Checklist · Last updated 2026-07-16
SCADA cybersecurity checklist.
Six categories to evaluate — for your own system, or any vendor's.
A defensible SCADA security posture spans six areas: identity and access, session management, transport encryption, audit and accountability, network architecture, and organizational governance. Use this checklist to evaluate any SCADA system — including SCAIQ™.
Six areas to evaluate
Identity & access
- Role-based access control with least-privilege defaults
- Two-factor authentication for all accounts with write/engineering access
- Configurable password policy with enforced complexity and rotation
- Account lockout after repeated failed attempts
- No shared/generic operator logins
Session management
- Sliding idle timeout on all sessions
- Absolute session lifetime enforced server-side
- Secure cookie flags (HttpOnly, Secure, SameSite)
Transport & encryption
- TLS/HTTPS for all browser traffic
- Authenticated, encrypted service-to-service channels
- Encrypted storage for configuration/screen files
Audit & accountability
- Every operator action attributed to user, workstation, and timestamp
- Login and security event logging
- Sensitive-page access logging
- Tamper-evident or centrally retained audit records
Network & deployment
- Segmentation between OT and IT networks
- No unnecessary internet-facing services
- Documented, minimal open ports
- Ability to run fully isolated/air-gapped where required
Process & governance
- Documented vulnerability disclosure/reporting process
- Regular access review (who has which role)
- Patch and update process defined for underlying OS/infrastructure
- Vendor security posture documented (development practices, certifications)
See how SCAIQ™ answers this checklist.
Bring your toughest SCADA questions. Our engineers will show you real screens, real alarms, and real trends.
Or talk to us directly: +91 84014 22388 ·sales@scaiq.com