scieee AI-readable full text Open interactive document viewer

INTEGRATION OF AUTOMATION AND NETWORK SECURITY IN INDUSTRIAL IT SYSTEMS: A CASE STUDY AT AGNELO ENGENHARIA (2022–2024)

Maycon A. Zuliani

Abstract

This article examines the integration of automation processes and network security measures within the ITinfrastructure of Agnelo Engenharia between 2022 and 2024. As the company expanded its internal systems anddigital workload, legacy network models and unsegmented communication paths exposed vulnerabilities incritical operational environments. Through a structured redesign guided by cybersecurity and automationprinciples, the IT department implemented VLAN segmentation, firewall hardening, encrypted remote access,and enhanced SCADA communication reliability. The study documents the methodology adopted, presentsmeasurable results, and discusses the interplay between security and automation in industrial IT environments.

Full text

Volume-09 Issue 07, July-2025 ISSN: 2456-9348 Impact Factor: 8.232 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [1167] INTEGRATION OF AUTOMATION AND NETWORK SECURITY IN INDUSTRIAL IT SYSTEMS: A CASE STUDY AT AGNELO ENGENHARIA (2022–2024) Maycon A. Zuliani Senior Systems and Network Analyst; IT Infrastructure and Cybersecurity Specialist, São Paulo, Brazil ABSTRACT This article examines the integration of automation processes and network security measures within the IT infrastructure of Agnelo Engenharia between 2022 and 2024. As the company expanded its internal systems and digital workload, legacy network models and unsegmented communication paths exposed vulnerabilities in critical operational environments. Through a structured redesign guided by cybersecurity and automation principles, the IT department implemented VLAN segmentation, firewall hardening, encrypted remote access, and enhanced SCADA communication reliability. The study documents the methodology adopted, presents measurable results, and discusses the interplay between security and automation in industrial IT environments. Keywords: Industrial Automation, Network Security, SCADA, Cybersecurity, VLAN Segmentation, Industrial IT Systems. INTRODUCTION Industrial environments increasingly depend on interconnected systems that combine automation, real-time monitoring, and digital communication. However, integrating these domains without proper security practices introduces operational and cybersecurity risks, especially in companies that previously relied on flat networks or legacy infrastructure. Between 2022 and 2024, Agnelo Engenharia—where Maycon Antonio Zuliani works as a Systems and Network Analyst—undertook an infrastructure modernization effort to support higher system availability, faster internal processes, and secure remote connectivity. Prior to these improvements, the company's network exhibited issues such as single-layer firewall control, unencrypted industrial communication, and decentralized monitoring mechanisms. The integration project sought to link automation and security without compromising operational continuity—an essential element in engineering environments handling sensitive internal systems. OBJECTIVES The project was guided by four primary objectives: 1. Increase security of industrial and administrative networks through segmentation and updated security controls. 2. Improve operational performance by stabilizing SCADA communication and reducing latency. 3. Enable secure remote access for maintenance and system monitoring. 4. Establish a foundation for long-term growth and future technology adoption, including virtualization, cloud integration, and advanced monitoring tools. METHODOLOGY This The methodological structure adopted in this study follows a multi-layered case-study approach, integrating elements of applied research, engineering analysis, and cybersecurity diagnostics. The method reflects real interventions performed within Agnelo Engenharia’s operational environment between 2022 and 2024. To maintain scientific rigor, the methodology was divided into sequential phases that align with industry- Volume-09 Issue 07, July-2025 ISSN: 2456-9348 Impact Factor: 8.232 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [1168] recognized frameworks, including NIST SP 800-82 and ISA/IEC 62443, both of which provide guidance on securing industrial communication networks. The approach encompassed (a) technical audits, (b) system instrumentation and measurement, (c) iterative implementation cycles, and (d) continuous validation of security and automation performance. 3.1 Phase 1 — Assessment and Baseline Characterization (2022) The first phase consisted of a deep diagnostic assessment of Agnelo Engenharia’s legacy IT-OT environment. This step was essential for identifying systemic vulnerabilities, architectural inefficiencies, and operational bottlenecks. The assessment comprised four analytical components: a) Network Topology Mapping A full mapping of logical and physical network segments was conducted, documenting: • traffic flow between PLCs, HMIs and administrative endpoints; • interdependencies across subnets; • unmanaged switches and legacy routing elements; • undocumented connections between automation layers and corporate IT systems. This allowed the identification of cross-domain routes susceptible to lateral movement — one of the primary risks described in NIST SP 800-82. b) Vulnerability Identification in Industrial Protocols The communication between PLCs and HMIs was inspected through packet analysis tools to detect weak or unencrypted protocols (e.g., Modbus/TCP). Key findings included: • lack of authentication mechanisms between controllers; • plaintext transmission of sensor data; • susceptibility to replay or man-in-the-middle attacks; • absence of application-layer filtering. These vulnerabilities directly contradicted the layered security principles proposed in ISA/IEC 62443. c) Performance Diagnosis (Bandwidth, Latency, Stability) Objective metrics were collected using SNMP polling, log extraction and real-time monitoring dashboards. The assessment demonstrated: • bandwidth saturation peaks during administrative traffic bursts; • instability in SCADA polling (random communication errors); • intermittent latency spikes affecting operator feedback loops. This established a measurable baseline for performance improvement. d) Firewall and Access Control Evaluation The pre-existing single-layer firewall had permissive rules, lacked industrial DPI capabilities, and did not enforce segmentation by function. The access control model was also predominantly static, without centralized authentication or identitybased policies. 3.2 Phase 2 — Implementation and Controlled Deployment (2023) Volume-09 Issue 07, July-2025 ISSN: 2456-9348 Impact Factor: 8.232 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [1169] The second phase involved the stepwise integration of automation and network security safeguards. All deployments followed an iterative approach to prevent downtime in mission-critical industrial systems. a) Segmentation Through VLAN Architecture A new logical architecture was defined to separate: • automation network (PLCs, HMIs, SCADA servers); • administrative network; • VoIP and auxiliary systems; • guest and contractor networks. Inter-VLAN traffic was routed exclusively through firewalls, preventing unauthorized traffic propagation. b) Industrial Firewall Configuration with DPI Cisco ASA and FortiGate appliances were configured with policies aligned to industrial protocol parameters. Enhancements included: • deep inspection for SCADA protocol anomalies; • rate-limiting and flood protection; • micro-segmentation aligned with automation zones and conduits; • event correlation rules. This is consistent with the defense-in-depth model highlighted in Kim & Park (2018). c) Deployment of Secure Remote Access (VPN) Encrypted tunnels were implemented using IPsec, enabling maintenance access without exposing internal industrial assets to the public Internet. Additional safeguards included: • MFA for privileged accounts; • restricted time-bound access for contractors; • logging of all remote sessions. d) Firmware Updates and SCADA Hardening Legacy firmware components were updated, introducing: • enhanced authentication; • secure boot mechanisms; • correction of previously exposed vulnerabilities. This step reduced the attack surface and improved device integrity. 3.3 Phase 3 — Optimization, Monitoring and Continuous Improvement (2024) The final phase focused on institutionalizing continuous cybersecurity and operational improvement mechanisms. a) Centralized Logging and SIEM Integration Volume-09 Issue 07, July-2025 ISSN: 2456-9348 Impact Factor: 8.232 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [1170] System events from firewalls, servers, PLCs, and SCADA endpoints were consolidated into a SIEM platform. This enabled: • real-time detection of anomalies; • correlation of events across IT-OT boundaries; • automated alerting and incident classification. b) Policy Review and Access Governance Security policies were updated to reflect the new architectural model, including: • role-based access control for automation engineers; • periodic credential rotation; • updated firewall rule governance. c) Periodic Performance Audits SCADA communication, network latency, system uptime, and log integrity were audited regularly. These audits were used to refine configurations and validate effectiveness. Data for this study were obtained from: • extracted performance logs; • security event datasets; • interviews with operators and analysts; • maintenance records and incident reports. RESULTS AND DISCUSSION Service 4. Results and Discussion The modernization effort produced significant technical, operational, and cybersecurity improvements. The results are analyzed in two dimensions: quantitative performance gains and qualitative improvements in security posture and operational resilience. 4.1 Quantitative Technical Results Performance Indicator Before (2021) After (2024) Improvement Network uptime 97.2% 99.8% +2.6% SCADA communication latency 450 ms 230 ms –48.9% MTTR – Mean Time to Recover 3.5 h 1.2 h –65% Detected and blocked intrusion attempts N/A 37 — Interpretation of results: • The 2.6% increase in uptime, although seemingly modest, represents a substantial improvement in environments in which every minute of unavailability impacts operational continuity. • The 48.9% reduction in SCADA latency directly improved responsiveness for field operators, reducing delays in decision-making. • The 65% reduction in MTTR indicates that failures now have lower downtime impact due to improved network observability and segmentation control. • The detection of 37 blocked intrusion attempts demonstrates that the company previously had no visibility into external threats. Volume-09 Issue 07, July-2025 ISSN: 2456-9348 Impact Factor: 8.232 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [1171] 4.2 Qualitative Discussion a) Reinforcement of Security Posture Prior to the project, the absence of segmentation meant that any compromised administrative workstation could potentially reach automation systems. Post-implementation, the architecture prevented: • lateral movement across operational domains; • unauthorized network scanning; • cross-traffic contamination. This strong separation is fully aligned with ISA/IEC 62443 zone and conduit models. b) Stabilization of Industrial Communication Legacy flat networks frequently caused interference in PLC–HMI traffic. After segmentation and firewall DPI deployment, automation protocols operated in a controlled and predictable environment. The reduction in instability also minimized operator troubleshooting time, contributing to improved internal productivity. c) Improved Operational Governance The adoption of SIEM, centralized logging, and new RBAC models introduced governance mechanisms previously absent in the company. These mechanisms allow Agnelo Engenharia to: • track privileged activity; • correlate anomalies; • maintain audit readiness; • adopt structured incident response aligned with NIST SP 800-82 guidelines. d) Foundation for Future Technological Growth The redesigned architecture created the prerequisites for: • secure cloud backup integration; • virtualization of automation servers; • IIoT initiatives with encrypted telemetry; • predictive maintenance via monitored sensors. This aligns with contemporary approaches to Cyber-Physical Systems (CPS) described by Boyes (2015). ACKNOWLEDGEMENT The author extends his appreciation to Agnelo Engenharia for granting institutional support and access to technical infrastructure, operational data, and documentation necessary for the development of this study. The successful implementation of the integration strategies described in this article relied on the collaboration of the company’s IT and automation teams, whose practical insights and operational experience were essential in validating the technical approaches adopted. The author also acknowledges the participation of system operators and internal users who contributed valuable feedback during the assessment, deployment, and optimization phases. Their collaboration ensured that the Volume-09 Issue 07, July-2025 ISSN: 2456-9348 Impact Factor: 8.232 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [1172] findings presented accurately reflect the real-world challenges and performance characteristics of industrial IT environments undergoing modernization. CONCLUSION This case study demonstrates that effective integration between automation and network security is both a technical and strategic imperative for industrial organizations. The solutions implemented—VLAN segmentation, VPN encryption, and firewall hardening—delivered measurable improvements in performance, reliability, and cybersecurity. The success of the project at Agnelo Engenharia validates that security cannot be an afterthought in automation design. Instead, it must be embedded within the operational fabric of industrial IT systems, supporting innovation and resilience against evolving cyber threats REFERENCES [1] ISA/IEC 62443 – Industrial communication networks – Network and system security standards, International Society of Automation, 2018. [2] NIST SP 800-82r2 – Guide to Industrial Control Systems Security, National Institute of Standards and Technology, 2021. [3] Kim, J., & Park, S. (2018). “A Defense-in-Depth Approach to Industrial Network Security.” IEEE Transactions on Industrial Informatics, 14(6), 2472–2483. [4] Boyes, H. (2015). “Cybersecurity in the Industrial Internet of Things.” Journal of ICT, 3(1), 25–36. [5] Stallings, W. (2017). Network Security Essentials: Applications and Standards. Pearson Education.