What problem does it solve?
Process historians (OSIsoft PI, Honeywell PHD, GE Proficy, AVEVA Historian) are high-value OT targets that often ship with insecure defaults like PI Trust authentication, exposed management ports, and unlogged data edits. This Skill guides the audit, hardening, and secure replication of historian servers so process data used for safety analysis and regulatory reporting stays protected.
Core Features & Use Cases
- Security Auditing: Scan historian network exposure (ports 5450, 5457, 443, 80, 3389, and more) and flag authentication weaknesses such as PI Trust entries and default piadmin accounts.
- Hardening Automation: Apply Windows Firewall rules, disable legacy authentication, and enable audit policies aligned with IEC 62443 and CIP-007 requirements.
- DMZ Replication Design: Configure unidirectional OT-to-DMZ data flows using data diodes or PI-to-PI connectors so enterprise users never touch the OT historian directly.
- Use Case: After a security assessment flags your Level 3 PI server as high-risk, use this Skill to audit exposed services, remove PI Trust entries, restrict RDP to a jump server, and verify DMZ replication is truly one-way.
Quick Start
Audit and harden the OSIsoft PI historian at 10.30.1.50, then verify DMZ replication is unidirectional.