Blog - swIDch

Brownfield Modernisation and Integrated Control Risks

Written by Admin | Aug 25 2026

 

Global manufacturing and critical infrastructure enterprises are accelerating digital transformation initiatives, connecting legacy brownfield environments to modern cloud infrastructure, edge computing, and unified IT management systems. However, layering modern access control frameworks over legacy operational technology built with fifteen to thirty year lifespans creates a severe security gap. Heterogeneous environments containing both modern control software and legacy programmable logic controllers render traditional defensive controls ineffective, introducing complex threat vectors for CISOs.

 

Legacy Lifecycle Limits and Smart Integration Blind Spots 

Core brownfield OT assets, including legacy programmable logic controllers (PLCs), human machine interfaces (HMIs), and engineering workstations (EWS), were engineered without native connectivity or user authentication. These devices rely on unencrypted serial communications or early industrial protocols such as Modbus RTU and Profibus.

During smart manufacturing upgrades, legacy hardware connects directly to IT and cloud networks through IP based IIoT gateways or protocol converters. Even when organisations deploy modern VPNs or privileged access management solutions at the upper network boundary, protocol translation strips user identity information before packets reach legacy controllers. This creates a structural blind spot where modern IT infrastructure intersects with unauthenticated legacy endpoints.

 

Identity Stripping and Lessons from the Oldsmar Incident 

This structural weakness was starkly demonstrated during the 2021 cyber attack on the water treatment plant in Oldsmar, Florida. An attacker compromised remote access tools and outdated management terminals to breach SCADA and HMI systems. The intruder then issued malicious commands directly to downstream control systems, increasing sodium hydroxide levels from 100 parts per million to 11,100 parts per million.

Investigations by CISA and industrial control specialists highlighted a pivotal issue: once the remote session was established, no endpoint access verification mechanism existed at the controller level to validate the specific human operator connecting to the device. As command packets passed through protocol converters to legacy devices, user identity was completely stripped, leaving the system unable to verify access legitimacy or establish post incident accountability.

 

The Unfeasibility of Rip and Replace Strategies 

Replacing every legacy PLC and HMI across an enterprise through a complete rip and replace strategy is financially and operationally unviable. Plant operations teams strongly resist wholesale equipment replacement due to crippling downtime costs and the risk of compromising proven control logic.

Furthermore, legacy controllers and remote terminal units lack the processing power and memory necessary to host endpoint detection agents, process complex encryption, or handle multi factor authentication. The priority for brownfield modernisation must focus on verifying operator identity at the endpoint access layer prior to execution without imposing computing overhead on legacy endpoints.

 

 

Achieving Access Trust Without Replacing Legacy Assets 

Successful brownfield modernisation requires more than opening network paths between old and new systems. Security leaders must extend identity verification mechanisms down to the final control boundary while preserving existing legacy infrastructure.

By validating operator identity and control privilege through an independent single-use mechanism before an endpoint connection is granted, organisations secure immutable audit trails without altering legacy PLCs. Advancing brownfield OT security depends on embedding absolute entity identification into integrated management workflows, ultimately establishing true access trust.

 

 

--------------------

 

swIDch will continue its quest to innovate and pioneer next-generation authentication solutions. To stay up-to-date with the latest trends sign up to our newsletter and check out our latest solutions.