MAS suite · IoT and OT connectivity
What crosses the OT boundary, in which direction, and who signs it off
SCADA, historian and edge connectivity for IBM Maximo Monitor, Predict and Health. One tag schedule, one direction of travel, no inbound route into the OT zone, and a written list of what deliberately does not cross.
The controlling artefact
A tag that is not on the data-flow schedule does not cross. Adding one later takes the same approvals as the original design.
The schedule is written and signed before a collector is installed anywhere. It names every tag, its direction, its sample rate, its destination and the person who authorised it.
The signed document
An extract for one asset class, four boiler feed pumps at one site
DFS-01 rev C
Tag names are illustrative. A first schedule for one asset class usually runs to between 40 and 120 tags, and the five columns are the ones an OT change board reads. This is the artefact a reader can forward to their OT team without editing it.
| Field | Source | Target | Frequency | Owner |
|---|---|---|---|---|
| BFP1_DE_VIB_RMS | Site historian tag | Monitor time series | 1 min | Historian owner |
| BFP1_SUCT_PRESS | Site historian tag | Monitor time series | 1 min | Historian owner |
| BFP1_DISCH_TEMP | Site historian tag | Monitor time series | 5 min | Historian owner |
| BFP1_MOTOR_CURRENT | Site historian tag | Monitor time series | 1 min | Control systems engineer |
| BFP1_RUN_STATE | Site historian tag | Monitor time series | On change | Control systems engineer |
| QUALITY_FLAG | Historian, per value | Monitor, retained | Every value | Historian owner |
| TAG_TO_ASSET_MAP | Manage asset register | Monitor asset binding | On change | Reliability data owner |
Hop by hop
Four hops, one direction of travel, four signatures
The walk we give an OT engineer, in the order they ask for it. Site architectures differ and the design is always specific to yours. The direction of travel, the signature list and the second list under the table do not change.
| What moves | From | Direction | To | Signed by |
|---|---|---|---|---|
| Scheduled tag values, with timestamp and quality flag | Site historian, read-only account | → | Collector in the DMZ | Historian owner, who authorises the account, the tag scope and the read rate against site load |
| One authenticated session, opened from the lower-trust side | Collector in the DMZ | → | MAS ingest endpoint | OT cybersecurity, the network owner and the OT change board, against the zone and conduit model the site already runs |
| Time series, landed with quality flags intact | MAS ingest endpoint | → | Maximo Monitor, then Predict and Health | MAS platform owner and the IT security function |
| The mapping that joins a tag to an asset and location record | Manage asset register | → | Monitor asset bindings | A named mapping owner, appointed before design starts, because the mapping decays whenever a plant project renames something |
What deliberately never leaves the OT environment
- Setpoints, commands or writes of any kind towards the plant.
- Control logic, engineering configuration and project files.
- Any data path into or out of a safety instrumented system.
- Inbound sessions, listening ports on the OT side, or a remote access route for MaxIron.
- OT credentials and domain accounts.
- Unfiltered protocol traffic. Only the scheduled tags, at the scheduled rate.
Demonstrated, not described
Five failure modes demonstrated before handover
Each of these is a way an ingest path degrades in service. Every test runs in front of the people who will live with it, and the results form part of the handover pack alongside the runbook, the escalation path and a named owner on each side of the boundary.
- T1
Link loss between the DMZ and the ingest endpoint
- Passes when
- The collector buffers for the agreed window, then recovers on reconnection with no back-pressure onto the historian.
- Witnessed by
- Historian owner and OT cybersecurity
- T2
Buffer reaching capacity during a long outage
- Passes when
- Oldest values are discarded first. The collector does not block, and nothing queues towards the plant.
- Witnessed by
- OT cybersecurity and the network owner
- T3
Unplanned collector restart
- Passes when
- Recovery without manual intervention, and the gap recorded in Monitor rather than filled by interpolation.
- Witnessed by
- MAS platform owner
- T4
Clock skew between the historian and the ingest path
- Passes when
- The effect on the time series is shown, and every value is stamped from the agreed time source.
- Witnessed by
- Reliability engineer and the MAS platform owner
- T5
A plant project renames a scheduled tag
- Passes when
- The flow fails loudly inside one sample interval, instead of producing a gap somebody finds at the next audit.
- Witnessed by
- Historian owner and the tag-to-asset mapping owner
What it takes
One site, one asset class, first workshop to handover
The shape of engagement we run most often. Connectivity is costed as its own phase, ahead of any Monitor or Predict configuration, because that is the order the work actually happens in.
- Week one
- Tag workshop
- Weeks four to eight
- Schedule signed
- Weeks nine to twelve
- Ingest path live
- MaxIron team
- Two engineers, part time
- Tags in a first schedule
- 40 to 120
- By month six
- Asset classes two and three
The historian owner, a control systems engineer and a reliability engineer, in one room for two days.
The elapsed time sits with the OT change board, not with engineering.
Collector, ingest pipeline, the T1 to T5 demonstration and the handover pack.
One integration engineer and one MAS platform engineer.
One asset class at one site. Illustrative rather than a cap.
Added as changes under a schedule that is already approved, which is the reason for writing one.
What this needed from the client
- A historian account, scoped read-only to the agreed tags.
- A named owner for the tag-to-asset mapping, appointed before design starts.
- Change board slots booked early, because they set the date rather than we do.
- An OT engineer available to witness the five acceptance tests.
Scope and boundaries
Where we stop at the OT boundary
Four commitments an OT engineer can hold us to.
We do not write towards the plant
No setpoints, no commands, no control writes, in any pattern we deliver. Asset context travels from Manage as far as the ingest endpoint and no further.
We do not ask for inbound access to the OT zone
No inbound sessions, no listening ports on the OT side, no remote access route for MaxIron. Where the site risk assessment calls for it, a unidirectional gateway enforces direction in hardware rather than in a firewall rule somebody can widen later.
We do not operate your SCADA or historian
Plant-side systems stay with the OT team. We own the MAS-side ingest, the Monitor connectors and the edge deployments the OT team has agreed to.
We do not deliver your segmentation programme
Zone architecture across a plant estate is a separate discipline with its own funding. We design one flow to sit correctly inside what you have, and we say when what you have cannot carry it yet.
MAS IoT and OT connectivity, frequently asked questions
- How long does the connectivity layer take?
- On one site with a working historian, the schedule is drafted inside two weeks and signed in four to eight. That elapsed time belongs to the change boards rather than to engineering. The collector, the ingest path and the T1 to T5 demonstration then take three to four weeks. By month six the work is usually the second and third asset class, added under a schedule that is already approved.
- Which direction does data flow?
- Out of the OT environment only. One outbound session is opened from the lower-trust side towards the ingest endpoint, with no inbound session into the OT zone, no listening port on the OT side and no remote access route created. Nothing we deliver writes a setpoint or a command towards the plant.
- What exactly crosses the boundary?
- Only what the data-flow schedule names: an agreed tag list, at an agreed sample rate, carrying timestamp and quality flag, with an agreed retention and destination. Adding a tag is a change that takes the same approvals as the original design.
- Who signs the schedule off?
- The historian or control systems owner, OT cybersecurity, the network owner, the OT change board, IT security, and the safety authority where the assets are safety-related. That list is why the schedule is written before anything is engineered.
- What if a site has no historian?
- That gap is scoped as its own project. Reading operational values from the control layer to work around a missing historian puts the acquisition path inside the zone that has to stay untouched. OT cybersecurity is now an asset management problem sets out the position.
- Can MaxIron host and operate this layer?
- The MAS-side components, meaning Monitor connectors, ingest pipelines and edge container deployments, run on the same managed cloud as the rest of MAS. SCADA and historians stay owned and operated by the OT team.
- Our SCADA estate is fragmented. Where do we start?
- On one or two asset classes where the historian data is already good enough to land Monitor or Predict, proving the pattern before it is extended. Consolidating an OT estate first is a longer programme, and neither Monitor nor Predict is waiting for it.
Related capabilities
Related capabilities and components
Bring your OT engineer to the first call.
Bring the person who owns the control network and the person who owns the historian. We walk the four hops above with them, take the objections as design input, and name the asset class that can be landed in MAS first without touching the control layer.
Bring this to the first call
- One site, and what sits at each hop: control layer, historian, DMZ, enterprise
- A tag list, or an export of historian points, for one asset class
- Your zone and conduit or segmentation documentation, however partial
- The change boards a flow like this has to pass
- What an earlier project was refused, and the reason given