Industrial data integration is not only about moving tags from OT to IT. In a modern PI System architecture, every connection must be treated as a governed security conduit - with a defined owner, protocol, direction, port, business justification, monitoring requirement and validation evidence.
This case study presents a cloud-based PI System integration pattern for multi-area industrial operations:
- On-premises remote areas remain in OT/PCN workgroup environments with DCS/PLC systems, redundant OPC DA sources, redundant OPC UA sources and redundant PI OPC Interface nodes where applicable.
- Cloud DMZ hosts the PI Server high-availability layer and PI Server Test as controlled aggregation points.
- Cloud IT hosts PI AF, PI Vision, SQL/RDBMS integration services and user-facing analytics under one Active Directory domain.
- Corporate dashboards are published as approved, curated data products - not by exposing the PI Archive or OT network directly.
From a cybersecurity perspective, the key discussion is how to convert the architecture into IEC 62443-style zones and conduits. The design review should validate restricted data flow, firewall allow-lists, identity and access control, system hardening, logging, recovery, and clear FAT/SAT evidence.
A few important lessons from the case:
- Keep OPC DA/DCOM local wherever possible. Avoid extending DCOM across DMZ or enterprise firewalls unless a documented exception and constrained RPC design are approved.
- Prefer certificate-based OPC UA or brokered transfer patterns for modernization.
- Treat one-way transfer / data diode architecture as an engineered publishing pattern, not simply as a firewall replacement.
- Use PI AF and PI Vision in the Cloud IT layer for contextualization and controlled visualization.
- Publish corporate dashboards through a governed, read-only and sanitized pathway.
- Prove the architecture through evidence: tag quality checks, buffering recovery, HA failover, firewall logs, negative testing and access-control validation.
Secure industrial data architecture is not proven by a diagram alone. It is proven by a validated operating model: secure by design, controlled by procedure and accepted through test evidence.
#PISystem #AVEVAPI #IndustrialCybersecurity #IEC62443 #OTSecurity #SCADA #IndustrialData #DataHistorian #OPCUA #DataDiode #DigitalTransformation #IndustrialAutomation
ONE-PAGE SUMMARY BULLETS
Case Context
- Cloud-based PI System architecture for multi-area industrial operations.
- Remote areas stay on-premises in OT/PCN workgroup environments with DCS/PLC data sources.
- Data sources include OPC DA, OPC UA, PI OPC Interface and historian replication patterns.
Target Architecture
- Cloud DMZ acts as the controlled PI data aggregation boundary.
- Cloud IT hosts PI AF, PI Vision, SQL/RDBMS and analytics services under one AD domain.
- Corporate dashboard publishing uses curated, approved data products only.
Cybersecurity Review Focus
- Translate all connections into IEC 62443 zones and conduits.
- Define source, destination, protocol, port, direction, owner, logging and test evidence.
- Apply least privilege, explicit allow-lists and deny-by-default principles.
Firewall & One-Way Transfer
- Validate TCP 5450/5457, HTTPS 443, SQL and AD-related flows against actual product versions.
- Avoid broad DCOM/RPC exposure; keep OPC DA local or migrate to OPC UA / brokered transfer.
- Evaluate data diode or one-way publishing where the risk assessment requires unidirectionality.
Improvement Opportunities
- Formalize zone/conduit register and firewall rule governance.
- Strengthen identity model with AD groups, MFA and role-based PI AF / PI Vision access.
- Prove HA, buffering, backup/restore, monitoring, logging and incident-response readiness.

