In modern industrial environments, reliance on telemetry is growing, yet raw data streams often become hidden technical debt. When PLCs and sensors send unstructured packets directly to SCADA or cloud systems, critical network congestion occurs and the attack surface expands. According to NIST SP 800-82, availability is a priority in OT environments, and network segmentation is a fundamental security control. Direct data transmission without validation at the network edge violates these principles.
Why raw data in OT is hidden technical debt and a threat
Technical leaders face the "data deluge" problem, where the volume of unnormalized data overwhelms communication bandwidth. The issue is not just volume, but trust: if a device transmits data that has not been verified at the gateway level, a vulnerability in equipment firmware can become a vector for penetrating the system core.
Edge normalization: noise reduction as an architectural control
The reliability of an IoT solution, as noted by AWS experts in the Well-Architected IoT Lens, is established at the architectural design stage by clearly defining which data is processed at the Edge and which in the cloud. Filtering high-frequency sensor noise at the gateway level allows for cleaning traffic before it reaches SCADA, minimizing the volume of data accessible to attackers.
OPC UA as an interoperability tool
OPC UA serves as a platform-independent architecture for interoperability and acts as a machine data normalization layer. It is important to note: OPC UA ensures data format standardization but does not replace network segmentation. Normalization is the first step toward creating a "trusted boundary," where data is brought into a unified format for predictive analytics.
Architectural security per ISA/IEC 62443: the role of the gateway in segmentation
The ISA/IEC 62443 standard series provides security guidance for industrial automation systems across more than 20 industries. In this paradigm, the Edge gateway functions as a proxy: legacy OT equipment that is difficult to update is isolated from the network. The gateway receives raw traffic, validates it, and forwards only normalized packets. Solutions using UnityBase platform mechanisms allow for implementing this approach, ensuring access control and auditing at the domain model level.
Maturity levels of data processing at the Edge
| Maturity level | Approach description |
|---|---|
| Level 1: Direct transmission | Raw data sent directly to SCADA/Cloud; high risk of overload. |
| Level 2: Basic filtering | Noise reduction at the gateway; traffic reduction without standardization. |
| Level 3: Normalization (OPC UA) | Data brought to a unified format to improve interoperability. |
| Level 4: Secure architecture | Normalization combined with segmentation and control per ISA/IEC 62443. |
FAQ
Does OPC UA replace the need for network segmentation in an OT environment?
No, OPC UA only provides data normalization and interoperability. Network segmentation according to the ISA/IEC 62443 standard remains a fundamental cybersecurity control.
How to reduce the load on the SCADA system without losing data accuracy?
Use Edge gateways for pre-filtering high-frequency noise and normalizing data before it reaches SCADA.
Which security standards should be applied to legacy equipment when integrating into IIoT?
Apply ISA/IEC 62443 principles to build segmentation, where the Edge gateway acts as a secure proxy server, isolating legacy equipment.