Application Allowlisting in OT: 7 Proven Steps to Safer HMIs

Share:
Cybersecurity
Application Allowlisting in OT: 7 Proven Steps to Safer HMIs

Antivirus signatures chase known threats, but an operator station only ever needs a short, fixed list of programs. Blocking everything outside that list stops unknown malware, rogue tools and careless USB installs before they ever run.

AppLocker WDAC Golden Image Audit Mode

HMI and engineering stations run the same few programs for years, which makes them ideal for application allowlisting. Only approved executables, libraries, drivers and scripts are allowed to start.

Hello everyone, today we are going to learn how application allowlisting protects HMI, SCADA and engineering workstations, which Windows tools support it and how to roll it out without stopping the plant.
application allowlisting

What Is Application Allowlisting?

Application allowlisting is a security control that lets only approved programs run on a computer and blocks everything else by default. On an HMI or SCADA server, the approved list is short and stable, so the control fits industrial systems very well.

Older documents call it whitelisting, and Honeywell uses that term in its service note on better control system defense. The idea is the same, a default deny policy instead of a default allow policy.

Golden image allowlist policy deployed across identical HMI stations
Image credit: Wavestone

Wavestone points out that the control should cover executables, DLLs, drivers and scripts. Application allowlisting that blocks only EXE files leaves an easy path for malicious libraries and PowerShell.

It complements network defenses such as those in SCADA network security. Even if malware reaches the station, it cannot start.

Why Plant Workstations Suit a Default Deny Model

Wavestone reports that ICS workstations are often updated only every 1 to 2 years. Many SCADA workstations stay in service for more than 10 years on an obsolete operating system.

Such machines cannot rely on daily antivirus updates or fast patching. Application allowlisting, however, stays valid for the whole period between planned changes.

The IEC 62443 standard lists software restriction as a key system requirement. It also appears in most ICS cybersecurity standards.

Windows Tools Compared

AppLocker

Rule based control built into Windows, managed by Group Policy.

Best for: Windows 7 era HMIs
Legacy
WDAC

Windows Defender Application Control, enforced at kernel level.

Best for: Windows 10 or later stations
Modern
Vendor Tools

Commercial agents such as Trellix Application Control.

Best for: mixed and very old fleets
Agent
DCS Vendor Service

Allowlist packaged and tested by the control system vendor.

Best for: validated DCS nodes
Supported

Wavestone notes that WDAC needs Windows 10 or later, while AppLocker is the only native option on Windows 7. Older fleets often need a commercial agent.

Always check vendor approval of your application allowlisting policy first, because a blocked DCS service can freeze displays. This matters on engineering and operator stations.

Rule Types and What They Trust

Rule TypeTrustsStrengthWeakness
PublisherDigital signatureSurvives updatesUnsigned plant software
HashExact file fingerprintVery preciseBreaks after every update
PathFolder locationEasy to writeWeak if folder is writable

Prefer publisher rules for signed vendor software and hash rules for unsigned tools. Avoid path rules on folders that normal users can write to.

7 Steps to Deploy Application Allowlisting

1
Inventory Software
List every program, service and script on each station.
2
Build a Golden Image
Create one clean reference build per station type.
3
Generate Policy
Scan the image to create publisher and hash rules.
4
Run Audit Mode
Log would be blocks during normal operation for weeks.
5
Review Logs
Add missing items and remove unneeded ones.
6
Enforce in Stages
Switch one station at a time to block mode.
7
Manage Change
Update the policy with every patch or project change.

Wavestone recommends the golden image method, since identical HMI stations can share one policy. One clean build becomes the trusted reference for the whole group.

Audit mode is essential because rare functions, such as monthly reports, may run only once in a while. Pair enforcement with secure remote access so vendors cannot bypass it.

Rollout Effort Formula

Total effort = Stations × Hours per station
Working days = Total effort ÷ (Crews × Hours per day)

Example:
40 stations, 6 hours each for audit review and enforcement
Total effort = 40 × 6 = 240 hours
2 crews working 8 hours a day
Working days = 240 ÷ 16 = 15.0

Plan the work around shutdowns or low load periods. Redundant operator stations allow one to be changed while the other stays online.

Rollout Planning Calculator

Allowlist Rollout Duration
Result
Total effort 240 hours, about 15.0 working days

Add time for the audit period and log review, which usually runs for several weeks. The calculator covers only hands on station work.

Strengths and Limits of Application Allowlisting

Advantages
  • Blocks unknown malware and ransomware.
  • Needs no daily signature updates.
  • Fits long lived legacy stations.
  • Stops unauthorised software installs.
Limitations
  • Policy must follow every change.
  • Poor rules can block plant software.
  • Does not stop abuse of approved tools.
  • Needs vendor testing and approval.

Attackers often use trusted tools already on the machine, a tactic covered in types of cyber attacks. Restrict scripting hosts wherever possible.

Combine this control with the ideas of zero trust for OT and a regular SCADA security checklist review.

Honeywell Service Note PDF

PDF
Application Whitelisting for Better Industrial Control System Defense
Honeywell service note on control system hardening

Trellix Allowlist Setup Video

Staff training makes the policy stick, and free OT cybersecurity training is a good starting point.

Application Allowlisting FAQ

What is application allowlisting?
It is a default deny control where only approved programs, libraries, drivers and scripts may run. Everything not on the approved list is blocked automatically by the operating system.
Is allowlisting the same as whitelisting?
Yes, both terms describe the same default deny security control. The industry now prefers the word allowlisting, while older vendor documents still use whitelisting.
Why is it suited to HMI stations?
HMI stations run a small, fixed set of programs for many years. That stable list is easy to approve once and then enforce with very little ongoing effort.
Which Windows tool should I use?
WDAC suits Windows 10 or later stations, while AppLocker is the native choice on Windows 7. Very old fleets often need a commercial agent from a security vendor.
What is audit mode?
Audit mode logs every program that would be blocked without actually stopping it. Engineers use these logs to refine the policy before switching to full enforcement.
Does it replace antivirus?
It greatly reduces reliance on antivirus but works best alongside other layers. Network segmentation, patching and account control are still needed for good defense in depth.
What is a golden image?
A golden image is one clean reference build of a station type. The policy created from it is deployed to every identical station in that group.

Related Articles

External References

What We Learn Today

  • Application allowlisting lets only approved software run on plant stations.
  • AppLocker, WDAC and vendor agents suit different Windows versions.
  • Golden images, audit mode and change control make rollout safe.
I hope you like above blog. There is no cost associated in sharing the article in your social media. Thanks for reading!! Happy Learning!!

Leave a Reply

Your email address will not be published. Required fields are marked *