Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Keep programmable logic controllers (PLCs) off the public internet. Separate operational technology (OT) from IT and public-facing networks, and route any necessary connections through a controlled, monitored boundary. Before changing network rules, inventory the systems and communications operations depend on; then allow only explicitly required connections and log them.
What OT network segmentation should accomplish
Segmentation is the separation of network areas, combined with controls on the traffic that can cross between them. For a water or wastewater utility, the goal is to prevent public-facing systems or general IT access from creating an unrestricted path to PLCs and other OT, while preserving the communications operators need to run and support the process.
There is no single topology or product that fits every utility. EPA and CISA guidance recommends OT/IT separation, default-deny connections to OT unless specifically allowed, and monitored, logged intermediary controls between the environments. The design should reflect the utility’s actual architecture and operational requirements.
1. Map assets and operational communications
Start by documenting what is connected and what must communicate before defining permitted flows. CISA, EPA, and FBI list OT/IT asset inventory and cybersecurity assessments among their recommended actions for water and wastewater systems.
#1 Best Overall
- Inventory OT and IT assets, including PLCs, human-machine interfaces (HMIs), engineering workstations, servers, and network equipment.
- Identify any PLCs or HMIs reachable from public-facing networks, and record vendor connections and other remote-access paths.
- Map the communications operations rely on: which systems need to connect, for what purpose, and across which network boundaries.
- Record the current network layout and ownership of each connection so proposed rules can be checked with the people responsible for operations and support.
This inventory is the basis for narrow allow rules. Without it, a default-deny change may block required operations, while broad exceptions can undermine the separation it is meant to create.
2. Define boundaries and permitted flows
Draw a clear boundary between OT and IT, and identify every path that crosses it—including paths used by remote operators, vendors, or support staff. Place an appropriate control at each connection path rather than relying on the network boundary to exist only on a diagram.
Use a default-deny approach for connections to OT: deny access unless a specific operational need has been identified and approved. For every exception, document its purpose and the systems involved. EPA’s 2024 guidance recommends routing OT–IT connections through an intermediary that is monitored and logged.
Rank #2
- 【◆Powerful Celeron N2840 Processor: N2840 Processor, 2 Cores 2 Threads, 1M Cache, Max Turbo Frequency 2.58 GHz, TDP 7.5 W. Compatible with OPNsense, Linux, Windows,ESXI, OpenWrt and other systems. Press "Delete" key to enter BIOS setup, supports Auto Power On, Wake On Lake, GPIO, PXE
- 【◆1GbE LAN: Mini Router PC with 2*Realtek RTL8111H network card chip full UDE 1000M with filter connector.Soft Router can monitor network data, improve network security, powerful and widely used.
- ◆DDR3L Memory & Large Storage Capacity: Firewall box computer with 1 x DDR3L SO-DIMM memory 1333/1600MHz, 1xMSATA3.0 SSD+1x2.5''SATA3.0 SSD/HDD.
- ◆UHD Graphics & Dual Display: N2840 processor integrated UHD Graphics, HD and VGA dual display interfaces support 4K@60Hz.
- ◆Rich interfaces: 2 x1000M Realtek RTL8111H-LAN,2 xUSB3.0, 4 xUSB2.0, HDMI,VGA,AUDIO supports data storage and system boot.
Do not treat a DMZ, firewall, or VPN label as proof that a path is appropriately restricted. Check that the deployed control actually limits the connections you intend to permit and produces logs that can be reviewed.
3. Remove direct public-internet access to PLCs
Do not leave PLCs directly reachable from the public internet. CISA and partner agencies’ advisory on internet-exposed PLCs calls for disconnecting PLCs from the public-facing internet. If remote access is required, the advisory recommends placing a control in front of the PLC: “If remote access is required, implement a network proxy, gateway, firewall and/or virtual private network (VPN) in front of the PLC to control network access.” The advisory was last revised December 18, 2024.
As part of the change, check that the internet-facing route to each identified PLC has been removed or restricted at the relevant boundary. If the utility still needs remote connectivity, redesign that access through the controlled path described below rather than restoring direct exposure.
Rank #3
- 【Processor & OS】Firewall Mini PC with Intel J3710 CPU up to 2.64GHz, 4Cores 4threads 2MB L2 Cache, TDP 6.5w, supports AES-NI. It tested with pf-sens/opn-sense linux ubuntu and other popular open source os. ("DEL" key to enter BIOS)
- 【Interfaces】The firewall pc has 4 * Intel I226 lan ports, 2 * USB3.0 ports, 1 * RS232COM port, 2 * HD port, 1 * DC port. Equipped with VESA mount, you can install the micro pc behind the monitor to save space.
- 【Fanless Design】only 6.5W; fanless heat dissipation design, aluminum alloy shell, efficient and fast heat dissipation, which can withstand temperatures up to 60°C. support 24/7 hours working, no noise.
- 【RAM & Storage】The firewall router equipped with 8G DDR3 RAM, max support 8GB; 128GB mSATA SSD, up to 512GB. Not support HDD. Size:5.27 * 4.98 * 1.43 inches, Weigh:500g, small but powerful.
- 【12 Months Service】You will get a firewall pc and accessories,If you encounter any problems during the use, please contact us through Amazon, we have a professional and efficient team dedicated to serving you.
4. Put necessary remote access behind a controlled boundary
Remote access should pass through controlled infrastructure at the OT boundary, such as a DMZ or bastion host, with access limited to what the user and task require. CISA and EPA’s HMI fact sheet recommends a DMZ or bastion host at the OT boundary, multifactor authentication (MFA), IP allowlisting, and logging remote logins. CISA’s PLC advisory also names a proxy, gateway, firewall, or VPN as possible controls in front of a PLC when remote access is necessary.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match- Require strong authentication; use MFA where applicable.
- Use strong, unique passwords for accounts that provide access to the boundary or OT systems.
- Restrict connection sources with IP allowlisting where it is appropriate to the utility’s access design.
- Log remote logins and review the logs as part of the utility’s monitoring process.
- Allow only the connections needed for the approved task; do not use the remote-access path as a general bridge from IT into OT.
These are controls to evaluate and apply in context, not a claim that any one technology makes remote access safe by itself. A VPN, for example, is one of the options named by CISA; the utility still needs to control which connections it permits and monitor them.
5. Choose controls based on the network, not a universal ranking
Official guidance names several possible controls and patterns, but does not rank them or prescribe one topology for every utility. Evaluate options against the actual connection paths and operating needs.
Rank #4
- Low Power J6413 Processor: Glovary J6413 4L micro firewall appliance uses Celeron J6413 processor, 4 Cores, 4 Threads, up to 3.0 GHz. J6413 4L features low power consumption and high energy efficiency, making it suitable for long-term stable work and supporting Auto Power On
- 4 x i226V 2.5GbE LAN: J6413 4L firewall router with 4 x i226V 2.5GbE LAN provides higher network speed, faster data transfer, and smoother virtualization. J6413 4L also offers better performance for multi-VM workloads and more efficient multi-LAN routing
- 2 x DDR4 RAM & 2 x NVMe: J6413 4L network hardware firewall features 2 x DDR4 RAM SO-DIMM memory (up to 64GB), 2 x M.2 2280 NVMe SSD slots, and 2 x SATA 3.0 slots for 2.5" HDDs (SATA cables included), providing larger storage capacities and more efficient data management
- 2HD + USB-C 3 Display: J6413 4L firewall box PC with 2 x HDMI + USB-C 3 display interfaces, integrated UHD Graphics, supports multi-screen setups, enabling efficient, simultaneous display of network activity for better control and visibility
- Fanless Design Mini Size: Glovary J6413 4L firewall device with aluminium alloy body, fanless quiet running without noise. Its compact size (17.7 cm x 12.5 cm x 5.5 cm, 1.2 kg) makes it ideal for home labs and enterprise network security applications
| Control or pattern | What the cited guidance establishes | Questions to resolve for your design |
|---|---|---|
| Firewall | Named as a control that can be placed in front of a PLC for required remote access; intermediary controls should be monitored and logged. | Can it allow and deny the specific flows the utility needs, and support the required monitoring and logging? |
| Proxy or gateway | Named by CISA as a possible control in front of a PLC when remote access is required. | Where will it sit, what connections will it mediate, and how will access be controlled and logged? |
| VPN | Named by CISA as one possible control in front of a PLC for required remote access. | What systems and users can reach OT through it, and what additional boundary restrictions and monitoring are needed? |
| DMZ or bastion host | CISA and EPA recommend these patterns at the OT boundary for HMI protection; their fact sheet also recommends MFA, IP allowlisting, and logging remote logins. | Does the arrangement create a controlled, monitored point of access that fits the utility’s topology and operational constraints? |
These are evaluation questions, not a comparative ranking. Confirm protocol compatibility and operational fit before selecting or changing controls; the guidance does not endorse a particular product.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.6. Validate, document, and reassess
After implementing the boundary, verify that only approved connections work and that the intended monitoring and logging are available. Review the permitted flows with the people responsible for the affected operations so restrictions do not silently disrupt essential communications.
- Update the asset inventory and network documentation when devices, connections, or remote-access arrangements change.
- Revisit allow rules against current operational needs; remove exceptions that are no longer required.
- Review logs for remote logins and other traffic crossing the OT boundary.
- Conduct cybersecurity assessments periodically. CISA, EPA, and FBI include assessments and asset inventory in their water-sector action list.
The specific schedule and technical validation method are not prescribed in the cited guidance; set them to fit the utility’s systems, risks, and operational requirements.
Quick Recap
Official guidance
- EPA and CISA, EPA Guidance on Improving Cybersecurity at Drinking Water and Wastewater Systems (September 2024).
- CISA and partner agencies, IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities (last revised December 18, 2024).
- CISA and EPA, Internet-Exposed HMIs Pose Cybersecurity Risks to Water and Wastewater Systems (as of December 13, 2024).
- CISA, EPA, and FBI, Top Cyber Actions for Securing Water Systems (February 21, 2024).
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

