Skip to content
Back to Case Studies

Case Study : PI System Integration

A secure PI System architecture is proven by evidence, not diagrams. See how IEC 62443 zones, governed conduits and FAT/SAT validation turn an OT-to-cloud design into a trusted operating model.

Sep 15, 2026

Industrial data integration is not only about moving tags from OT to IT. In a modern PI System architecture, every connection must be treated as a governed security conduit - with a defined owner, protocol, direction, port, business justification, monitoring requirement and validation evidence.

This case study presents a cloud-based PI System integration pattern for multi-area industrial operations:

  • On-premises remote areas remain in OT/PCN workgroup environments with DCS/PLC systems, redundant OPC DA sources, redundant OPC UA sources and redundant PI OPC Interface nodes where applicable.
  • Cloud DMZ hosts the PI Server high-availability layer and PI Server Test as controlled aggregation points.
  • Cloud IT hosts PI AF, PI Vision, SQL/RDBMS integration services and user-facing analytics under one Active Directory domain.
  • Corporate dashboards are published as approved, curated data products - not by exposing the PI Archive or OT network directly.

From a cybersecurity perspective, the key discussion is how to convert the architecture into IEC 62443-style zones and conduits. The design review should validate restricted data flow, firewall allow-lists, identity and access control, system hardening, logging, recovery, and clear FAT/SAT evidence.

A few important lessons from the case:

  1. Keep OPC DA/DCOM local wherever possible. Avoid extending DCOM across DMZ or enterprise firewalls unless a documented exception and constrained RPC design are approved.
  2. Prefer certificate-based OPC UA or brokered transfer patterns for modernization.
  3. Treat one-way transfer / data diode architecture as an engineered publishing pattern, not simply as a firewall replacement.
  4. Use PI AF and PI Vision in the Cloud IT layer for contextualization and controlled visualization.
  5. Publish corporate dashboards through a governed, read-only and sanitized pathway.
  6. Prove the architecture through evidence: tag quality checks, buffering recovery, HA failover, firewall logs, negative testing and access-control validation.

Secure industrial data architecture is not proven by a diagram alone. It is proven by a validated operating model: secure by design, controlled by procedure and accepted through test evidence.

#PISystem #AVEVAPI #IndustrialCybersecurity #IEC62443 #OTSecurity #SCADA #IndustrialData #DataHistorian #OPCUA #DataDiode #DigitalTransformation #IndustrialAutomation

ONE-PAGE SUMMARY BULLETS

Case Context

  • Cloud-based PI System architecture for multi-area industrial operations.
  • Remote areas stay on-premises in OT/PCN workgroup environments with DCS/PLC data sources.
  • Data sources include OPC DA, OPC UA, PI OPC Interface and historian replication patterns.

Target Architecture

  • Cloud DMZ acts as the controlled PI data aggregation boundary.
  • Cloud IT hosts PI AF, PI Vision, SQL/RDBMS and analytics services under one AD domain.
  • Corporate dashboard publishing uses curated, approved data products only.

Cybersecurity Review Focus

  • Translate all connections into IEC 62443 zones and conduits.
  • Define source, destination, protocol, port, direction, owner, logging and test evidence.
  • Apply least privilege, explicit allow-lists and deny-by-default principles.

Firewall & One-Way Transfer

  • Validate TCP 5450/5457, HTTPS 443, SQL and AD-related flows against actual product versions.
  • Avoid broad DCOM/RPC exposure; keep OPC DA local or migrate to OPC UA / brokered transfer.
  • Evaluate data diode or one-way publishing where the risk assessment requires unidirectionality.

Improvement Opportunities

  • Formalize zone/conduit register and firewall rule governance.
  • Strengthen identity model with AD groups, MFA and role-based PI AF / PI Vision access.
  • Prove HA, buffering, backup/restore, monitoring, logging and incident-response readiness.

Cloud Based PI System Integration