Table of Contents
ToggleWhen ransomware or a failed hard disk stops a plant, the only thing that matters is how fast you can rebuild the control system exactly as it was. A tested backup of every PLC, DCS, HMI and server turns a disaster into a planned recovery.
Control system files are the memory of a plant, and losing them can stop production for weeks. A disciplined OT backup and recovery plan keeps clean copies offline and proves they restore before an incident ever happens.

What Is OT Backup?
OT backup is the practice of taking regular, verified copies of everything a control system needs to run, such as PLC programs, DCS configurations, HMI projects, historian databases, server images and network device settings. Its purpose is simple, to rebuild any part of the automation system quickly after a cyber attack, hardware failure or human error.
Office IT backup protects documents and emails, while an OT backup protects the logic that opens valves and starts motors. A good plan begins with a complete list of devices, as explained in OT asset inventory, because you cannot back up what you do not know exists.

In a typical Indian plant, the engineering station, operator stations and controllers described in DCS components ES, OS and AS all hold unique files. Many run old Windows versions that cannot accept modern backup agents.
Why Plants Cannot Skip OT Backup Anymore
TechTarget, reporting on the Dragos OT Cybersecurity Year in Review, states that ransomware attacks against industrial organisations rose by 87 percent year over year. The same report counted ransomware groups targeting OT and ICS growing from 50 in 2023 to 80 in 2024.
Dragos also observed that victims who enforced strict network segmentation between IT and OT and performed offline backup testing recovered significantly faster. Segmentation is covered in the Purdue model for ICS cybersecurity, while this article covers the OT backup half.
Many plants without an OT backup discover during an incident that the newest PLC program exists only inside the running controller. If that controller is wiped, the logic changes made over years of tuning are lost with it.
What to Back Up in a Control System
| Asset | What to Copy | Typical Method | Suggested Frequency |
|---|---|---|---|
| PLC and safety PLC | Program, tags, hardware config, firmware version | Upload to engineering software, archive project | After every change, plus monthly |
| DCS controllers | Control database, graphics, alarm settings | Vendor backup utility on engineering station | After every change, plus monthly |
| HMI and SCADA servers | Project files, tag database, full disk image | Image based backup, project export | Weekly image, daily project |
| Historian | Archive files, configuration, tag list | Database backup, archive copy | Daily |
| Engineering workstations | Full disk image, licences, software versions | Image based backup | Monthly and before upgrades |
| Switches, routers, firewalls | Running configuration, firmware | Config export over console or SSH | After every change |
Historians deserve special care because they hold years of process data used for quality records and audits, as described in what is a process historian. Losing the server is painful, but losing the archive files can break regulatory traceability in pharma and power plants.
Types of OT Backup Copies
Sector level copy of a whole disk with the operating system.
PLC or DCS project saved with comments and hardware settings.
Selected folders such as recipes and reports.
Only the blocks changed since the last backup.
Settings from switches, firewalls and drives.
An image backup restores a dead HMI in less than an hour, but it does not replace a clean project archive of the controller. The difference between uploading from a running controller and working on a saved file is explained in PLC online and offline programming.
Always store the matching engineering software version and licence details next to each project archive. A backup that only opens in a version you no longer own is almost useless during a 3 am breakdown.
The 3 2 1 Rule for OT Backup Storage
The 3 2 1 rule for OT backup means three copies of critical data, on two different types of media, with one copy kept offline or immutable. Industrial Monitor Direct describes it as production data plus two backups, for example disk plus tape or disk plus immutable cloud, with one copy unreachable from the network.
N = number of servers and workstations imaged
Versions = backup generations kept on each copy
Copies = 3 for the 3 2 1 rule
Example:
N = 8, image size = 120 GB, project data = 5 GB, versions = 4, copies = 3
8 × 120 + 5 = 965 GB per generation
965 × 4 × 3 = 11580 GB
Total storage = 11580 GB, about 11.58 TB
Full images grow fast, so compression and incremental jobs matter. Keep an older generation too, since ransomware often hides for weeks.
7 Proven Steps to Build an OT Backup Program
RTO, the recovery time objective, is how long a system may stay down, and RPO, the recovery point objective, is how much recent change you can afford to lose. ProArch notes that many OT teams never define these targets, which leaves no way to judge whether an OT backup design is good enough.
Step one links directly with patching and change control, because every patch or logic change should trigger a fresh copy. The same discipline is described in OT patch management, where a verified backup is the first item before any update.
OT Backup Storage Calculator
Second Worked Example: Estimating Restore Time
Suppose an HMI server image of 120 GB must be restored from a USB 3 disk that delivers about 100 MB per second in practice. The copy takes 120000 ÷ 100 = 1200 seconds, or 20 minutes, before any checks.
Add about 30 minutes for booting and licences, plus 20 minutes to verify controller communication. The realistic RTO is near 70 minutes, so a 30 minute target needs a standby virtual machine.
Offline and Immutable Copies
Immutable storage cannot be changed or deleted until a retention period ends, even by an administrator account. NIST SP 800 82 Rev 3 lists backup storage and immutable storage among the data security capabilities for OT, because ransomware deliberately hunts for backups before it encrypts.
An offline copy is a disk or tape that is physically disconnected after the job, while one way transfer can be enforced with a data diode. Never keep the only backup server in the same Windows domain as the plant, since stolen domain credentials unlock both.
Domain controllers and historians must run before operator stations can log in. This sequence should sit inside your ICS incident response plan so that nobody improvises during a crisis.
Acronis notes that testing often needs production systems offline, so many OT backups are never fully validated. Booting the image in a sandbox avoids touching the running plant.
OT Backup Restore Testing Checklist
- Restore at least one server image to spare hardware or a virtual machine each quarter.
- Open every PLC and DCS archive in the correct engineering software version.
- Compare the restored program with the running controller using a compare tool.
- Verify historian archives open and show the expected date range.
- Record the actual restore time and compare it with the RTO.
- Update the runbook with every problem found during the test.
Industrial Monitor Direct puts it bluntly, a backup that has never been restored is not a backup but a hope. It recommends quarterly restore tests against the agreed RTO and RPO.
Keep one spare engineering laptop with all licensed tools installed, sealed and stored with the offline backups. During ransomware recovery, the normal engineering station is usually the first machine you cannot trust.
IEC 62443 and NIST Guidance on OT Backup
IEC 62443 3 3 includes system requirement SR 7.3 for control system backup and SR 7.4 for control system recovery and reconstitution. These requirements sit beside the zone and conduit design explained in IEC 62443 zones and conduits.
NIST SP 800 82 Rev 3, the Guide to Operational Technology Security published in September 2023, asks organisations to develop a recovery and restoration capability. It also states that a major sign of a good security program is how quickly the system can be recovered after an incident, a point echoed by cybersecurity standards for PLCs.
Advantages and Limitations of an OT Backup Plan
- Turns ransomware recovery into a known, timed procedure.
- Protects years of logic tuning and alarm settings.
- Supports audits and change control evidence.
- Reduces dependence on the original system integrator.
- Needs storage, time and trained people every month.
- Legacy systems may need manual or image based methods.
- Restore tests can need spare hardware or downtime.
- Backups hold sensitive plant details and must be protected.
Where OT Backup Matters Most in Indian Industry
Common Mistakes and Troubleshooting
A frequent mistake is storing OT backup files on a share that every workstation can write to, which lets ransomware encrypt them along with the plant. Separate zones and an industrial DMZ keep the backup server reachable only through controlled paths.
Label every archive with asset tag, date, software version and the name of the engineer who took it. Clear naming saves hours when you must pick the last clean copy under pressure.
NIST Guide to OT Security PDF
Video: Essential OT Backup Tips
OT Backup FAQ
It is the regular copying of everything a control system needs, such as PLC programs, DCS databases, HMI projects and server images. The copies let engineers rebuild any part of the system after an attack or failure.
Unlike office backup, it must respect plant uptime and old operating systems. It also needs the matching engineering software to make the files useful.
Controller project archives come first, because they hold the logic that runs the whole process. Next come HMI and SCADA projects, historian archives and full images of engineering workstations.
Network switch and firewall configurations are often forgotten. Without them, a redundant ring or a segmented network may not come back correctly after a full rebuild.
It means keeping three copies of critical data on two different types of media. One of those copies must be offsite, offline or immutable so ransomware cannot reach it.
For a plant, this could be the live system, a local backup server and a disconnected disk in a fire safe. Rotate the offline disk on a fixed weekly or monthly schedule.
A quarterly restore test of at least one server image and a sample of controller archives is a sensible minimum. Critical systems such as safety controllers may need a test after every major change.
Record the real restore time and compare it with the agreed recovery time objective. Update the written procedure with every problem you find during each test.
IEC 62443 3 3 contains requirement SR 7.3 for control system backup and SR 7.4 for recovery and reconstitution. Both expect backups to be taken, protected and usable for a full rebuild.
NIST SP 800 82 Rev 3 asks plants to develop a recovery and restoration capability. It lists backup storage and immutable storage among the data security capabilities for operational technology.
Most controllers allow an online upload of the program without stopping the process. The engineer must still follow the site permit and change control rules before connecting a laptop.
After the upload, compare it with the archived project to detect any unrecorded changes. Save the result with the date, software version and controller tag in the name.
Modern ransomware searches the network for backup servers and encrypts or deletes them first. A disconnected disk or an immutable store remains safe because the malware simply cannot reach it.
Dragos found that victims with offline backup testing and strict segmentation recovered much faster. That single offline copy often decides whether recovery takes days or many weeks.
Related Articles
- OT Asset Inventory Guide for ICS
- ICS Incident Response Plan for OT
- OT Patch Management for ICS
- IEC 62443 Zones and Conduits
- Data Diode for OT Network Security
External References
- NIST SP 800 82 Rev 3, Guide to Operational Technology Security
- Dragos: Ransomware Attacks Against Industrial Organisations Up 87 Percent, TechTarget
- Backup, Wikipedia
What We Learn Today
- An OT backup must cover PLC and DCS projects, HMI and SCADA servers, historian archives, engineering workstations and network device configurations, not just files on one server.
- The 3 2 1 rule keeps three copies on two media types with one copy offline or immutable, so ransomware cannot encrypt every version at once.
- An OT backup is proven only by a timed restore test, ideally every quarter, compared against the agreed recovery time and recovery point objectives.
