top of page

Is Your Temporary Odorizer HMI Exposed to the Internet?

  • 6 minutes ago
  • 6 min read

Remote monitoring is one of the most useful capabilities available on a temporary natural gas odorization system. Operators can verify injection performance, review alarms, and respond to changing conditions without traveling to a remote site.

But remote access can become a major operational-technology risk when a PLC, HMI, web screen, VNC service, or programming interface is published directly to the public internet. A password-protected login page is not the same as a securely isolated industrial control system. If the internet can reach the login screen, automated scanners and unauthorized users can reach it too.

For equipment involved in natural gas odorization, operators should treat that exposure as a pipeline safety, compliance, and business-continuity concern.

Why internet-exposed odorizer HMIs create risk

Many industrial PLC/HMI combinations include convenient web-screen or remote-viewing features. These tools can work well on a protected private network, but the HMI should not be expected to serve as the security gateway for an internet connection.

A common exposure occurs when a cellular modem receives a public IP address and forwards traffic directly to the HMI. Even when a password is required, the embedded service remains available to anyone who discovers the address. Public IP addresses are routinely scanned, and exposed services may receive connection attempts without being specifically targeted.

CISA warns that internet-accessible industrial control systems, SCADA equipment, remote-access technologies, and IIoT devices increase operational and security risk. Its guidance recommends identifying internet-exposed assets and removing or restricting exposure when it is not operationally necessary. Read the CISA Internet Exposure Reduction Guidance.

What could happen to an exposed temporary odorizer?

The consequences depend on the HMI, firmware, application design, and whether remote users have monitoring-only or control privileges. Exposure does not prove that a system has been compromised, but it creates an unnecessary path to equipment that performs an operational function.

  • Automated scanning and repeated login attempts

  • Exhaustion of available HMI or remote-viewer sessions

  • An embedded web server or viewing service becoming unresponsive

  • Denial-of-service conditions that block legitimate operators

  • Unauthorized viewing of process values, alarms, or operating status

  • Attempts to access configuration, maintenance, or programming functions

  • Interruption of remote monitoring during a critical temporary operation

  • Reduced confidence in operating records and alarm history

If an exposed interface permits control, the potential impact becomes more significant. Unauthorized changes to injection settings, alarm limits, operating modes, or system availability could affect odorization performance.

Under-odorization can make a natural gas leak more difficult for the public to recognize. Over-odorization can contribute to odor complaints, false leak reports, emergency responses, and avoidable operational disruption. Cybersecurity therefore supports the same goals as good odorization practice: reliable equipment, controlled changes, verifiable performance, and public safety.

Is temporary odorizer cybersecurity a critical-infrastructure issue?

Natural gas pipelines are part of the nation’s critical infrastructure. That does not mean every public odorizer login is automatically a national-security incident. It does mean that internet-exposed control equipment should be treated as more than an ordinary website-security problem.

Temporary odorization systems may support pipeline commissioning, emergency bypasses, CNG supply, maintenance projects, odor-fade remediation, or other time-sensitive operations. Loss of monitoring or control can affect the project the odorizer was deployed to protect.

CISA has repeatedly advised industrial asset owners to minimize control-system exposure, place critical devices behind protective security controls, and use secure remote-access methods when access is required. See its industrial HMI security guidance.

How Burgess Pipeline Services approaches remote-access security

Burgess Pipeline Services designs remote odorizer access around a basic requirement: the PLC and HMI should not be directly exposed to the public internet.

Our systems use controlled, encrypted remote-access methods that place security protections between authorized personnel and field equipment. Routine monitoring is separated from administrative and programming functions, unnecessary services remain unavailable, and access can be removed when it is no longer required.

  • No direct public access to the odorizer PLC or HMI during normal operation

  • Encrypted remote communications

  • Controlled authorization for approved users and equipment

  • Separation of routine monitoring from administrative functions

  • Restricted access to programming and configuration services

  • Revocable access for lost devices and departing personnel

  • Secure configuration and recovery procedures

  • Commissioning tests that verify unnecessary public services remain closed

Specific security configurations are not published because those controls form part of the system’s protective design. Customers can receive appropriate security information during project planning, cybersecurity review, or commissioning.

A password-protected web screen is not a complete security architecture

A strong HMI password remains important, but it should not be the only protection. Direct internet exposure still permits outside systems to reach the service, initiate connections, test credentials, and interact with the embedded device.

A stronger design prevents unauthorized internet traffic from reaching the PLC or HMI in the first place. The control equipment remains behind the security boundary instead of being expected to function as the security boundary.

Questions distribution operators should ask

Before temporary odorization equipment is connected to a live pipeline, the operator should understand how remote access works and which services are reachable from outside the site.

  1. Is the PLC or HMI directly accessible from the public internet?

  2. Which services and modem ports are publicly reachable?

  3. Can an outside network reach the web screen, remote viewer, or programming interface?

  4. Is remote access protected by a controlled encrypted connection or only by an HMI password?

  5. Can access be limited to approved personnel and assigned equipment?

  6. Can access be removed promptly when a device is lost or an employee leaves?

  7. Are programming and project-download services disabled during normal operation?

  8. Are configuration backups stored securely?

  9. Is there a documented process for reviewing and removing access?

  10. Has the public address been tested to confirm that unnecessary HMI services are closed?

If these questions cannot be answered clearly, the operator may not have enough information to evaluate the exposure created by the temporary equipment.

How to verify an odorizer is not publicly exposed

Operators should include remote-access security in the equipment acceptance process rather than treating it as an optional IT review.

  • Document every remote service required for operation

  • Confirm who owns and administers the cellular connection

  • Test the public address from a network outside the project site

  • Verify that PLC, HMI, programming, and management services are not publicly reachable

  • Confirm that authorized remote access still works through the approved secure method

  • Record the accepted configuration and retain a protected backup

  • Repeat the review after firmware changes, modem replacement, or configuration imports

This review should be performed without disrupting a live odorization process. Any firewall, router, HMI, or remote-access change should follow the operator’s management-of-change and operational testing requirements.

Protecting remote access without sacrificing visibility

Temporary odorization equipment often needs reliable remote monitoring. The solution is not to eliminate useful visibility; it is to provide that visibility through a controlled path that does not publish the control system to the internet.

A secure design allows authorized personnel to monitor the equipment while reducing exposure to automated scanning, unauthorized connection attempts, and unnecessary public services. It also gives the equipment owner a practical way to review and revoke access over the life of the project.

Verify your temporary odorizer’s exposure

Distribution operators should know exactly how temporary equipment connects to the internet and which services are accessible remotely.

Burgess Pipeline Services can help operators review temporary odorizer remote-access security, identify publicly exposed HMI services, remove direct PLC/HMI internet exposure, separate routine monitoring from administrative access, verify that unnecessary services are closed, and document cybersecurity commissioning tests.

Do not wait for an HMI lockup or suspected intrusion to discover that control equipment has been exposed to the public internet.

Contact Burgess Pipeline Services at info@burgessps.com or (951) 587-5707 to review the remote-access security of temporary natural gas odorization equipment.

Frequently asked questions

Should an odorizer HMI be accessible from the public internet?

Normally, no. The PLC and HMI should remain behind protective security controls. When remote access is required, it should use a controlled and encrypted method appropriate for operational technology.

Is an HMI password enough to secure a temporary odorizer?

A password is useful but should not be the only protection. Direct exposure still allows outside systems to reach and interact with the HMI service.

Can secure access still support multiple field odorizers?

Yes. A properly managed remote-access program can authorize approved personnel for assigned equipment without directly publishing each PLC or HMI to the internet.

What should an operator request from a temporary odorizer provider?

Request a list of required remote services, confirmation that the PLC/HMI is not directly public, an access-removal process, protected configuration backups, and documented commissioning tests.

 
 
bottom of page