Why this matters now
As industry faces an ever-increasing number of new challenges—workforce reductions, supply chain shortages, increased global competition, and more—operational technology (OT) teams are continually looking for ways to optimize their operations. Often this takes the form of new software at the edge, including AI tools and advanced analytics. Modern software is a critical steppingstone on the path to operational excellence.
As Daniel Smith explains in a recent article in Control Design, these solutions must be implemented with a strong cybersecurity foundation:
“The strongest security is implemented in layers and has overlapping mechanisms. It certainly must start with the hardware-validated root of trust, so that the following security layers have a strong starting point.”
This highlights that layered security is essential, but only when built on a strong foundational architecture.
Takeaway: Effective edge cybersecurity begins with a hardware-rooted foundation and extends through layered protections.
TL;DR
- Edge software is critical for operational optimization.
- Layered cybersecurity must start with a root of trust.
- Hypervisors enable secure workload separation.
- Containerization reduces vulnerability spread risk.
- Edge architectures give OT greater control over security.
Security and performance at the edge
One way to help deliver layered security is to implement the right technology for edge computing. Fit-for-purpose edge controllers like Emerson’s RX3i edge controllers are specifically built for secure edge computing.
“RX3i edge controllers use real-time hypervisor technology to run real-time deterministic control applications alongside PACEdge software for edge computing. The PACEdge software collects and preprocesses data close to the devices, enabling fast, low-latency distribution to local systems, reducing bandwidth usage. A hypervisor partitions two cores for the runtime and two cores for Linux. The system then uses Docker to containerize each of the applications on the PACEdge software, and a shared OPC UA data table manages communication between the two partitions.”
This architecture, driven by fit-for-purpose edge controllers and PACEdge™ software allows real-time control and edge computing workloads to coexist securely without compromising performance.
Takeaway: Hypervisor-based architectures enable secure partitioning of control and compute workloads at the edge.
That containerization is a critical differentiator for edge computing solutions. First and foremost, it helps isolate applications and their dependencies, reducing the risk and speed of spreading vulnerabilities.
In addition to the cybersecurity benefit, containerization makes deployment easier, allowing teams to access application marketplaces and deploy solutions without extensive IT expertise.
“Teams can put firewalls in and lock down traffic to the control system, but the exposure to the cloud is still risky and complicates operations and lifecycle maintenance. It is much easier to use an edge device that gives flexibility of configuration, empowering OT teams to take full control of their security posture.”
This reinforces the value of keeping control at the edge rather than relying heavily on cloud connectivity.
Takeaway: Edge-based architectures give OT teams greater control over security while reducing cloud-related risk.
Maintaining control without compromise
With advanced systems, teams can maintain strict networking isolation by separating real-time PLC activity from edge computing workloads while tightly controlling communication between them.
Hypervisor technology enables restricted communication channels, such as limiting traffic to OPC UA on specific ports, ensuring data exchange remains controlled and secure.
Takeaway: Secure edge architectures allow organizations to expand capabilities without compromising control or performance.
