Recovery sequence
What you actually do when you have to recover.
You are standing in front of a plant that will not restart until the engineering layer comes back. The SCADA project files, the HMI images, the workstation state, the controller configs. The copies you would normally reach went down with the network. This is how you get the one copy that did not.
What you are recovering from
Four cold storages sit inside the unit. Each holds a full generation of the engineering layer, on the cadence you set: daily, weekly, monthly, matched to how often your configs actually change. Three of the four stay powered off and physically disconnected at all times. One spins up, and only while it is being written. On the bad day you have four known-good generations, and none of them was reachable from your production network, your recovery environment, or anything an attacker could reach from the outside.
The restore, step by step
- 1. Go to the unit. Every control lives on the front-panel touchscreen, on-prem, in your hands. There is no remote control path and no network login, so there is no credential to steal.
- 2. Connect a clean target. A rebuilt workstation, or a sandbox machine kept off the production network. It connects to the outward-facing side of the unit over USB 3.1.
- 3. Pick the generation. Choose which of the four copies to bring back: last night's, last week's, the last monthly — the last-known-good one from before the failure reached anything.
- 4. The copy mounts as a plain drive. The outward-facing side presents your selected data as an ordinary external drive. Nothing runs, nothing executes, nothing phones out.
- 5. Two logs, so you can reconcile. One log lists what was written to that cold storage and when. The second lists what you asked to pull back. You check one against the other before you trust a single file.
- 6. Pull and rebuild. Copy the project files back. Reload the HMI image. Restore the controller configs. Bring the workstation back to the state it held before the bad day, from a copy nothing on the network could reach.
What bounds the time
Restore speed comes down to two things you can see: how much data, and USB 3.1 throughput. That is the whole list. No vendor ticket, no queue, nobody flying out. For the engineering layer, the part that gates the restart, that is the difference between a long afternoon and the week you just spent.
What you are not doing
You are not hunting for the password to a tape nobody wrote down. You are not restoring from a copy that sat on the same network and went down with it. There are no credentials to wait on, because the unit never had a network login in the first place.
Walk through your recovery scenario with us.
We will show you what the restore sequence looks like for your environment, your data volumes, and your OT stack.