I agree with your points. However, the challenge of incorporating the corporate networking security protocols is daunting. The Facilities fiefdom disallows anyone but Facilities touching, well, facilities. The service contracts do not allow for anyone but the service personnel to touch the control systems, in most instances. I like the idea of a front end, but unless the service personnel can reach their systems from their 50 year old control systems, they will void the contracts. And as soon as you mention VPNs or encryption or air gapping - you risk losing all support for the critical systems (I'm speaking mostly from experience in supporting production pipelines in labs). What is needed is a full rethink of ownership of these systems, and buy-in and new contracts. And, lotsa new people.

I've rarely seen a classic "control system" (HVAC, security, wet and dry lab systems, anything with modems and 9600kbps transmission, ANSI screens, etc) be configured in anything BUT 1980's architecture. These industrial control systems are so old and embedded no one has the money or incentive to remove them and install modern tech. And most of them are archaic, and so incredibly vulnerable it can make a person lose sleep. Think yet another "tip of the iceberg"moment. Think water control, sewage control, electrical control, alarms control, traffic light control. NOT ALL, but the majority are hopelessly insecure and controlled by people who use FAX machines. Anything installed before 2000 or so (the majority) are childlike in design and harbor absolutely no notion of security.

