MAS suite · IoT and OT connectivity

What crosses the OT boundary, in which direction, and who signs it off

SCADA, historian and edge connectivity for IBM Maximo Monitor, Predict and Health. One tag schedule, one direction of travel, no inbound route into the OT zone, and a written list of what deliberately does not cross.

Plant floor on one side of a boundary and a control and operations room on the other, representing the OT and IT boundary for IBM MAS

The controlling artefact

A tag that is not on the data-flow schedule does not cross. Adding one later takes the same approvals as the original design.

The schedule is written and signed before a collector is installed anywhere. It names every tag, its direction, its sample rate, its destination and the person who authorised it.

The signed document

An extract for one asset class, four boiler feed pumps at one site

DFS-01 rev C

Tag names are illustrative. A first schedule for one asset class usually runs to between 40 and 120 tags, and the five columns are the ones an OT change board reads. This is the artefact a reader can forward to their OT team without editing it.

Field Source Target Frequency Owner
BFP1_DE_VIB_RMS Site historian tag Monitor time series 1 min Historian owner
BFP1_SUCT_PRESS Site historian tag Monitor time series 1 min Historian owner
BFP1_DISCH_TEMP Site historian tag Monitor time series 5 min Historian owner
BFP1_MOTOR_CURRENT Site historian tag Monitor time series 1 min Control systems engineer
BFP1_RUN_STATE Site historian tag Monitor time series On change Control systems engineer
QUALITY_FLAG Historian, per value Monitor, retained Every value Historian owner
TAG_TO_ASSET_MAP Manage asset register Monitor asset binding On change Reliability data owner

Hop by hop

Four hops, one direction of travel, four signatures

The walk we give an OT engineer, in the order they ask for it. Site architectures differ and the design is always specific to yours. The direction of travel, the signature list and the second list under the table do not change.

What moves From Direction To Signed by
Scheduled tag values, with timestamp and quality flag Site historian, read-only account Collector in the DMZ Historian owner, who authorises the account, the tag scope and the read rate against site load
One authenticated session, opened from the lower-trust side Collector in the DMZ MAS ingest endpoint OT cybersecurity, the network owner and the OT change board, against the zone and conduit model the site already runs
Time series, landed with quality flags intact MAS ingest endpoint Maximo Monitor, then Predict and Health MAS platform owner and the IT security function
The mapping that joins a tag to an asset and location record Manage asset register Monitor asset bindings A named mapping owner, appointed before design starts, because the mapping decays whenever a plant project renames something

What deliberately never leaves the OT environment

  • Setpoints, commands or writes of any kind towards the plant.
  • Control logic, engineering configuration and project files.
  • Any data path into or out of a safety instrumented system.
  • Inbound sessions, listening ports on the OT side, or a remote access route for MaxIron.
  • OT credentials and domain accounts.
  • Unfiltered protocol traffic. Only the scheduled tags, at the scheduled rate.

Demonstrated, not described

Five failure modes demonstrated before handover

Each of these is a way an ingest path degrades in service. Every test runs in front of the people who will live with it, and the results form part of the handover pack alongside the runbook, the escalation path and a named owner on each side of the boundary.

  1. T1

    Link loss between the DMZ and the ingest endpoint

    Passes when
    The collector buffers for the agreed window, then recovers on reconnection with no back-pressure onto the historian.
    Witnessed by
    Historian owner and OT cybersecurity
  2. T2

    Buffer reaching capacity during a long outage

    Passes when
    Oldest values are discarded first. The collector does not block, and nothing queues towards the plant.
    Witnessed by
    OT cybersecurity and the network owner
  3. T3

    Unplanned collector restart

    Passes when
    Recovery without manual intervention, and the gap recorded in Monitor rather than filled by interpolation.
    Witnessed by
    MAS platform owner
  4. T4

    Clock skew between the historian and the ingest path

    Passes when
    The effect on the time series is shown, and every value is stamped from the agreed time source.
    Witnessed by
    Reliability engineer and the MAS platform owner
  5. T5

    A plant project renames a scheduled tag

    Passes when
    The flow fails loudly inside one sample interval, instead of producing a gap somebody finds at the next audit.
    Witnessed by
    Historian owner and the tag-to-asset mapping owner

What it takes

One site, one asset class, first workshop to handover

The shape of engagement we run most often. Connectivity is costed as its own phase, ahead of any Monitor or Predict configuration, because that is the order the work actually happens in.

Week one
Tag workshop

The historian owner, a control systems engineer and a reliability engineer, in one room for two days.

Weeks four to eight
Schedule signed

The elapsed time sits with the OT change board, not with engineering.

Weeks nine to twelve
Ingest path live

Collector, ingest pipeline, the T1 to T5 demonstration and the handover pack.

MaxIron team
Two engineers, part time

One integration engineer and one MAS platform engineer.

Tags in a first schedule
40 to 120

One asset class at one site. Illustrative rather than a cap.

By month six
Asset classes two and three

Added as changes under a schedule that is already approved, which is the reason for writing one.

What this needed from the client

  • A historian account, scoped read-only to the agreed tags.
  • A named owner for the tag-to-asset mapping, appointed before design starts.
  • Change board slots booked early, because they set the date rather than we do.
  • An OT engineer available to witness the five acceptance tests.

Scope and boundaries

Where we stop at the OT boundary

Four commitments an OT engineer can hold us to.

We do not write towards the plant

No setpoints, no commands, no control writes, in any pattern we deliver. Asset context travels from Manage as far as the ingest endpoint and no further.

We do not ask for inbound access to the OT zone

No inbound sessions, no listening ports on the OT side, no remote access route for MaxIron. Where the site risk assessment calls for it, a unidirectional gateway enforces direction in hardware rather than in a firewall rule somebody can widen later.

We do not operate your SCADA or historian

Plant-side systems stay with the OT team. We own the MAS-side ingest, the Monitor connectors and the edge deployments the OT team has agreed to.

We do not deliver your segmentation programme

Zone architecture across a plant estate is a separate discipline with its own funding. We design one flow to sit correctly inside what you have, and we say when what you have cannot carry it yet.

MAS IoT and OT connectivity, frequently asked questions

How long does the connectivity layer take?
On one site with a working historian, the schedule is drafted inside two weeks and signed in four to eight. That elapsed time belongs to the change boards rather than to engineering. The collector, the ingest path and the T1 to T5 demonstration then take three to four weeks. By month six the work is usually the second and third asset class, added under a schedule that is already approved.
Which direction does data flow?
Out of the OT environment only. One outbound session is opened from the lower-trust side towards the ingest endpoint, with no inbound session into the OT zone, no listening port on the OT side and no remote access route created. Nothing we deliver writes a setpoint or a command towards the plant.
What exactly crosses the boundary?
Only what the data-flow schedule names: an agreed tag list, at an agreed sample rate, carrying timestamp and quality flag, with an agreed retention and destination. Adding a tag is a change that takes the same approvals as the original design.
Who signs the schedule off?
The historian or control systems owner, OT cybersecurity, the network owner, the OT change board, IT security, and the safety authority where the assets are safety-related. That list is why the schedule is written before anything is engineered.
What if a site has no historian?
That gap is scoped as its own project. Reading operational values from the control layer to work around a missing historian puts the acquisition path inside the zone that has to stay untouched. OT cybersecurity is now an asset management problem sets out the position.
Can MaxIron host and operate this layer?
The MAS-side components, meaning Monitor connectors, ingest pipelines and edge container deployments, run on the same managed cloud as the rest of MAS. SCADA and historians stay owned and operated by the OT team.
Our SCADA estate is fragmented. Where do we start?
On one or two asset classes where the historian data is already good enough to land Monitor or Predict, proving the pattern before it is extended. Consolidating an OT estate first is a longer programme, and neither Monitor nor Predict is waiting for it.

Bring your OT engineer to the first call.

Bring the person who owns the control network and the person who owns the historian. We walk the four hops above with them, take the objections as design input, and name the asset class that can be landed in MAS first without touching the control layer.

Bring this to the first call

  • One site, and what sits at each hop: control layer, historian, DMZ, enterprise
  • A tag list, or an export of historian points, for one asset class
  • Your zone and conduit or segmentation documentation, however partial
  • The change boards a flow like this has to pass
  • What an earlier project was refused, and the reason given