Operational Technology
Pages
Page 23 of 37
Cloud-hosted supervisory control and data acquisition (SCADA)

This guidance is for operational technology (OT) organisations that are considering migrating their supervisory control and data acquisition (SCADA) solution to the cloud. OT organisations can use this guidance to help determine the suitability of cloud solutions.
Introduction to ‘cloud-hosted SCADA’
Cloud-hosted supervisory control and data acquisition (SCADA) is an emerging area with varying levels of maturity and adoption across operational technology (OT). Cloud-hosted SCADA can include a range of scenarios from simple data processing and enrichment, through to a full stack deployment where control of physical OT assets is possible.
Organisations are increasingly looking towards the cloud to solve the challenges presented by ever more connected infrastructure. The following guidance aims to identify some of the key considerations required before deciding on migrating SCADA to the cloud.
This guidance does not aim to provide a definitive view on whether SCADA in the cloud is the correct route for every OT organisation. However, it will help you to:
- identify the benefits the cloud can bring (as well as some of its unique challenges)
- make a risk-based decision before implementing cloud-hosted SCADA (of which cyber security is a core consideration)
Note:
Although OT-specific considerations are highlighted in this guidance, cloud-hosted SCADA and commodity IT security in the cloud share a lot in common. For this reason, the NCSC’s cloud security guidance should also be applied.
Threat to SCADA
SCADA forms the basis for data collection and control across critical national infrastructure (CNI), as well as in other cyber-physical systems. These solutions are responsible for the effective monitoring and controlling of physical distributed assets that have real-world effects.
Due to the criticality of their work, OT organisations that host CNI are at a high risk of targeted cyber attacks. As the NCSC's Annual Review 2023 stated, “it is highly likely the cyber threat to UK CNI has heightened in the last year”. In 2023, the NCSC also released a joint advisory with CISA (the US’s Cybersecurity and Infrastructure Security Agency), highlighting the risks posed by China against UK CNI.
This persistent and elevated threat means cyber security needs to be at the forefront of all decisions in both CNI and wider cyber-physical systems, and you should understand the challenges that a shift to the cloud will involve.
Moving to the cloud doesn’t simply change where a SCADA system is hosted; it fundamentally alters the traditional management, security boundaries, connectivity model, and access control mechanisms, as the system is now internet-connected.
- Legacy SCADA solutions were designed to be ‘air-gapped’, isolated from both the public internet and the organisation's enterprise networks.
- Current SCADA solutions are designed to be logically separated and protected, with controlled and limited access across zone boundaries.
- A cloud SCADA solution needs to be able to ensure this controlled and limited connectivity is maintained and monitored.
Sections in this guidance
- Understanding the business drivers and cloud opportunities Identifying and understanding your organisation's use case for ‘cloud-hosted SCADA’ so that adequate controls can be put in place.
- Organisational readiness Understanding if the organisation has the skills, people, and policies to support a shift to the cloud.
- Technology and cloud solutions suitability
Understanding if your technology is suitable for migration and how your cloud solution should be architected with considerations for its new environment.