Earlier this year, a household name in IT networking launched a whole new product line purpose-built for the factory floor. Fanless. Rugged. Built for places where dust, vibration and heat are the norm, and expected to run 24/7 without a single reboot. The message was clear: industrial networking has officially gone mainstream.
The scenarios will look familiar if you've ever picked a router for a site: from a solar farm in the desert to a pumping station in the tropics. At every one of those sites, the same unassuming little box sits between the machines that make money and everyone who isn't supposed to reach them. In an OT network, the router — and especially theindustrial wireless router— is not just plumbing. It's the security boundary. Choose and configure it right, and your PLCs, SCADA systems, CCTV cameras and HMIs sit behind a wall you actually control. Get it wrong, and that same box quietly opens your production line to anyone scanning the internet.
Here's what that means in practice — and what to check before you buy.
Picture a real site. A few PLCs control the machines. A SCADA server collects the data. Operators watch HMI panels. A couple of cameras watch the floor. Everything plugs into a switch, which plugs into a router — and that router is the only door between your control equipment and the rest of the world: the internet, your head office, your remote engineers dialing in.
On the IT side, the network is defended by layers: firewalls, proxies, endpoint agents. On the OT side, most plants have none of that. The router oftenisthe firewall, the VPN gateway and the access controller, all in one metal box bolted to a DIN rail. Treat it like a security appliance, not a gadget — because that's what it is.
Two forces are making this conversation unavoidable. In North America, regulators and insurers are pushing OT owners toward recognized security frameworks — IEC 62443, NIST guidance, NERC CIP for the power sector — and auditors now ask where the network boundary sits. In Southeast Asia, the pressure is different but just as real: plants run in heat, humidity and rainy-season storms, on power that isn't always stable, at sites where an IT engineer is a two-hour drive away. Different reasons, same conclusion: the edge device you install has to be both a security gate and something you can trust to keep running.
The most common mistake I see: someone needs remote access to a machine, so they open a port on the router and forward it straight to the PLC or HMI. Now that device is exposed to the whole internet — and industrial protocols were never designed to face attackers.
The fix is a VPN, and this is where an industrial wireless router earns its keep. The USR-G806w 4G cellular router and the USR-G816 5G cellular router both support IPSec, OpenVPN, L2TP, PPTP and GRE. The enhanced OpenVPN implementation lets the router join three different OpenVPN servers as a client, or act as a server itself, and you can import a config file with one click — no certificate gymnastics. Your remote engineer opens an encrypted tunnel to the plant network; the PLC never sees a public port. No port forwarding, no exposed HMI, no "we'll just open it for the weekend" conversations.
A VPN gets you into the network. ACL rules decide what you can touch once you're in. Industrial routers with firewall ACL let you restrict by source IP, destination IP, port and protocol. Your PLC needs to talk to exactly one SCADA server on exactly one port. It does not need to chat with the office Wi-Fi, the camera recorder, or anything else. Write that rule, apply it, and the blast radius of any compromise shrinks to almost nothing.
This is also the fastest way to look good in an audit. "This device can only be reached by the SCADA server, on one port, over VPN" is a sentence that satisfies most assessors. One rule — and it does more for your security posture than a year of firewall review meetings.
Production, office and surveillance have different trust levels. Put them in separate subnets or VLANs so a problem on one side doesn't wash over the others. The USR-G809s gigabit edge router — 10 ports including two SFP fiber and eight Gigabit — is a natural place to draw those lines at a site. Pair the separation with QoS: give PLC control commands priority and let video traffic queue behind them. Machines keep their timing; cameras still record.
An OT router that's easy to manage remotely is a blessing, especially when the site is far away. One that exposes its web login to the internet is an incident waiting to happen. Keep the management plane off the public internet. Use a vendor cloud platform instead: with USR's remote management platform you can reconfigure, reboot and upgrade firmware over an encrypted channel, and set alarms for device offline, weak signal or traffic overrun — pushed by SMS or email. If a site drops, you know in minutes, not on the next maintenance visit. For a plant in the tropics, that can mean the difference between one trip out and five.
This one gets overlooked, and it's the one that bites people in hot climates. A router that dies at 45°C inside a sealed cabinet leaves your site unmonitored and unmanaged — that's an OT security event in itself. Real industrial routers are built for the floor: the USR-G816 runs from -35°C to 75°C; the USR-G806w from -20°C to 70°C, with surge, EFT and ESD protection, plus a hardware-and-software watchdog that restarts the device if a process hangs. Dual SIM slots mean if one carrier drops, the router switches to the backup and the site stays online. The G809s adds dual power inputs and 9–36V wide-voltage input for sites with unstable power — think monsoon-season voltage dips in Southeast Asia, or aging rural feeders in the Americas.
Standards matter too. If you ship to Europe, look for RED cybersecurity certification (EN 18031) — several PUSR devices already carry it. Depending on your market, also check alignment with IEC 62443 or NERC CIP. Ask the vendor, put it in writing, keep it in the file.
Take a typical remote site in a hot, humid climate: a water pumping station. In the cabinet: one PLC, one HMI, two cameras. On the DIN rail: a USR-G806w 4G industrial wireless router.
Now scale it up. A campus with a production line, an office building and a CCTV system. This is where the USR-G809s sits at the edge of the plant network, splitting traffic into production, office and surveillance subnets, enforcing ACLs between them, and running QoS so control traffic never waits behind a video stream. When the plant needs a cellular backup WAN — no fiber to the building, or a single fiber you don't trust — pair it with a 4G or 5G industrial wireless router, the G806w or the G816, for automatic failover.
Buy the router like the security device it is, not like a home gadget. For most manufacturers, the practical answer is: an industrial wireless router at each remote site as the encrypted, filtered, self-healing edge — and a gigabit edge router like the USR-G809s drawing the boundary where IT meets OT. Do that, and the PLCs, SCADA systems, cameras and HMIs behind it become a lot harder to reach — and a lot easier to defend. And when the auditor — or the weather — comes calling, you'll have an answer ready.