Solution Brief | Check Point Security for Industrial Control Systems (ICS)
Learn how Check Point Security for Industrial Control Systems (ICS) protects OT and ICS environments with asset visibility, network segmentation, zero trust enforcement, SCADA application control, and advanced threat prevention. Strengthen cyber security across critical infrastructure and industrial networks.

© 2023 Check Point Software Technologies Ltd. All rights reserved.
ICS and OT Networks Are Prime Targets The expanding attack surface for industrial manufacturing and critical infrastructure facilities is influenced by several factors, including the growing prevalence of nation-state actors and state-sponsored attacks, technological advancements, the increasing connectivity of industrial control systems (ICS), and the convergence of operational technology (OT) and information technology (IT) networks.
However, the advantages of interconnected ICS systems also create vulnerabilities that can be exploited by threat actors to disrupt infrastructure operations and processes. For instance, attackers can manipulate commands sent to controllers, altering their logical sequences, or changing sensor readings, resulting in disruptions to industrial processes. These disruptions can be subtle and challenging to detect initially, but they progressively cause damage over time.
To effectively mitigate these risks, organizations must prioritize the implementation of an ICS security solution that offers a comprehensive approach to minimizing risk exposure across both IT and OT environments. By leveraging such a solution, organizations can proactively block attacks before they compromise critical assets. Furthermore, it must be easily scalable and non-disruptive to critical processes, ensuring uninterrupted functionality of industrial operations.
Easy to Hack, Hard to Patch ICS assets and OT networks are susceptible to cyberattacks due to several inherent vulnerabilities, which include:
• Weak or Hardcoded Passwords • Flat Network Design (lacks border segmentation) • Legacy or Proprietary Software (Lack of Security Support) • Limited Software Updates and Patching
Recognizing the need to protect these vulnerable assets, OT security solutions have emerged to offer visibility and security to the multitude of devices and systems connected to industrial and operational networks.
Check Point Security for Industrial Control Systems (ICS) ENSURE THE SAFETY AND INTEGRITY OF YOUR OPERATIONAL TECHNOLOGY (OT) ENVIRONMENT
Check Point Security for ICS and OT Networks Check Point extends the industry’s most comprehensive cybersecurity solution to protect extreme ICS and OT network environments with its family of Quantum Rugged security gateways. Organizations with Industrial Control Systems such as SCADA (Supervisory Control and Data Acquisition) can safely connect Industrial IoT (IIoT) assets to their OT networks. With Quantum Rugged firewalls, organizations can segment OT network devices to apply zero trust policy enforcement within the OT network along the lines of the Purdue model: Field sensors in a physical LAN, PLCs in a controller LAN, HMIs in the process network and SCADA servers in the operations layer. Deploying Quantum Rugged security gateways in these rugged environments provides enhanced visibility of ICS assets and network communications with asset discovery, network segmentation and access control, and advanced threat prevention. Check Point firewalls can identify and provide granular control of over 1,800 SCADA applications in these harsh environments.
With industrial domain expertise, the solution prevents OT related attacks and continually minimizes the OT attack surface—all in a way that is easily scalable and non-disruptive to critical industrial processes.
Applying Security to ICS We will now dissect the six different layers mentioned above, their mapping to various network areas, and explain the communication flows between these Purdue model levels. Additionally, we’ll provide Check Point’s recommendations for securing them. To accomplish this, the following diagram will be used as an example.
Figure 1 presents a high-level representation of a typical IT/OT environment, showcasing The Purdue model organized by levels.
• Manufacturing plants usually integrate both OT and IT within a single site. Utilities and energy, including gas, water and electricity, often operate across distributed environments, connecting numerous remote sites to a central facility. It’s essential to consider potential bandwidth constraints when planning the architecture.
© 2023 Check Point Software Technologies Ltd. All rights reserved.
© 2023 Check Point Software Technologies Ltd. All rights reserved.
QUANTUM RUGGED SOLUTION BRIEF 3
Figure 1: OT/ICS network segmentation and micro-segmentation by Purdue model
© 2023 Check Point Software Technologies Ltd. All rights reserved.
QUANTUM RUGGED SOLUTION BRIEF 4
With industrial domain expertise, the solution prevents OT related attacks and continually minimizes the OT attack surface—all in a way that is easily scalable and non-disruptive to critical industrial processes.
Core Capabilities Check Point Quantum Rugged security gateways deliver proven, integrated AI-powered security, with secure high-speed 5G connectivity and more for deployments in harsh environments as part of a complex end-to-end ICS security solution. It offers:
Deep ICS asset visibility and risk analysis
• Identify, classify and analyze every OT device inside the network with best-of-breed discovery engines
• Get granular fingerprints on each device, including communication protocol used, brand, model, type, IP, MAC address, firmware version and more
• Obtain a behavioral baseline of normal ICS asset communications to easily detect anomalies
• Expose risk indicators such as weak passwords, outdated firmware and known vulnerabilities (CVEs)
SCADA/ICS Security and Compliance
• Monitor and control more than 100 SCADA protocols and over 1,800 functions (commands)
• Establish alert or prevention policies at the SCADA command level for secure communication between ICS assets
© 2023 Check Point Software Technologies Ltd. All rights reserved.
QUANTUM RUGGED SOLUTION BRIEF 5
PROTOCOLS
CODESYS IEC 61850
DICOM IEC 61375-2-3
Direct Message Profile IEC 61400
DLMS/COSEM - IEC62056 KNXnet/IP
Ethernet Global Data (EGD) - Producer/Consumer MELSEC Q
E3 MMS Protocol
Ether-S-I/O Protocol Modbus Protocol
EtherCat Motorola MDLC
FactoryTalk RNA OPC AE
Fanuc Focas OPC DA
FBNet Protocol OPC HDA
GAZ MODEM 3 Protocol (GM3) OPC UA
HL7 OPC XML DA
IEC 61400 OPC Common
AMS Unity Protocol (UMAS)
Asterix (ATC Standard) Windman Protocol
Building Automation and Control Networks (BACnet) Simple Transportation Management Protocol (STMP)
CANopen ZigBee Encapsulation Protocol
CNP ISO/IEC 14908 M3 Protocol
Common Industrial Protocol Manufacturing Message Specification Protocol (MMS)
Component Network over IP (CN/IP) MELSOFT Protocol
DIS MQTT
DMP Omron FINS Protocol
DMP3 Protocol Siemens S7
EtherNet/IP SafetyNet
Ether-S-Bus Profinet CBA/IO Hart IP
ICCP
IEC 60870-5-104
Figure 2: SCADA and Industrial Internet of Things (IIoT) supported protocols by Application Control
© 2023 Check Point Software Technologies Ltd. All rights reserved.
QUANTUM RUGGED SOLUTION BRIEF 6
Intuitive zero trust segmentation
• Segment the IT network from the OT network to prevent lateral movement and lateral infection
• Add micro-segmentation to prevent unauthorized east-west communication between assets within the ICS zones
• Apply granular security rules based on OT protocols
• Gain single-pane policy management for IT and IoT/OT, with a distinct OT policy layer
• Having a dedicated OT dashboard to manage and review all OT/ICS traffic and alerts
Mitigate known vulnerabilities, prevent threats and zero-day malware
• Virtually patch OT devices running unpatched firmware and legacy operating systems
• Identify and block, or alert on, unauthorized access to and from OT devices and servers
• Prevent the newest OT-targeted malware attacks in real-time with ThreatCloud AI, Check Point’s global threat intelligence
Why Check Point Encompassing network and device-level ICS security in the most severe environments, Quantum Ruggedized security gateways extend Check Point’s comprehensive cyber security portfolio to prevent sophisticated cyberattacks, adapting protections to any ICS, IoT or OT device across smart-office, smart- building, medical and industrial environments.
• Broadest range of cybersecurity solutions to protect connected devices across multiple industries
• Industry-leading threat prevention with a 99.7% catch rate of Gen-V cyberattacks
• Full visibility of connected assets in a unified Infinity cybersecurity architecture
• Wide range of gateway options including choices of SMB/branch, enterprise-scale and ruggedized security gateways for industrial environments
© 2023 Check Point Software Technologies Ltd. All rights reserved.
QUANTUM RUGGED SOLUTION BRIEF 7
Benefits of Secure ICS Encompassing network and device-level ICS security solutions, Quantum Ruggedized security gateways make security effortless:
• Verify proper segmentation with appropriate security controls enabled between segments.
• Implement sandboxing technologies at the perimeter (level 5), including SSL/TLS inspection. Within internal segments (level 4 and below), ensure a minimum security stack that includes Firewall, IPS, Identity Awareness, and Application Control. Additionally, prioritize sandboxing as a vital defense against zero-day attacks, a common method hackers employ to target critical infrastructure.
• Threat Prevention is vital. Detection only informs you when the damage has already been done.
• The IPS blade contains signatures for securing ICS environments. Enable IPS in “prevent mode” wherever possible and make sure to specifically monitor alerts for these signatures.
• Application control supports over 100 SCADA protocols up to the command-level. This allows for the creation of a security policy that authorizes only specific commands to be sent to an asset and deny everything else.
• Visibility is key to security. Ensure there is enough resources dedicated to monitor the environment. Tools like SmartEvent, 3rd-party Discovery Engines and a dedicated SIEM can reveal a lot of information that may otherwise go unnoticed.
• Comply with the latest OT cybersecurity regulations, including standards like NERC CIP, NIST 800-82, and ISA/IEC 62443, to maintain a secure operational environment.
© 2023 Check Point Software Technologies Ltd. All rights reserved.
QUANTUM RUGGED SOLUTION BRIEF 8
Check Point Infinity Quantum Rugged security gateways are seamlessly integrated with Check Point Infinity, the only fully consolidated cyber security architecture that protects your business and IT infrastructure against Gen VI multi-vector ‘Nano’ cyber-attacks across networks, IoT devices, endpoint, cloud and mobile. Check Point Infinity delivers unprecedented protection against current and potential attacks—today and in the future.
© 2023 Check Point Software Technologies Ltd. All rights reserved.
Worldwide Headquarters 5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel | Tel: +972-3-753-4599
U.S. Headquarters 959 Skyway Road, Suite 300, San Carlos, CA 94070 | Tel: 1-800-429-4391
www.checkpoint.com © 2023 Check Point Software Technologies Ltd. All rights reserved.
Don’t leave your OT security to chance. Get the visibility you need and the protection you deserve.
Contact us for a demo today, or get in touch with your account representative
to discuss your OT security needs.