• Cogent DataHub
  • Industrial
    • Industrial AI
    • Industrial IoT
      • Edge Computing
      • DHTP – The DataHub Transfer Protocol
      • IIoT Protocol Comparison
      • Demo
    • Cogent DataHub
    • Security
    • DataHub™ Service
    • ETK – Embedded Toolkit
      • IoT Gateways
      • Tested Devices
  • Case Studies
    • Blog
    • White Papers
    • News
  • Partners
    • Microsoft
    • Siemens
    • AVEVA
    • Join Now!
  • Investors
    • Financials
  • About Us
    • Management
    • Customers
    • Careers
    • Legal Notices
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

Security for Industrial IoT

by Bob McIlvride

T he issue of remote data access to data from an industrial system is not new.  For years plant owners have been creating ways for their managers, operators, maintenance technicians and partners to gain access to the valuable real-time information generated by their plants.  Innovative business practices, such as globalization and just-in-time manufacturing, have driven a need to have low-latency remote access to this data, often through untrusted networks to semi-trusted end users.  For example, a manufacturer may want to share production information with a remote supplier, but not provide login access to the manufacturing system or database.

Several fundamental security problems have arisen from this need for remote real-time access:

Exposure to attack from the Internet.  When a plant allows a user to access the system remotely, it naturally creates an attack surface for malicious actors to attempt to also gain access to the system.

Exposure to attack from the IT network.  If a plant allows a user to access the system remotely, it also needs to expose itself to the network infrastructure of the company’s IT system.  Generally the plant network is a subnet within the larger company network.  Entry into the plant will be via the IT infrastructure.  Attacks from the IT network are less likely, but some kinds of problems in the IT network could disrupt normal network data flow on the plant network.  It is wise to separate the IT and plant networks as much as possible.

Remote access beyond the required data.  Giving a remote user access to a desktop, such as Microsoft RDP, means that a curious or malicious user can try to gain access to programs and data beyond what was intended.  Even if the user is trustworthy, but the user’s system is compromised, a remote access program becomes a point of attack into the plant system.

Exposure of a portion of the plant network.  Some plants have chosen to use VPN connections to limit Internet attacks.  However a VPN effectively puts all participants onto a local sub-network, which gives the participating machines effectively local network access to one another.  Compromising any machine on the network (such as a remote supplier) produces an opportunity for an attacker to hack into the plant network via the VPN.

High cost.  VPNs, RDP entry points, firewalls and routers require ongoing attention and effort from IT personnel.  This cost increases as the number of participants in the system increases.  Plants that do not devote the resources to IT are more likely to implement their remote data access less securely.

How can Skkynet Help?

Skkynet’s unique solution, SkkyHub™, provides a mechanism for dealing with all of the traditional security problems in remote plant data access.

NO Exposure to attack from the Internet.  Users of Skkynet’s SkkyHub install an agent within the plant that collects plant information and pushes it out to Skkynet’s real-time data servers.  Since this connection is outbound, from the plant to the Internet, there is no requirement for the plant to open any inbound TCP ports, and thus the plant never exposes itself to attack from the Internet.

NO Exposure to attack from the IT network.  It is good practice to isolate the plant from the IT network using a router that allows only out-bound connections from the plant into the IT network.  Using the SkkyHub service, the IT network can be treated as untrusted by the plant, and a firewall placed between the two that allows no inbound connections into the plant.  Disruptions on the IT network will not affect data flow within the plant network, though they could affect data flow from the plant to the Skkynet service.  The plant remains secure and functional, even if remote data access is degraded.

We designed a solution to address all traditional security problems in remote plant data access.

NO Remote access beyond the required data.  Using SkkyHub, the plant decides which data to make available remotely.  The plant engineer can choose any subset of the data produced by his plant, and make it available to remote users in data groups.  Each group has its own read/write permissions as well as limits based on the remote user name and the IP address from which the remote user is connecting.  The remote user has no mechanism to extend his access to data beyond what the plant engineer allows him.

NO Exposure of a portion of the plant network.  The SkkyHub service does not create a VPN, or any kind of general-purpose network construct.  It only makes a TCP connection for the transmission of data.  Consequently, no participating machine is ever exposed to any other via a local network or VPN. The data can be routed through network proxies, data proxies and DMZ servers to ensure that the plant network never has a direct connection to the Internet, even for outbound connections.  Participating systems in the Skkynet service never need to share a network.

NO High cost.  SkkyHub eliminates many security hurdles, thereby substantially reducing the IT cost of implementation.  Often, a plant can participate in the Skkynet service without any change to existing IT infrastructure.  The plant has no need to hire extra IT expertise or to install extra networking equipment.  Often the only cost is for configuration of the Skkynet agent at the plant and the Skkynet service itself.

Skkynet’s technology follows good industry practice by using SSL connections for all Internet traffic, and by validating the trust chains of certificates.  This enhances your security for Industrial IoT, and protects you against network snooping and against man-in-the-middle attacks.

Download White Paper (PDF)

Share this entry
  • Share on Facebook
  • Share on X
  • Share on WhatsApp
  • Share on LinkedIn
  • Share by Mail
https://skkynet.com/media/2015/11/Blog-security-for-iiot-image.jpg 430 1000 Bob McIlvride https://skkynet.com/media/skkynet-logo.svg Bob McIlvride2015-11-02 06:00:112018-05-21 17:26:59Security for Industrial IoT

Skkynet White Papers

Explore the questions, watch the developments, and evaluate solutions for one of the biggest opportunities of our time: Implementing secure, real-time data access on the Industrial IoT.

Recent Entries

  • Wood processing plant case study - banner
    Case Study: Wood Processing Plant in North America
  • case-study-heritage-petroleum
    Case Study: Heritage Petroleum, Trinidad and Tobago
  • wind-turbine-control-usa
    Case Study: Wind Turbine Control, USA
X Logo X Logo Followon X RSS Feed Logo RSS Feed Logo Subscribeto RSS Feed
About Us Icon white

About Us

Skkynet has been helping organizations securely share real-time data for more than 25 years. We offer privately-hosted or fully managed solutions for moving data in industrial, embedded and financial systems, from anywhere to anywhere.

News

January 28, 2026

Skkynet Reports Fiscal 2025 Financial Results: Subscription Revenue Surges 268% Amidst Strategic Pivot to AI and SaaS

December 18, 2025

Skkynet Announces C$2.6 Million Industrial AI Product Development Initiative

December 16, 2025

Skkynet Appoints M&A and Software Executive Shaunna Balady to Advisory Board

December 9, 2025

Skkynet Appoints Industry Veteran Gary Tillery as Chief Executive Officer

Contact us icon white

Contact Us

Skkynet
2233 Argentia Road, Suite 302
Mississauga, ON L5N 2X7

International: 1-905-702-7851

US/CA Toll Free: 1-888-702-7851

[email protected]

Skkynet logo white

Cogent DataHub | Industrial | Case Studies | Partners | Investors | About us

Back to Top

linkedIn logotwitter logoyoutube logo

© 2026 Skkynet | All rights reserved | Legal notices
Link to: Industrial SaaS Whitepaper Link to: Industrial SaaS Whitepaper Industrial SaaS Whitepaper Link to: Industrial IoT Myths – Busted! Link to: Industrial IoT Myths – Busted! Industrial IoT Myths – Busted!
Scroll to top Scroll to top Scroll to top

We are using cookies to give you the best experience on our website.

You can find out more about which cookies we are using or switch them off in .

Skkynet logo
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

3rd Party Cookies

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping this cookie enabled helps us to improve our website.

Cookie Policy

More information about our Cookie Policy