Skip to content

Security1 publisher2 min readPublished

Restoring a SCADA workstation from its OS backup leaves the alarm setpoints behind

SC World's OT resilience explainer argues that a plant can restore the operating system and the SCADA application after ransomware and still be missing the PLC programs, HMI screens and alarm tables that control the process.

The Watch · Security desk

What happened

  • SC World's OT resilience explainer says most manufacturing recovery plans treat operational technology like IT: restore servers and applications from backup, verify network connectivity, return systems to operational status.
  • Its central claim is that ransomware-encrypted SCADA workstations can be restored at the operating system and application level while the process configurations, alarm setpoints and historian connections stay missing.
  • Standard IT backup products capture file systems and databases and miss device-level configurations along with the engineering documentation that defines safe operating parameters.
  • Validation adds delay, because process engineers, either internal staff or contracted third-party specialists, have to review configurations before production restarts.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint A recovery time objective negotiated on restore speed understates restart time at a plant, since the engineering review lands after the restore job finishes and before the process runs.
  • exposure The hazard from an incomplete restore falls on the control room: operators watch chlorine levels or turbine vibration through screens and alarms that may not be the ones they were trained on.
  • decision Backup coverage becomes a scoping decision for whoever buys the product, because device programs and engineering files are in scope only if the buyer names them.
  • precedent Restore drills scored on whether the application starts will keep issuing passes, so the pass criteria have to carry an engineering sign-off to mean anything for a plant.

An operating system image of a SCADA workstation holds the operating system and the SCADA application. What lets that workstation control a process sits somewhere else: PLC program versions, HMI screen configurations, historian tag mappings and alarm setpoint tables, held as engineering files, database configurations and device programming [4]. The operating system and application backup leaves all four classes of artifact behind [1].

SC World gives two failure modes. A water treatment plant restores its SCADA system from IT backup after ransomware, the application starts, and the HMI screens come up in default configurations instead of the custom displays operators use to watch chlorine levels, pump status and filtration stages [6]. A power generation facility restores turbine control, passes every IT system check, and runs with incorrect turbine speed setpoints or disabled vibration alarms [7]. Both are written as failure modes to consider, and the piece does not cite a dated incident [13].

The validation it proposes runs in three layers. Device: PLC programs, controller configurations and safety system logic match the pre-incident baseline. System: SCADA configurations, HMI displays, alarm setpoints and historian connections are correctly restored. Process: the restored systems can monitor and control production according to the procedures that define safe operation [8]. "What changes the outcome: treating OT recovery as process engineering, not system administration," the explainer says [10].

This is an argument from architecture. On its account, IT disaster recovery produces system availability, and for business applications availability is the same thing as operational capability [11]. In OT, availability only enables capability, because capability needs process-specific engineering data that IT backup architectures do not capture [12]. No measured failure rate sits under the claim.

Testing it on one site is cheap. A single SCADA host restored from last night's backup into an isolated network would show whether the alarm setpoint table and the historian tag mappings come back with it. The explainer's bar for a finished recovery is that the restored system can safely control the manufacturing process [14].

What to watch

  • Any operator publishing restore-test results that show which engineering artifacts actually came back from backup.
  • Backup vendors adding PLC program and HMI project capture to OT product scope.
  • OT insurers or auditors asking for engineering sign-off evidence before a ransomware restart claim.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories