OT Cybersecurity for Industrial Control Systems in South Africa
Quick Answer: What Is OT Cybersecurity for Industrial Control Systems?
OT cybersecurity protects the controllers, industrial networks, HMIs, drives and safety systems that keep physical plant processes running — prioritising safety, availability and process integrity, not only data confidentiality. For South African mining, manufacturing, water and heavy-industry operations, an effective approach is typically built around IEC 62443-aligned architecture, protection for legacy equipment through compensating controls, network segmentation, passive monitoring rather than active scanning, and safety-first design for systems governed by safety instrumented systems (SIS).
In practice, this means secure industrial controllers such as Allen-Bradley ControlLogix 5580 and GuardLogix 5580 (TÜV Rheinland IEC 62443-4-2 SL1 certified), managed industrial switches such as the Stratix 5800, and Fortinet FortiGate next-generation firewalls for OT/IT segmentation. Staro Process Control, an authorised Rockwell Automation distributor and Fortinet OT security partner, provides the local engineering support South African industrial sites need to apply this architecture correctly.
Operational technology (OT) protects the automation layer that physically runs a plant — controllers, industrial networks, HMIs, drives and safety systems. For South African mining operations, manufacturing plants, processing facilities, utilities and other heavy industries, the growing connection between operational technology and enterprise IT creates significant advantages, but also introduces new cybersecurity risks.
A compromised office computer is a serious IT problem. A compromised industrial control system can potentially stop conveyors, interrupt pumping, alter control logic, disrupt production or interfere with safety-critical processes. For this reason, effective OT cybersecurity cannot simply copy traditional IT security practices — it must be engineered around the realities of the plant.
Why OT Cybersecurity Is Different From IT Security
Traditional IT cybersecurity places considerable emphasis on confidentiality, user information and data protection. Industrial control systems have additional priorities: safety, availability, process integrity and reliability.
A plant cannot necessarily restart a PLC, install an operating system update or actively scan every device simply because a security tool recommends it. Industrial environments may also contain equipment installed over many years — PLCs, HMIs, engineering workstations, industrial switches, drives and instrumentation from different technology generations — alongside modern connected devices that were never originally designed for today’s threat landscape.
The objective should therefore be defence in depth: multiple complementary layers that prevent one compromised device, account or network connection from exposing the entire plant.
Why IEC 62443 Matters in Industrial Cybersecurity
One of the strongest foundations for securing industrial automation and control systems is the ISA/IEC 62443 family of standards. Rather than treating an industrial site as one trusted network, IEC 62443 supports a structured approach involving secure components, controlled communication paths, access management and segmentation of industrial systems according to their function and risk.
For South African industrial facilities, this provides a useful framework when designing or modernising:
- PLC and control networks
- Safety control systems and safety instrumented systems (SIS)
- SCADA infrastructure
- Industrial Ethernet networks
- Engineering workstations and remote access
- IT/OT connections and industrial DMZs
- Plant-floor network zones
The goal is not simply to install a firewall. It is to create an industrial architecture where access between systems is intentional, controlled and appropriate to the process.
Secure the Control Layer With ControlLogix 5580
Cybersecurity should extend all the way down to the industrial controller. The Allen-Bradley ControlLogix 5580 family provides industrial control together with security functionality designed for modern connected automation environments.
Applicable ControlLogix 5580 controllers and firmware revisions are TÜV Rheinland-certified to IEC 62443-4-2 Security Level 1 when configured to Rockwell Automation’s specified security requirements. Rockwell documents digitally-signed controller firmware, role-based access control, and controller-based change detection and logging among the family’s native security capabilities, alongside support for CIP Security on compatible EtherNet/IP communications. For plants planning a larger controller upgrade, Staro’s ControlLogix 5590 L90 processor guide covers the newest generation of the platform.
This matters because the PLC is no longer an isolated piece of equipment. It may communicate with remote I/O, variable frequency drives, HMIs, SCADA platforms, historians, engineering workstations, maintenance systems, industrial servers and enterprise applications — so security at controller level adds another essential layer to the overall OT cybersecurity architecture.
CIP Security Adds Protection to Industrial Communications
Another important capability is CIP Security, which authenticates communicating devices and provides mechanisms for data integrity, authentication and confidentiality across compatible EtherNet/IP communications. Rockwell’s IEC 62443 guidance includes CIP Security as part of certain certified ControlLogix and GuardLogix configurations. Instead of assuming that every device connected to the industrial network can automatically be trusted, secure communications become part of the control-system design — an approach covered in more depth in our article on OT security with Rockwell Automation.
GuardLogix 5580 Combines Safety and Security
Cybersecurity becomes particularly important where automation and functional safety intersect. The GuardLogix 5580 platform allows standard and safety control to operate within the Rockwell Automation architecture while incorporating the same certified security functionality as ControlLogix 5580.
Rockwell documentation confirms that applicable GuardLogix 5580 firmware supports TÜV Rheinland IEC 62443-4-2 SL1 certification and includes digitally-signed controller firmware alongside centralised authentication and access-control capabilities. Staro provides Allen-Bradley support for PLC, HMI and drive projects, including ControlLogix and GuardLogix controller applications.
This makes security especially relevant in systems controlling equipment such as conveyors, crushers, pumps, process machinery, materials handling systems, manufacturing cells, rotating equipment and other hazardous industrial processes governed by a safety instrumented system. An OT cybersecurity strategy must never compromise the safety function merely to satisfy an IT security requirement — safety and cybersecurity need to be engineered together.
Industrial Network Segmentation Limits Cyber Risk
One of the most important themes in modern industrial cybersecurity is network segmentation. A flat industrial network allows a problem affecting one area to spread more easily into other systems. Instead, control environments can be separated into logical security zones, for example:
Enterprise IT → Industrial DMZ → Plant Operations → Process Area → Control Cell → Industrial Devices
Communication between these zones can then be restricted according to operational requirements, limiting unnecessary connectivity and making it significantly more difficult for an attacker or compromised device to move laterally through the plant.
FortiGate NGFWs for OT/IT Segmentation
Segmentation is most effective when the firewalls enforcing it understand industrial protocols, not only IT traffic. Fortinet FortiGate Next-Generation Firewalls are widely used at the industrial DMZ and between plant-floor zones to inspect OT traffic, enforce protocol-aware access policies, and give plants visibility into east-west communication between control cells.
Staro Process Control supports this layer directly as a Fortinet Operational Technology (OT) Security specialist, deploying FortiGate NGFWs alongside Rockwell Automation and Allen-Bradley hardware — so the same partner responsible for the control and network layer can also design and support the segmentation and firewall layer around it, mapped against frameworks such as NIST CSF 2.0.
Stratix 5800 for Secure Industrial Network Segmentation
The Allen-Bradley Stratix 5800 Managed Industrial Ethernet Switch is particularly relevant to this architecture. Developed using Rockwell Automation and Cisco technology, Stratix 5800 switches support Layer 2 switching and Layer 3 routing, enabling industrial networks to be divided into controlled network segments.
Rockwell specifically highlights segmentation as a way to create domains of trust and protect against unwanted network traffic. The Stratix 5800 uses Cisco IOS-XE and has obtained IEC 62443-4-2 certification. (For more on the wider Stratix managed-switch family, see our introduction to the Stratix 5400 industrial managed switch.)
For industrial plants, this means the network infrastructure itself becomes part of the cybersecurity strategy rather than simply transporting Ethernet traffic. A properly designed architecture can separate, for example, crushing and conveying systems, process plant control, utilities, safety systems, packaging lines, engineering workstations, production servers, third-party equipment and corporate IT connections — improving security without removing the connectivity modern production requires.
Where Stratix 5950 Fits in Existing Plants
Some existing industrial installations may still contain Stratix 5950 Security Appliances. The Stratix 5950 combined Cisco ASA Firewall and FirePOWER technology with industrial cybersecurity capabilities including access control, intrusion prevention, threat detection and Deep Packet Inspection — giving visibility into industrial communications and control over specific industrial protocol activity, rather than only basic IP addresses and ports.
However, Rockwell Automation discontinued the Stratix 5950 product family, with sale of new units ending on 1 January 2024. Plants with these devices already installed should treat them as part of their installed-base lifecycle and migration planning, rather than specifying the Stratix 5950 for a new project — new segmentation and threat-detection designs should be built around the Stratix 5800 and FortiGate NGFWs instead.
This is precisely where lifecycle planning becomes part of cybersecurity. It is not only about whether a device works today — plants must also understand whether it is supported, whether vulnerabilities can still be addressed, whether replacement equipment is available, and what happens if it fails.
How Do You Protect Legacy Industrial Control Systems?
This is particularly relevant in South Africa, where many mines and industrial facilities operate equipment with long service lives. Replacing every legacy PLC or industrial device is rarely practical.
A better approach often involves protecting older equipment through compensating controls such as:
- Network segmentation and restricted communication paths
- Industrial firewalls, including protocol-aware NGFWs at segmentation points
- Controlled engineering access and role-based permissions
- Secure remote-access architecture
- Network monitoring and configuration management
- Asset inventory, backups and recovery procedures
This allows plants to progressively improve cybersecurity without requiring an immediate plant-wide automation replacement.
Passive Monitoring Is Important in OT Networks
Another difference between IT and OT cybersecurity is how equipment should be assessed. Aggressive scanning techniques that may be acceptable on an office network can create unnecessary risk when used against sensitive or older industrial devices.
For this reason, passive network monitoring is often valuable in OT environments. Rather than continuously interrogating equipment, passive monitoring observes industrial network communications to identify devices, communication patterns and unusual behaviour — helping plants establish a baseline of what normal operation looks like, so unexpected communications become easier to identify.
For example, a PLC that normally communicates only with an HMI and remote I/O suddenly communicating with an unknown workstation should warrant investigation. This contextual understanding is one reason OT cybersecurity requires both cybersecurity expertise and industrial automation knowledge.
OT Cybersecurity Must Include Asset Visibility
A plant cannot adequately protect equipment it does not know exists, yet industrial networks often contain equipment installed during multiple expansions, upgrades and maintenance projects. An OT cybersecurity assessment should identify connected PLCs, safety controllers, industrial switches, HMIs, servers, drives, engineering stations, remote-access equipment, firmware versions, network connections and unsupported or obsolete devices.
Asset visibility creates the foundation for risk assessment, so plants can prioritise the systems where failure or compromise would have the greatest impact on production, safety or uptime. Staro has previously covered this risk-based approach in its guidance on OT endpoint security, while tools such as FactoryTalk AssetCentre help plants track controller changes, versions and backups — see securing industrial operations with FactoryTalk AssetCentre.
Cybersecurity Patching Must Consider Plant Availability
Cybersecurity advice often sounds simple: “install the latest updates.” Industrial environments are rarely that straightforward. Firmware and software changes may require compatibility verification, application testing, planned shutdowns, controller backups, recovery planning, OEM verification and process risk assessments.
Importantly, cybersecurity-capable hardware does not eliminate the need for lifecycle management. Rockwell Automation continues to publish security advisories and corrected firmware for industrial automation products, which is why plants need a process for monitoring vulnerabilities and determining when an update should be safely introduced, rather than assuming installed equipment remains secure indefinitely. Our guide to the top OT security challenges and how to address them looks at this balance between security and uptime in more detail.
A Practical OT Cybersecurity Strategy for South African Plants
Instead of approaching industrial cybersecurity as one major IT project, industrial organisations can build protection progressively — starting by understanding the plant, then strengthening the architecture in layers:
- Identify critical assets — determine which PLCs, SCADA systems, controllers, networks and production assets are essential to plant operation.
- Document the industrial network — understand which devices communicate, where IT and OT connect, and where remote access enters the environment.
- Assess legacy-system exposure — identify unsupported operating systems, outdated controllers and equipment that cannot support modern security functionality.
- Create network zones — separate operational areas according to process, criticality and security requirements.
- Control communication between zones — allow only the connections necessary for the industrial process, enforced with protocol-aware NGFWs at key boundaries.
- Strengthen authentication and access — restrict engineering access according to the user’s responsibilities.
- Introduce secure industrial components — technologies such as ControlLogix 5580, GuardLogix 5580, Stratix 5800 and FortiGate NGFWs can support stronger cybersecurity architectures where modernisation is appropriate.
- Monitor industrial communications — establish normal network behaviour and investigate deviations without destabilising critical equipment.
- Manage vulnerabilities and firmware — create an OT-appropriate process for evaluating security advisories, patches and firmware revisions.
- Test recovery — cybersecurity planning must include reliable backups, known-good configurations and procedures for restoring operations.
IEC 62443 and NIST CSF 2.0 Can Work Together
Industrial organisations do not necessarily need to choose one cybersecurity framework. IEC 62443 is particularly useful for the architecture and technical protection of industrial automation and control systems. The NIST Cybersecurity Framework 2.0 can complement this by helping organisations structure broader cybersecurity governance around activities such as identifying risk, protecting assets, detecting incidents, responding and recovering, and — new in version 2.0 — governing the programme itself.
For large mines, manufacturing groups and infrastructure operators, mapping a segmentation and firewall deployment against NIST CSF 2.0 while engineering the plant-floor architecture to IEC 62443 provides a more complete approach than treating cybersecurity as an isolated technology purchase.
OT Cybersecurity Is an Engineering Discipline
One of the most important principles for industrial organisations is that OT cybersecurity should not be separated from the automation system it protects. Installing security technology without understanding the process can create its own operational risks.
The cybersecurity architecture needs to account for controller communications, safety requirements, network traffic, redundancy, production schedules, engineering access, equipment lifecycle, maintenance practices and recovery requirements — which is why industrial cybersecurity requires cooperation between OT engineers, automation teams, IT cybersecurity specialists and plant management.
Strengthen Industrial Cybersecurity With Staro Process Control
Staro Process Control supports South African industrial organisations with Rockwell Automation and Allen-Bradley automation products, Fortinet OT security technology, and practical industrial engineering knowledge. Staro is an authorised Rockwell Automation distributor and a Fortinet Operational Technology (OT) Security specialist, providing access to both the controller/network hardware and the firewall/segmentation layer around it (Staro Process Control).
For organisations reviewing OT cybersecurity, Staro can help place individual products within the bigger architecture — from controllers and industrial networking to segmentation, asset visibility, lifecycle planning and secure automation infrastructure.
Reviewing your plant’s OT cybersecurity posture? Contact Staro Process Control to assess your industrial control and network architecture today.
Frequently Asked Questions (FAQs)
1. What is OT cybersecurity in an industrial control system?
OT cybersecurity protects the automation technology responsible for controlling physical processes, including PLCs, HMIs, SCADA systems, industrial networks, drives and safety systems. Its priorities are operational availability, process integrity, equipment safety and protection against unauthorised access or manipulation.
2. What is IEC 62443?
IEC 62443 is a family of international cybersecurity standards focused on industrial automation and control systems. It covers secure system design, network segmentation, security programmes and cybersecurity requirements for industrial components and systems.
3. How can legacy PLCs be protected from cyber threats?
Legacy PLCs can often be protected using compensating controls such as network segmentation, restricted communications, controlled engineering access, industrial firewalls, passive monitoring and secure remote-access systems, instead of immediately replacing every controller.
4. Are ControlLogix 5580 and GuardLogix 5580 controllers IEC 62443 certified?
Specified ControlLogix 5580 and GuardLogix 5580 controller and firmware combinations are TÜV Rheinland-certified to IEC 62443-4-2 Security Level 1 when implemented to Rockwell Automation’s certification requirements, with native features including digitally-signed firmware, role-based access control, change detection and logging, and CIP Security support.
5. How does the Stratix 5800 improve OT cybersecurity?
The Stratix 5800 provides managed industrial Ethernet switching with Layer 2 and Layer 3 functionality, allowing plants to segment networks into controlled areas. Built on Cisco IOS-XE technology, it is IEC 62443-4-2 certified and is the current recommended Stratix platform for new segmentation projects.
6. Is the Stratix 5950 Security Appliance still available?
No. Rockwell Automation discontinued the Stratix 5950, with sales of new units ending on 1 January 2024. Plants with an existing Stratix 5950 should treat it as part of installed-base lifecycle and migration planning, moving toward the Stratix 5800 and FortiGate NGFWs for new segmentation and threat-detection designs.
7. Does Staro Process Control supply Fortinet FortiGate firewalls for OT security?
Yes. Staro Process Control is a Fortinet Operational Technology (OT) Security specialist in addition to being an authorised Rockwell Automation distributor, supplying and deploying FortiGate Next-Generation Firewalls for industrial network segmentation alongside Allen-Bradley controllers and Stratix switches.
ELECTRICAL, CONTROL & INSTRUMENTATION PRODUCTS
Control Systems – By Allen Bradley
- Programmable Controllers (PLC)
- Industrial Safety
- Condition Monitoring
- Industrial Computers & HMI
- Variable Speed Drives
- Soft Starters
- MV Drives & Soft Starters
- Power Monitoring
- Industrial Low Voltage Control Gear
Connectivity, Upgrade & Migration – By Prosoft
- Remote Access
- Gateways
- Industrial Wireless
- Rockwell in Chassis
- Schneider in Chassis
- Siemens in Chassis
Surge Suppression
– By SineTamer
We are an Authorised Distributor for SineTamer products and solutions managing the quality of electrical power to devices and protecting the following circuits.
- AC & DC Circuits
- Control System Circuits
- Data & Telecoms Circuits
- 525V and 690V Volts
- Medium Voltage
Flow Meters
– By UPC
Electromagnetic Flow Meters
Turbine Flow Meters
Vortex Flow Meters
Ultrasonic Flow Meters
Woltman Type Water Meters
Water Meters
Analyzer
Dosing Pump
MECHANICAL PRODUCTS & SOLUTIONS
We supply and service the Valve, Pump and Pneumatics market from our various global partners.
Pumps
- Submersible
- End Suction, In Line
- Vertical Turbine
- Slurry Pumps
Valves
- Steam Traps
- Forged with extended Bonnets
- Knife, Butterfly & NVRV
- Gate, Globe, Check & Ball
- Cryogenic
- Control Valves
- Safety Valves
- Boiler valve solutions
We are also the sole South African distributor of NSV valves.
Pneumatics
- Cylinders, Regulators & Solenoid Valves
- Tubing, Fittings & Connectors
- Air Drying Solutions










HEAD OFFICE
17 Venus Street, Sasolburg, 1947
+27 (0)16 971 3333
SECUNDA BRANCH
16 Steenkamp Street, Secunda, 2302
+27 (0)17 634 7011
sales@staro.co.za



