17/78 SUREWAVE SFC USER MANUAL
––
4 Cyber security
Overview
This product is designed to be connected to and to communicate information and data via net-
work interface.
It is customer's sole responsibility to provide and continuously ensure a secure connection be-
tween the product and customer network or any other network (as the case may be). Customer
shall establish and maintain any appropriate measures (such as but not limited to the installa-
tion of firewalls, application of authentication measures, encryption of data, installation of anti-
virus programs, etc.) to protect the product, the network, its system and the interface against
any kind of security breaches, unauthorized access, interference, intrusion, leakage and/or theft
of data or information.
ABB and its affiliates are not liable for damages and/or losses related to such security breaches,
any unauthorized access, interference, intrusion, leakage and/or theft of data or information.
––
Deployment guidelines
The recommended Cyber Security deployment for the SureWave SFC is for it to be only used in a
trusted network with restricted access. The user is responsible for creating a defense-in-depth
protection by allocating firewall solutions to each network.
For secure remote access, use a VPN connection – the SureWave SFC is not approved by ABB for
direct Internet connection. The user of the product should be aware that the unsecure nature of
the Modbus TCP protocol exposes the communication between the product and the control sys-
tem. Authentication and integrity of transmitted information is not provided by the proto-col.
This enables certain types of attacks, such as man-in-the-middle attacks, eavesdropping attacks
and replay attacks for instance. The main security is provided through monitoring the cyber se-
curity, topology (asset management) and correct operation of the data networks using the
cyber security monitoring modules and features of the firewalls and managed switches