The engineering workstation is the computer used to configure and program the control systems that run a process. It holds the project files, the programming software and the access needed to change how controllers behave, which makes it one of the most powerful machines in any plant.
That power is exactly why it is dangerous. An engineering workstation often touches both IT and OT, runs general-purpose software, and is the ideal pivot for an attacker who wants to reach the controllers. Securing it is one of the highest-leverage things an OT security program can do.
01Key takeaways
- 01
An engineering workstation (EWS) can configure and reprogram the controllers that run the physical process.
- 02
It is frequently dual-homed, touching both IT and OT, which makes it a bridge attackers seek.
- 03
General-purpose use, such as internet, email and USB, brings IT-style risk to a machine with OT-level power.
- 04
Hardening and dedicating the EWS to its purpose dramatically reduces its exposure.
- 05
Its connectivity to OT should be controlled and limited to the times engineering work is actually happening.
02What an engineering workstation is and why it matters
An engineering workstation is the machine engineers use to develop, configure and load the logic that controllers execute. It runs vendor programming environments, stores project files and holds the credentials and connectivity to push changes to PLCs and other devices.
Whoever controls the engineering workstation can, in effect, change how the process runs. That is enormous power concentrated in one place, which is why its security deserves outsized attention.
The engineering workstation is where someone can legitimately rewrite what the plant does. Compromise it and an attacker can too.
03The dual-homed problem
Engineering workstations are often connected to both the IT network, for updates, licensing, documentation and email, and the OT network, to reach the controllers. That dual-homed position makes the machine a literal bridge between the two environments.
For an attacker who has compromised IT, a dual-homed engineering workstation is a direct route to operations. It already has the access, the tools and the connectivity that the attacker would otherwise have to build, which is why it is such a prized pivot.
04Common exposures
Engineering workstations accumulate risk when they are used like ordinary PCs while holding extraordinary power.
- Internet and email access that exposes the machine to phishing and web-borne threats.
- USB use for transferring project files, firmware and tools, carrying media-borne risk.
- General-purpose software and browsing on a machine that can reprogram controllers.
- Shared or weak credentials, and accounts that span IT and OT.
- Project files and backups stored without protection, valuable to an attacker mapping the process.
05Hardening and dedicated use
The most effective principle is to make the engineering workstation a single-purpose machine, treated according to the power it holds rather than the convenience of using it like a normal PC.
- Dedicate the workstation to engineering tasks and remove general-purpose internet and email use.
- Apply strict application allowlisting so only approved tools run.
- Use strong, unique credentials and avoid accounts shared with IT.
- Control and scan any media used with the workstation.
- Keep the machine patched where feasible and monitor it for changes.
06Controlling its connectivity to OT
Even a hardened engineering workstation should not have a standing, always-on connection to the controllers. Engineering work happens occasionally, so the connection to OT can be present only when that work is actually taking place.
An AIRGAPNET controlled connectivity pattern can keep the path between the engineering workstation and the OT network disconnected by default, opening it only for an approved engineering session and closing it afterward. This removes the dual-homed bridge except during supervised work, so a compromised workstation has no standing route to the controllers.
The combination is powerful: a dedicated, hardened machine whose dangerous connectivity exists only when it is genuinely needed.
07Closing thought
The engineering workstation concentrates the ability to change how a plant operates into a single machine, and too often that machine is used like any other office PC. That mismatch between power and treatment is what makes it the most dangerous computer in the plant.
Dedicate it to its purpose, harden it to match its power, and ensure its connection to the controllers exists only during supervised work. Protect the engineering workstation and you protect the keys to the process itself.
FAQFrequently asked questions
What is an engineering workstation in OT?
An engineering workstation (EWS) is the computer used to develop, configure and load the logic that controllers execute. It runs vendor programming software, stores project files, and holds the access needed to change how PLCs and other devices behave.
Why is the engineering workstation so dangerous?
It can reprogram the controllers that run the physical process and is often connected to both IT and OT. That combination of deep control and a bridging position makes it a prized pivot for attackers who want to reach operations.
What is the dual-homed problem?
Engineering workstations are often connected to both the IT and OT networks at once, forming a bridge between them. For an attacker who has compromised IT, a dual-homed workstation is a direct route to operations with the access and tools already in place.
How do you secure an engineering workstation?
Dedicate it to engineering tasks, remove general-purpose internet and email use, apply application allowlisting, use strong unique credentials, control and scan media, and patch and monitor it. Treat it according to the power it holds.
Should an engineering workstation always be connected to OT?
No. Engineering work happens occasionally, so the connection to the controllers should exist only during approved sessions. Keeping the path disconnected by default removes the dual-homed bridge except during supervised work.
SRCSources of record
Power demands control
Connect the engineering workstation to OT only during supervised work.
Keep the path between a hardened engineering workstation and the controllers disconnected by default, opening it only for approved sessions, so a compromise has no standing route in.