JUNE 2026 • IT Hub Engineering
USB and Removable Media in Industrial Environments: Real Risk, Practical Policy
Years of cybersecurity effort can be undone by one USB stick plugged into an HMI. Removable media is the classic blind spot in OT security because it bypasses every network control you can build - the threat never touches the wire.
Why It Is Such a Problem
- Air-gapped networks are usually USB-connected networks in practice.
- Vendor engineers carry project files and, unknowingly, malware from other sites.
- Antivirus on OT hosts is often disabled for compatibility, so the stick is never scanned.
A Policy That Works
- Ban direct use by default. Media must pass through a dedicated, up-to-date scanning workstation (the clean station) before entering the OT area.
- Control ports: disable USB mass storage on HMI and engineering workstations via policy or endpoint control software; allow only whitelisted devices where genuinely needed.
- Log and audit: know which stick, which user, which machine, and what was copied. If you cannot answer those questions, you do not have a policy, you have a hope.
- Prefer network transfer: where a secure file-transfer path exists (DMZ share, signed packages), make it the default and treat USB as the exception.
Vendor Management
Include media rules in vendor contracts and onboarding: no personal drives, files delivered through approved channels, scanning mandatory. The vendors who complain are usually the ones whose machines most need the control.
#cybersecurity
#usb
#policy
#ot