Skip to main content

Supervisory

Distributed Control System (DCS)

An integrated control platform for continuous processes, combining controllers, operator stations, engineering tools and a proprietary control network.

Critical criticalityLevel 2 – Level 1

What it does

Runs regulatory and advanced control across an entire process unit with tightly coupled operator and engineering environments.

Typically locatedProcess plants: refining, chemicals, power generation, pharmaceuticals.

At a glance

PurdueLevel 2 – Level 1
CategorySupervisory
Protocolsfoundation-fieldbus, profibus, profinet, hart, opc-ua, modbus-tcp
Talks toField devices, Operator stations, Historian, Safety systems (via defined interfaces)
Common vendorsHoneywell (Experion), Emerson (DeltaV), Yokogawa (CENTUM VP), ABB (800xA, Symphony Plus), Siemens (PCS 7, PCS neo)

Why should I care?

Distributed Control System sits at Level 2 – Level 1. Compromise here is not just a data problem — it changes what the physical process does or what operators can see and control.

Common security problems

  • Long lifecycles with unsupported OS versions
  • Vendor-managed systems with standing remote access
  • Complex change control that discourages patching

If it is compromised

  • Loss of control or view across an entire process unit
  • Unit shutdown and long recovery

What to monitor

  • Engineering changes and downloads
  • Domain and local authentication
  • Vendor remote sessions
  • Console and server health

How to defend it

  • Vendor-approved hardening baselines
  • Segment the DCS as its own zone
  • Time-bound, monitored vendor access
  • Validated backups of configuration and images