Why Cybersecurity Follows the Data
An online dissolved gas analysis (DGA) monitor sits on the transformer and reports into the substation network — and increasingly into remote operations and cloud platforms. Because it is part of the substation information network, it inherits the same cybersecurity obligations as the systems around it. The framework that power utilities increasingly apply is the IEC 62443 series, a defense-in-depth standard for industrial automation and control systems (IACS). This article translates its key controls into concrete practice for online monitoring.
Zones and Conduits
IEC 62443 organizes security around zones and conduits. A zone is a group of assets with similar security requirements — for example, the online monitoring network versus the production control zone or the management information zone. A conduit is the communication path between zones. In practice, the online monitoring network should be reasonably isolated from other zones, with firewalls or security gateways deployed at the boundaries. Zone isolation contains the blast radius: if one device is compromised, the rest of the substation control network is not automatically reachable.
Identity, Authentication, and Least Privilege
Access control starts with identity. Devices should support user grading and account control at the device, station, and cloud-platform levels, applying the principle of least privilege — every user and every service gets only the access needed for its role. A field technician reading gas values does not need configuration rights; a commissioning engineer does not need the same privileges as a platform administrator. Minimal, role-scoped access reduces both accident and attack surface.
Communication Security: TLS and Minimal Exposure
Data in transit must be protected. The practical controls are:
- TLS encryption enabled on all remotely accessible channels, so readings and commands cannot be read or altered on the wire.
- Management ports minimally exposed — only the interfaces actually required for operation are reachable from outside the substation.
- Unnecessary services disabled — a monitor does not need an open telnet, debug, or file-sharing service in production; if it is not used, it is closed.
These are especially important for devices that support remote operation and maintenance, where the remote-access channel is the highest-value target and therefore a management priority.
Integrity Protection: Firmware Signing and Message Validation
Trusting the device itself is as important as protecting the network path. Firmware signature verification ensures that only genuine, vendor-signed firmware can be installed, blocking malicious or tampered images. Message validation protects the communication protocol from tampering and injection. Together these controls mean that a compromised channel cannot easily turn into a compromised device.
Logging and Auditing
You cannot investigate what you did not record. Devices should log logins, configuration changes, alarms, and maintenance operations, giving operators a traceable record for incident response and compliance. Audit logs turn a “security event” from a rumor into a reconstructable timeline, and they are a routine requirement in utility cybersecurity assessments.
Data Governance: Timestamps, Traceability, and Mark-Don’t-Delete
Cybersecurity is only half the story; the other half is keeping the data trustworthy for years. Good data governance for online DGA includes:
| Control area | Practice | Purpose |
|---|---|---|
| Zone isolation | Separate monitoring network; firewalls or security gateways at boundaries | Contain the blast radius of a compromise |
| Least privilege | Role-scoped accounts at device, station, and cloud levels | Reduce accident and attack surface |
| Communication security | TLS on remote channels; minimal port exposure; disable unused services | Protect data in transit |
| Integrity protection | Firmware signing and message validation | Prevent tampering and malicious firmware |
| Logging and auditing | Record logins, configuration changes, alarms, maintenance | Support traceability and incident response |
| Data governance | Complete timestamps, traceable calibration records, flag rather than delete anomalies | Preserve trend integrity and auditability |
Measurement data should carry integrity validation, unified timestamps, and traceable calibration records. Abnormal data — flushing transition segments, abnormal device self-test results — should be flagged rather than simply deleted, so the trend database is not silently polluted. Deleting anomalies hides both measurement noise and potential evidence; flagging preserves the trend and the story.
PAS DGA for online DGA monitoring
PAS DGA monitors are designed to be integrated as trusted members of the substation network, with firmware integrity, role-based access, and auditable logging aligned with IEC 62443 practice. The DGA-900 9-gas plus moisture L-PAS monitor supports secure integration into traditional and digital substations. For the standards landscape around DGA and monitoring, see IEC 60599 vs IEEE C57.104 and our L-PAS DGA white paper guide.
To discuss cybersecurity requirements for your monitoring project, contact PAS DGA.