&E
      • DataHub Modbus Tunneller
      • DataHub DDE Tunneller
      • Individual Features
        • Redundancy
        • Data Diode Mode
        • Monitoring
    • Historians
      • Connect to InfluxDB
      • Connect to Amazon Kinesis
      • Connect to AVEVA Historian
      • Connect to AVEVA Insight
      • Connect to AVEVA PI
      • Connect to RESTful Systems
      • Connect to Kafka
      • Connect to ODBC
      • Connect to Azure Event Hubs
      • Connect to OPC Classic HDA
    • Notifications
      • Alarm and Notification
      • Email / SMS
      • OPC A&E support
      • OPC UA A&C support
    • Excel and DDE
      • DataHub Add-In
        for Microsoft Excel
      • DDE / Excel
    • Loggers
      • DataHub OPC Logger
      • DataHub Modbus Logger
  • Purchasing
    • How to Purchase
    • Request a Quote
    • Feature Matrix
    • Software Subscription Plan
    • Maintenance Support Plan
    • Educational Program
  • Learning Hub
    • Industries & Use Cases
      • Wind & Solar
      • Conventional Energy
      • Oil & Gas
      • Minerals & Mining
      • Manufacturing
      • Food & Beverage
      • Pharma & Healthcare
      • System Integration
      • Machines & Tools
    • Knowledge Center
      • Videos
      • Webinars
      • How-To
      • Case Studies
      • White Papers
      • Essential Guides
        • MQTT & Sparkplug Essentials
        • DataHub Security Essentials
    • Connecting
      • Industrial AI
      • Industrial IoT
      • Secure OT to IT
      • OPC
      • Historian
      • MQTT
        • Sparkplug
      • Database
      • Modbus
      • Excel
      • Web
      • Embedded
      • Open APIs
      • DHTP
      • Architecture
  • Support
    • FAQ
    • Documentation
    • Release Notes
    • Technical Specifications
  • About
    • Partners
    • Customers
    • Testimonials
    • Privacy Policy
    • Terms of Use
    • Legal Notices
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Download
  • Products
    • DataHub Smart MQTT Broker
    • DataHub IoT Gateway
    • DataHub OPC Gateway
    • DataHub service for Azure
    • DataHub OPC Bridge
    • OPC DataHub
    • DataHub WebView
    • DataHub Modbus OPC Server
    • Tunnellers
      • DataHub UA Tunneller
      • DataHub DA Tunneller
      • Tunnel A&E
      • DataHub Modbus Tunneller
      • DataHub DDE Tunneller
    • Historians
      • Connect to InfluxDB
      • Connect to Amazon Kinesis
      • Connect to AVEVA Historian
      • Connect to AVEVA Insight
      • Connect to AVEVA PI
      • Connect to RESTful Systems
      • Connect to Kafka
      • Connect to Azure Event Hubs
      • Connect to ODBC
      • Connect to OPC Classic HDA
    • Notifications
      • Alarm and Notification
      • Email / SMS
      • OPC A&E support
      • OPC UA A&C support
    • Excel and DDE
      • DataHub Add-in for Microsoft Excel
      • DDE / Excel
    • Loggers
      • DataHub OPC Logger
      • DataHub Modbus Logger
      • Monitoring
    • Individual Features
      • Redundancy
      • Data Diode Mode
      • Monitoring
  • Purchasing
    • How to Purchase
    • Request a Quote
    • Feature Matrix
    • Software Subscription Plan
    • Maintenance Support Plan
    • Educational Program
  • Learning Hub
    • Industries & Use Cases
      • Wind and Solar
      • Conventional Energy
      • Oil & Gas
      • Minerals & Mining
      • Manufacturing
      • Food and Beverage
      • Pharma and Healthcare
      • System Integration
      • Machines and Tools
    • Knowledge Center
      • Videos
      • Webinars
      • How-to
      • Case Studies
      • White Papers
    • Essential Guides
      • MQTT and Sparkplug Essentials
      • DataHub Security Essentials
    • Connecting
      • Industrial AI
      • Industrial IoT
      • Secure OT to IT
      • OPC
      • Historian
      • MQTT
        • Sparkplug
      • Database
      • Modbus
      • Excel
      • Web
      • Embedded
      • Open APIs
      • DHTP
      • Architecture
  • Support
    • FAQ
    • Documentation
    • Release Notes
    • Technical Specifications
  • About
    • Partners
    • Customers
    • Testimonials
    • Privacy Policy
    • Terms of Use
    • Legal Notices
Network security for OT data

Network security is not enough for OT data

Everyone agrees network security is essential for IT systems. And yet, securing OT (operational technology) networks is even more critical. One successful exploit on a production network might halt production, incur huge costs, and even put lives at risk. For OT systems, a secure network is essential—but that’s not enough anymore. There’s still the question of data security.

Before the days of Industry 4.0, Internet of Things, and digitalization, it was fairly simple to secure OT networks and data—just disconnect them, by air gap if need be. But that is no longer an option for any company that wants to stay competitive. The modern enterprise needs secure access to data from OT to increase efficiency and cut production costs. The good news is that with the right approach, secure access to OT data does not have to be overly complicated or costly. Whatever level of network security you have, there are easy and affordable ways to access your OT data securely.

Data security: different from network security

Such affordability is possible because data security is different from network security. Although data security can be implemented alongside network security, and be fully compatible with it, the goals of each are not exactly the same. The difference is a little like home security.

Running a system without network security is like leaving a door open, allowing anyone to enter your house. Unwanted visitors can steal things or hold your family members hostage for ransom. You’re also exposed to viruses from any infected person who walks in.

Network Security Open door house analogy

Securing the network

To secure the network, a company might implement zero-trust network access—at significant cost. Such a solution often uses VPNs to restrict network access to a limited number of authorized people. Using a VPN is like allowing only invited guests with a key to enter your house. These guests can still be carrying unwanted viruses that might infect your household. A VPN that extends from the IT network to OT simply extends the security perimeter to enclose OT. Should anyone in IT receive a phishing email or plug in a thumb drive with a virus on board, the malicious code could easily propagate to OT.

Network security VPN shared key house analogy

An invisible mail slot

For data access, a better solution—which is both cost effective and secure—is to simply close the network to everyone and set up secure data connections. It’s like pushing open an invisible mail slot in your door and exchanging messages with an authorized mail carrier. Nobody enters the house to bring in a virus or hold your family members hostage. When you close the mail slot it blends back in with the door. Only the mail carrier knows it’s there and only they can drop off or pick up messages.

Network security invisible mail slot house analogy

For industrial systems, the invisible mail slot is an outbound firewall port at the plant. The mail carrier is typically a tunnelling application or MQTT broker running on-site or in a DMZ. If you are using a DMZ, the IT side can implement the same mail slot interface–and keep all IT inbound firewall ports closed as well. Using a DMZ is recommended by the EU’s NIS 2 Directive and NIST SP 800-82 as the best way to segregate OT and IT networks. Each network must be secure, and any data connection between them must also be secure. Network security and data security should work hand in hand.

Network security OT to IT diagram

Viable options

Whatever level or type of network security you deploy, you need the right software and services to gain secure access to your data. If you simply need to isolate your OT system from IT or the cloud, you can use MQTT or Sparkplug to make outbound connections while keeping all inbound firewall ports closed. Some tunnel/mirroring software, such as Skkynet’s Cogent DataHub, can do this and more. Unlike MQTT, this kind of well-designed tunnel/mirroring solution can pass data seamlessly across a DMZ in both directions, maintaining the connection status and data quality information at every step.

To make an even more secure connection and ensure one-way data flow, you can use a data diode. This is a hardware device that allows and enforces only one-way communication, and prevents any kind of message from the destination getting back to the source. Some tunnel/ mirror solutions are fully compatible with data diodes, and can even be used to aggregate data sources on the sending side or to distribute data to various clients on the receiving side.

Working together

The thing to remember is that network security and data security are both important. They may be implemented separately, but they should work together as one unit. No matter what level or type of network security you have, Skkynet provides the technology and know-how you need to fully integrate it with data security.

Download White Paper (PDF)
Share this entry
  • Share on Facebook
  • Share on X
  • Share on WhatsApp
  • Share on LinkedIn
  • Share by Mail

Learning Hub Posts

  • Fractal Unified Namespace — Frequently Asked Questions
  • webinar-OT-network-segmentation
    OT Network Segmentation Webinar Hosted by MAC Solutions
  • webinar-iiot-world-energy-panel
    IIoT World Energy Day: Extending Grid Capacity with IIoT and AI: From Data to Capital Decisions
  • UNS-white-paper-featured-image
    Stop Unifying Everything
  • How to access process data through a Data Diode
    How to Access Process Data Through a Data Diode
  • Cogent DataHub Service for Azure
    Cogent DataHub Service for Microsoft Azure from Skkynet
  • Secure OPC networking: OT to IT and the Cloud webinar
    Webinar: Secure OPC networking – OT to IT and the Cloud
  • How to connect OPC UA to OPC DA featured image
    How to convert OPC UA to OPC DA
  • Network Security is not enough for OT Data
  • best-practices-OT-to-IT-series-featured-image
    Best Practices: OT to IT
  • how-to-video-redundancy-featured-image
    How to Configure Redundancy
  • for-mqtt-smarter-is-better banner
    White Paper: For MQTT Smarter is Better
  • Use Case: Wind Farm Access featured image
    Use Case: Wind Farm Access
  • DataHub Apache Kafka title card
    New Historian Connections for DataHub Version 11
  • DataHub WebView Pages and Solutions title card
    WebView Enhancements for DataHub version 11
  • DataHub Security Model title card
    New Security Model for
    DataHub version 11
Cogent DataHub footer logo white
  • Download
  • Products
  • Purchasing
  • Learning Hub
  • Support
  • About
  • Back to Top
  • LinkedIn iconTwitter iconYouTube icon

Skkynet
302-2233 Argentia Road
Mississauga, ON L5N 2X7

International: 1-905-702-7851
US toll free: 1-888-702-7851

[email protected]
[email protected]
[email protected]
[email protected]

© 2026 Skkynet | All rights reserved | Legal notices
Scroll to top Scroll to top Scroll to top

We are using cookies to give you the best experience on our website.

You can find out more about which cookies we are using or switch them off in .

Cogent DataHub Logo
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

3rd Party Cookies

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping this cookie enabled helps us to improve our website.

Cookie Policy

More information about our Cookie Policy