Remote Access to SCADA Systems: Platforms, Protocols, and the Connectivity Layer
Who makes SCADA remote access software, how operators actually connect to field sites, the real-world data volumes involved, and the cellular hardware that ties it all together.
What remote SCADA access actually means
SCADA – Supervisory Control and Data Acquisition – is the software and hardware architecture used to monitor and control distributed industrial infrastructure. A water utility operating 200 pump stations, a DNO managing 400 substations, a solar developer running 30 ground-mount sites: all of them need to see live data and issue commands from a control room, without a technician physically on site at every location, every hour of the day.
Remote access has two distinct meanings in this context. The first is the day-to-day operational view: the SCADA HMI (human-machine interface) that operators watch on screens in a control room, pulling telemetry from remote sites over a WAN connection. The second is engineering or maintenance access: an engineer connecting from a laptop or a remote office to diagnose a fault, update configuration, or review historical data. Both use the same underlying connectivity but have different security and latency requirements.
This article covers both – the platforms that deliver remote SCADA access, the industries they serve, and then the connectivity layer that makes it possible for existing SCADA systems that were not designed with cellular in mind.
The three-layer architecture: field devices connect via the cellular connectivity layer to the SCADA platform and cloud, with remote engineers accessing the platform layer directly over VPN.
The SCADA platform landscape: who makes remote access software
The SCADA market is large, fragmented, and deeply entrenched in specific verticals. A water utility that deployed Wonderware in 2005 is unlikely to switch platforms. A DNO that standardised on Siemens WinCC a decade ago will buy more Siemens. What follows is an overview of the major platform vendors, the sectors they dominate, and how their remote access architectures work.
Ignition – Inductive Automation
Web-nativeThe fastest-growing SCADA platform globally. Ignition runs as a Java-based server with a browser-rendered HMI – Perspective – that works on any device without plugins. Remote access is built in: operators open a HTTPS session to the Ignition gateway. Common in water, wastewater, food and beverage, and manufacturing. The software licensing model (site licence, not per-client) has driven rapid adoption in the UK. Integrates natively with MQTT via the Sparkplug B specification, which maps well to cellular-connected remote sites.
AVEVA (formerly Wonderware / Schneider SCADA)
Enterprise / oil and gasAVEVA is the dominant platform in oil and gas, offshore, and large process industries. The product line includes AVEVA System Platform, AVEVA Historian, and AVEVA InTouch HMI. Remote access is delivered via AVEVA Connect – a cloud-hosted SaaS layer – or via traditional VPN to an on-premise server. AVEVA’s strength is in large, complex process plants with thousands of tags and multiple historian servers. Common in UK petrochemical, upstream oil and gas, and power generation.
Siemens WinCC and TIA Portal
Manufacturing / utilitiesSiemens WinCC is the HMI/SCADA layer within the TIA Portal ecosystem, which ties together Siemens PLCs (S7 series), drives, and instrumentation. Remote access is provided via Siemens Remote Service (SRS) and the TIA Portal’s built-in remote access capability. WinCC Unified – the newer web-based version – renders HMI screens in a browser, removing the requirement for a dedicated client install. Very common in UK manufacturing, automotive, and utilities where the PLC estate is Siemens S7.
Schneider Electric EcoStruxure Geo SCADA Expert
Utilities / DNOsFormerly ClearSCADA, acquired by Schneider Electric and rebranded. The dominant SCADA platform for UK Distribution Network Operators and water utilities. WebX is the browser-based remote access client. EcoStruxure Geo SCADA Expert is built specifically for geographically distributed infrastructure – it handles thousands of remote outstations efficiently even over low-bandwidth links. Deeply integrated with DNP3 and IEC 60870-5-101/104 – the protocols used in UK distribution networks.
GE Vernova – Proficy iFIX and CIMPLICITY
Power generation / industrialGE’s Proficy suite covers SCADA, HMI, historian, and MES. iFIX is the client-server HMI; CIMPLICITY is the alternative path favoured in power generation. Remote access uses Proficy Operations Hub – a web-based interface. Common in UK power generation, including gas turbine sites, and in large manufacturing facilities. GE Vernova also produces the Smallworld GIS platform used by UK DNOs for network mapping, which integrates with SCADA alarm data.
Rockwell Automation – FactoryTalk
ManufacturingRockwell’s FactoryTalk View is the HMI/SCADA layer for Allen-Bradley PLC environments. FactoryTalk Remote Access (FTRA) provides secure remote connectivity without requiring a VPN – it uses an outbound-initiated cloud relay. FactoryTalk Optix is the newer web-native successor. Common in UK automotive, pharmaceutical, and food and beverage manufacturing where the PLC estate is Allen-Bradley / ControlLogix. The Rockwell ecosystem favours EtherNet/IP over Modbus, which has implications for router and gateway selection.
Kepware / PTC
Protocol gateway / OPC UAKepware KEPServerEX is not a SCADA platform – it is an OPC UA server and protocol gateway. But it appears in almost every SCADA installation that bridges legacy serial devices to modern IP infrastructure. KEPServerEX connects to Modbus RTU devices, DNP3 outstations, Allen-Bradley PLCs, Siemens S7 controllers, and hundreds of other drivers, then exposes them as OPC UA endpoints or MQTT publishers. Remote SCADA platforms connect to Kepware rather than directly to the field device. PTC acquired Kepware in 2016 and has integrated it into the ThingWorx IIoT platform.
Inductive Automation Cirrus Link / MQTT Sparkplug
MQTT / IIoTCirrus Link (now part of Inductive Automation) produces MQTT transmission modules that publish SCADA data using the Sparkplug B specification over MQTT. This matters for cellular-connected sites: rather than polling a remote RTU over a VPN tunnel – which requires a persistent connection – the RTU publishes data to an MQTT broker when it has something to say. This publish-subscribe model is more efficient over cellular links with variable latency. Ignition consumes Sparkplug B data natively.
Smaller and sector-specific platforms
Beyond the tier-one vendors, a significant portion of UK SCADA installations run on specialist or sector-specific platforms. OSIsoft PI (now AVEVA PI System after the 2021 acquisition) is the dominant process historian – not a SCADA platform itself, but the data layer that many SCADA systems write to. Remote access to PI data uses PI Web API or PI Vision. Yokogawa and Emerson serve the refining and petrochemical sector with DCS platforms (CENTUM VP and DeltaV respectively) that include built-in remote access capability. Mipuz and Zetron serve public sector critical infrastructure in the UK. For smaller installations, particularly in water and agriculture, platforms such as ClearSCADA (pre-Schneider), Iconics Genesis64, and open-source options including OpenSCADA and ScadaBR are in active use.
Industries that depend on SCADA remote access
Understanding the SCADA market requires understanding the sectors. Each has different connectivity requirements, regulatory obligations, and tolerance for downtime.
Water and wastewater
UK water companies (Severn Trent, Anglian, Thames, United Utilities, Yorkshire Water, and others) operate thousands of remote sites: pump stations, booster stations, pressure reducing valves, service reservoirs, and treatment works. A typical water company may have 2,000-5,000 remote telemetry units. The dominant protocols are DNP3 and Modbus, with IEC 61850 appearing in newer installations. Connectivity has historically been over private radio (VHF/UHF), leased lines, or GPRS/2G. The 2G/3G sunset has forced widespread re-evaluation of the connectivity layer – the majority of new UK water sector SCADA connectivity is now 4G LTE. The dominant SCADA platform is Schneider EcoStruxure Geo SCADA Expert (formerly ClearSCADA).
Electricity distribution (DNOs)
UK Distribution Network Operators (National Grid Electricity Distribution, SP Energy Networks, Northern Powergrid, UKPN, Electricity North West, Scottish and Southern Energy Networks) operate the 11kV-132kV networks that distribute electricity to homes and businesses. Each substation contains IEDs (intelligent electronic devices) – protection relays, meters, and switching controllers – that communicate using IEC 61850 or DNP3. Remote access enables protection engineers to retrieve fault records, adjust protection settings, and monitor power quality without site visits. Security requirements under NIS Regulations and the Network and Information Systems Regulations are strict: multi-factor authentication, audit trails, and network segmentation are mandatory.
Oil, gas, and pipelines
Pipeline SCADA covers compressor stations, offtake points, block valves, and cathodic protection monitoring. Sites are often in remote rural or coastal locations where cellular coverage quality is variable. Protocols include Modbus, DNP3, and proprietary variants (BSAP, DF1). Latency requirements are relatively relaxed for most measurements (polling intervals of 30-300 seconds are typical for non-safety functions), but alarm response time matters: a leak detection algorithm may need sub-second data. AVEVA is the dominant platform at the upstream level; Schneider and GE Vernova appear in midstream pipeline operations.
Renewable energy and BESS
Solar farms, wind sites, and battery energy storage systems (BESS) generate substantial telemetry: inverter data, string-level monitoring, grid connection data, and environmental sensors. A 50MW solar farm may have 200+ data points per inverter, with 50-100 inverters on site. BESS sites add DNP3 SCADA comms for the grid operator (typically to the Balancing Mechanism or contracted demand response scheme). Under ENA Engineering Recommendation G100 and the requirements of Tactical Solution 2 controllable assets, BESS operators must maintain a live DNP3 connection to the network operator’s systems. Cellular connectivity is the primary medium for UK BESS installations where a dedicated leased line is not economic.
Manufacturing and Industry 4.0
Factory SCADA is usually on-premise and local network connected, but remote access for engineering support and multi-site production management has become standard. A production manager overseeing three sites, or a controls engineer providing remote support to a customer installation, needs the same secure remote access capability as a utility operator. OT security is a growing concern: a manufacturing plant connected to corporate IT networks provides an attack surface that was not present when SCADA ran on isolated serial networks.
How much data does SCADA actually use?
One of the most common misconceptions about SCADA over cellular is that it requires significant bandwidth. In practice, SCADA telemetry is extraordinarily lightweight by modern standards. The data volume is determined by three factors: the number of points being polled, the polling interval, and the protocol overhead per transaction.
| Application type | Points | Poll interval | Daily data (est.) | Monthly (est.) |
|---|---|---|---|---|
| Simple pump station | 20-50 | 60 sec | 2-8 MB | 60-240 MB |
| Water pressure zone | 50-150 | 30 sec | 8-25 MB | 240 MB – 750 MB |
| 11kV substation (IEC 61850) | 200-500 | Event + 5 min | 10-40 MB | 300 MB – 1.2 GB |
| Solar farm inverter data | 500-2000 | 15 sec | 50-200 MB | 1.5 – 6 GB |
| BESS with DNP3 + video | 300+ + CCTV | 1-5 sec + stream | 500 MB – 5 GB | 15 – 150 GB |
| Pipeline compressor station | 100-300 | 10 sec | 20-80 MB | 600 MB – 2.4 GB |
The figures above assume uncompressed Modbus or DNP3 polling. Modern MQTT-based architectures with change-of-value publishing (only transmitting when a value changes beyond a threshold) can reduce data volumes by 60-90% compared to fixed-interval polling. The implication for SIM selection is that a standard 1-2 GB/month industrial SIM is adequate for most single-site SCADA applications, with solar and BESS installations requiring larger data allowances – particularly if CCTV or video analytics are included on the same cellular link.
SCADA data volume estimator
The connectivity layer: connecting existing SCADA to cellular
The majority of operational SCADA systems in the UK were not designed with cellular connectivity in mind. They use serial protocols (Modbus RTU, DNP3 serial, IEC 60870-5-101) or early IP-based variants (Modbus TCP, DNP3 over IP, IEC 60870-5-104) over whatever WAN was available when the system was installed. Private leased lines, BT ISDN, Frame Relay, and private radio have all served as SCADA WAN technologies at various points in the last 30 years.
The job of the cellular router in a SCADA installation is to replace that legacy WAN connection and provide a secure, reliable IP path between the field site and the SCADA control centre or cloud platform. This sounds simple. In practice it involves protocol bridging, VPN termination, firewall configuration, and in many cases a step change in the security architecture of a system that has historically relied on physical isolation for protection.
The case for industrial cellular routers over consumer hardware
Consumer routers are occasionally pressed into SCADA service by integrators looking to reduce cost. This is a false economy. SCADA applications require:
- Industrial temperature range operation: -40C to +70C is common in outdoor cabinets. Consumer hardware is not rated for this.
- Dual SIM with automatic failover: loss of SCADA comms on a single SIM MNO outage is unacceptable for critical infrastructure.
- Hardware watchdog and auto-reboot: remote sites cannot have an engineer visit to cycle power on a locked-up router.
- VPN client built in: the router must terminate the VPN tunnel, not pass it through to a separate device.
- Serial port (RS232/RS485) or serial-to-IP conversion: many SCADA outstations still communicate over serial, not Ethernet.
- DIN rail mounting: SCADA control panels use DIN rail. Wall-mount consumer hardware does not fit.
- Remote management without SCADA traffic interruption: configuration changes and firmware updates must not drop the operational data link.
Milesight UR32 and UR41: a closer look
For the bulk of UK SCADA connectivity requirements – pump stations, substations, renewable energy sites, pipeline outstations – a CAT 4 or CAT 1 router covers the data volume and latency requirements without over-engineering. The Milesight UR32 and UR41 cover both ends of this requirement with a product line designed for industrial deployment.
The Milesight UR32 is a compact industrial router built around a CAT 4 modem (150 Mbps downlink, 50 Mbps uplink – far beyond what SCADA telemetry requires, but providing headroom for video, firmware downloads, and concurrent VPN traffic). It supports dual SIM with automatic failover, WireGuard and OpenVPN out of the box, RS232 and RS485 serial ports for direct connection to legacy SCADA outstations, and DIN rail mounting. The operating temperature range runs to -40C. This is the specification that matters for a pump station or a roadside cabinet: not peak throughput, but reliability in an unattended installation over five or ten years.
The Milesight UR41 uses a CAT 1 modem – deliberately. CAT 1 has a theoretical downlink of 10 Mbps and uplink of 5 Mbps, which is more than sufficient for SCADA telemetry and imposes lower power draw and lower module cost than CAT 4. For deployments where the site has a marginal power budget – solar-powered remote outstations, for example – CAT 1 is the correct choice. The UR41 retains dual SIM, serial ports, DIN rail mounting, and the full Milesight management stack (DeviceHub, Node-RED support, and the Milesight Development Platform for edge processing).
Both models support Milesight DeviceHub for centralised remote management – configuration, firmware updates, VPN provisioning, and reboot without requiring an engineer site visit. This is the equivalent of Teltonika RMS in the Milesight ecosystem, and it matters: a fleet of 200 cellular routers at remote pump stations can be managed from a single interface without disturbing the SCADA data flow.
See the full Milesight hardware coverage on IoTPortal and the IoTPortal router and gateway directory for specification comparisons.
A typical pump station or substation SCADA connectivity build: RTU/PLC connects via RS485 serial to the Milesight router, which terminates a VPN tunnel over 4G. Dual SIM provides resilience across two MNOs. Milesight DeviceHub handles remote router management separately from the SCADA data path.
SIM selection and fixed IP for SCADA
SCADA over cellular almost always requires a fixed (static) IP address on the SIM. The SCADA control centre needs to know where to find the remote site – a dynamic IP that changes on reconnection breaks the polling architecture. There are two ways to achieve this: a fixed public IP SIM (the SIM is assigned a routable, static public IP address by the MNO or MVNO), or a fixed private IP SIM on a private APN (the SIM gets a static private address on a network that only routes to your organisation’s infrastructure).
For SCADA applications, the private APN route is generally preferred. It provides a fixed IP address and keeps the SCADA traffic off the public internet entirely – the cellular link connects directly to the operator’s private WAN. This is the architecture used by most UK water companies and DNOs for new cellular SCADA deployments. The cellular router at the remote site connects to the private APN; the SCADA server connects to the same private network at the control centre end. No VPN is technically required because the traffic never traverses the public internet – though many operators run a VPN regardless, for defence in depth.
For smaller operators or where a private APN is not commercially available at the required scale, a fixed public IP SIM combined with a VPN is the standard approach. The router establishes a WireGuard or OpenVPN tunnel to a VPN concentrator at the control centre, and the SCADA polling traverses this encrypted tunnel.
See the IoTPortal guide to IoT SIM cards explained and the IoT SIM card directory for UK provider options.
The antenna: the component most likely to be underspecified
SCADA installations are not typically located in RF-friendly environments. A pump station is underground or inside a concrete building. A substation cabinet is a steel enclosure. A pipeline outstation is in a rural field with minimal nearby infrastructure. These environments attenuate cellular signals significantly – a steel cabinet can add 10-20 dB of loss to the signal reaching an antenna mounted inside it.
The supplied stub antennas fitted to industrial routers are adequate for bench testing. They are not adequate for deployed SCADA installations. The correct solution for cabinet installations is a bulkhead-mount MIMO antenna: an antenna with an SMA or N-type connector, mounted through the cabinet lid or side panel, with the antenna element on the outside. This alone can be the difference between a router that struggles to hold a 4G connection and one that maintains full signal continuously.
For SCADA sites in areas with poor coverage – remote pipeline stations, wind turbine bases, flood monitoring stations – a higher-gain directional antenna pointed at the nearest cell tower provides additional margin. Yagi antennas offering 10-15 dBi gain are used in extreme cases, though they require accurate pointing and are more sensitive to tower changes by the MNO.
The key specifications for a SCADA site antenna are: frequency band coverage (for UK 4G, this means Band 20 at 800 MHz for rural coverage and Band 3 at 1800 MHz for urban areas at minimum, with bands 1, 7, and 28 desirable for broader compatibility), MIMO support (2×2 is the standard for 4G LTE SCADA applications), and IP rating (IP67 minimum for outdoor-mounted antennas).
For antenna selection guidance, product listings, and installation advice for SCADA and industrial IoT applications, see IoTAntenna.co.uk. The IoTPortal antenna directory also lists tested antennas suitable for SCADA cabinet installations.
Security architecture for remote SCADA access
Remote SCADA access security is not a product decision – it is an architecture decision. The Purdue model (ISA-95) provides the most widely used reference architecture: Level 0 is the physical process, Level 1 is the PLCs and RTUs, Level 2 is the local HMI and control network, Level 3 is the site operations network, and the industrial DMZ separates OT from IT and from external access. Remote access should land in the DMZ or at Level 3, never directly at Level 1 or 2.
The practical implementation for cellular-connected SCADA sites involves:
- VPN termination at the router: all traffic from the field site exits through an encrypted tunnel. The router does not forward unencrypted SCADA protocol traffic onto the public internet under any circumstances.
- Firewall rules: the router’s firewall blocks all inbound connections that are not part of the VPN tunnel or an explicitly permitted management channel. Default-deny inbound is the correct posture.
- Multi-factor authentication: any human access to the SCADA platform over the internet requires MFA. This is a requirement under NIS Regulations for operators of essential services.
- Separation of SCADA and management traffic: the cellular link carrying SCADA data should be logically or physically separate from the management channel used to update the router firmware or change configuration. Many industrial routers support VLANs for this purpose; Milesight DeviceHub communicates over a separate management channel.
- Audit logging: all remote access sessions should be logged, with timestamps, user identity, and actions taken. This is both a security requirement and a regulatory obligation for critical national infrastructure.
Future connectivity technologies for SCADA
The current UK SCADA connectivity landscape is 4G LTE dominant, with 5G appearing at new-build sites where latency or throughput requirements justify it. Several emerging technologies will change this picture over the next five to ten years.
5G RedCap
RedCap (Reduced Capability) is the 5G variant designed for industrial IoT – it offers lower cost and power than full 5G while delivering 100 Mbps+ throughput and sub-10ms latency. EE and Vodafone are commercially live with RedCap on their 5G SA networks in 2026. The first generation of RedCap SCADA routers is beginning to appear. For new-build SCADA installations from 2027 onwards, RedCap is the likely default choice. See 5gRedCap.co.uk for technical coverage.
eRedCap
Enhanced RedCap (eRedCap) is the Release 18 evolution of the standard, introducing further power and cost reductions alongside support for URLLC (ultra-reliable low-latency communications) profiles relevant to real-time SCADA control applications. eRedCap is the standard most relevant to safety-critical SCADA applications where deterministic latency matters – protection relay coordination, for example. Standardised 2024-2025, commercial deployments expected 2028-2030. See eRedCap.com for the specification detail.
Ultra-RedCap
The Release 19 evolution beyond eRedCap – pushing further on energy efficiency and introducing new device categories suited to low-cost industrial sensors at scale. Ultra-RedCap is the emerging term for this generation. Still in standardisation; commercial relevance is likely 2030+. Background on the technology direction at UltraRedCap.com.
LTE-450
Several European countries (Germany, Finland, Denmark) are deploying dedicated LTE networks in the 450 MHz band specifically for critical infrastructure SCADA. The physics of 450 MHz – far superior range and building penetration compared to 800 MHz – makes it ideal for rural and underground SCADA installations. UK interest is growing, particularly for water sector applications. No commercial UK deployment yet, but the regulatory and business case is under active consideration. Coverage at LTE450.co.uk.
NTN / Satellite
3GPP Release 17 standardised NTN (non-terrestrial networks) – direct-to-satellite cellular connectivity using standard cellular chipsets. Starlink, OneWeb, and emerging LEO constellations provide an alternative connectivity path for SCADA sites where terrestrial 4G coverage is absent or unreliable. Current limitations for SCADA include latency (20-40ms for LEO, which is acceptable for most SCADA polling), cost, and terminal size. The convergence of 5G NTN with cellular IoT modules is the medium-term direction.
iSIM / eUICC
SGP.32 – the GSMA specification for IoT remote SIM provisioning – enables a SCADA router’s SIM to be remotely provisioned to a different MNO over the air. For a fleet of 500 remote SCADA sites, this means the SIM can be switched from one operator to another without a site visit. This matters when coverage patterns change, or when a better commercial deal is available. eUICC / iSIM technology for IoT is covered in depth at eUICC.co.uk.
Further reading on IoTPortal
The SCADA Over Cellular guide on IoTPortal covers the protocol layer in detail – Modbus, DNP3, OPC UA, IEC 61850, and how each maps to cellular backhaul requirements. For the router classification framework that applies to SCADA hardware selection, see the cellular router classifications guide. The IoT connectivity reference library covers the broader cellular IoT architecture context.



