Secure Deployment Guidance

Security starts with the deployment

Predator Software products are commonly deployed within operational technology and shop-floor environments where Windows servers, databases, CNC controls and industrial networks meet. Secure deployment helps reduce unnecessary exposure while preserving the connectivity manufacturers need for production.

This guidance provides a practical baseline for deploying Predator Software. It should be applied alongside your organisation's own cybersecurity policies, machine-builder instructions and site-specific risk assessment.

Cybersecurity knowledge behind the guidance

Our secure deployment guidance combines practical manufacturing and CNC deployment experience with knowledge held by an ISC2 Certified in Cybersecurity (CC) professional within Predator Software. This includes security principles, access controls, network security, security operations, business continuity, disaster recovery and incident response.

That cybersecurity knowledge is applied in a manufacturing context: protecting CNC programs, reducing unnecessary network exposure, controlling privileges, isolating legacy equipment and improving the resilience of connected shop-floor systems.

ISC2 Certified in Cybersecurity CC

ISC2 Certified in Cybersecurity (CC) is an individual professional certification and does not certify Predator Software products or deployments.

Recommended Network Architecture

  • Segment manufacturing equipment. Place CNC machines and other shop-floor devices on dedicated manufacturing or OT VLANs rather than the general corporate network.
  • Control traffic between networks. Use firewall rules to permit only the systems, ports and protocols required for the Predator application and connected equipment.
  • Restrict internet access. CNC controls and legacy machine devices should not have unrestricted direct internet access.
  • Avoid direct inbound exposure. Do not expose Predator services, Windows shares, SQL Server, RDP or CNC communication ports directly to the public internet.
  • Use secure remote access. Remote administration and support should use a controlled VPN or equivalent secure access method with strong authentication.
  • Document permitted connections. Maintain an inventory of machines, IP addresses, required protocols and firewall rules.

Legacy CNC protocols

Many CNC controls use legacy serial, FTP, file-share or proprietary communications that were designed before modern authentication and encryption became standard. Where the machine itself cannot support stronger security, compensate with network segmentation, firewall allowlisting, restricted routing and tightly controlled access to the Predator server.

Windows-based CNC controls: where supported, use Predator Secure DNC instead of FTP or Windows/SMB file shares. This removes the need to enable SMB simply to transfer CNC programs and avoids having to place an older or unsupported Windows-based machine control on the corporate domain just to access a shared folder.

Windows Server & Workstation Security

  • Use a currently supported Windows edition appropriate to the installed Predator version.
  • Apply operating-system security updates through a controlled patching process.
  • Use dedicated service accounts with only the permissions required for their function.
  • Avoid routine use of Domain Administrator or other highly privileged accounts for Predator services.
  • Enable Windows Firewall and restrict inbound connections to required hosts and services.
  • Use endpoint protection appropriate to the manufacturing environment and test exclusions rather than disabling protection broadly.
  • Restrict interactive logon to administrators and authorised support personnel.
  • Synchronise system time from a trusted source so audit records across servers and machines can be correlated.

SQL Server & Database Security

  • Use a dedicated database account for Predator services rather than sharing administrative credentials.
  • Do not use the SQL Server sa account for routine application operation.
  • Restrict database network access to authorised application servers and administrative systems.
  • Protect stored database credentials and limit access to Predator configuration files.
  • Use encrypted SQL connections where supported by the deployed environment.
  • Back up the database regularly and test restoration rather than relying solely on successful backup jobs.

Product-Specific Guidance

Predator DNC Predator DNC

  • Restrict CNC program folders to authorised users and services.
  • Use controlled program sources rather than unmanaged copies across workstations and shares.
  • Use Predator Secure DNC for Windows-based CNC controls where supported. Prefer it to FTP or Windows/SMB file shares for CNC program transfer.
  • Avoid joining an older or unsupported Windows-based CNC control to the corporate domain simply to access a file share; Predator Secure DNC can remove that dependency on SMB.
  • Allow only required server-to-machine communication through the manufacturing firewall.
  • Disable unused machine protocols, listeners and interfaces where practical.
  • Protect DNC configuration and stored credentials from unauthorised modification.
  • Retain relevant transfer and configuration logs to support traceability and investigation.

Learn more about Predator DNC

Predator MDC Predator MDC

  • Permit collection only from known, authorised machine addresses.
  • Keep monitoring interfaces read-only wherever the machine protocol and required function allow.
  • Restrict collectors and services to the minimum Windows and database permissions required.
  • Control inbound listeners and machine-data ports through host and network firewalls.
  • Monitor disk, database and service availability so collection faults do not go unnoticed.
  • Synchronise time across MDC servers and production equipment where practical.

Learn more about Predator MDC

Remote Access & Support

  • Use VPN or another authenticated secure-access platform rather than direct port forwarding.
  • Use multi-factor authentication where the remote-access platform supports it.
  • Grant access only to named authorised personnel and remove access when no longer required.
  • Limit remote sessions to the systems and networks required for the support activity.
  • Record and review remote-access activity in accordance with your organisation's security policy.

Backup, Recovery & Change Control

  • Back up Predator databases, configuration and other business-critical application data.
  • Keep at least one protected backup copy that is not continuously writable from the production server.
  • Test restoration procedures periodically.
  • Document significant configuration changes and retain appropriate release or change records.
  • Apply Predator security updates and relevant supported-platform updates through a controlled maintenance process.

Secure Deployment Checklist

AreaRecommended Baseline
NetworkManufacturing VLAN / OT segment with controlled routing
FirewallOnly required Predator, SQL and machine communication paths allowed
Internet ExposureNo direct exposure of CNC controls, Predator services, SQL or RDP
AccountsNamed administrator accounts and least-privilege service accounts
DatabaseDedicated application credentials, restricted network access and tested backups
Remote AccessSecure VPN or equivalent controlled access with MFA where available
Legacy CNCsCompensating controls through segmentation, allowlisting and restricted routing
UpdatesSupported Predator version and controlled security-patching process
LoggingRetain relevant application, transfer, system and remote-access logs

Need help with a secure Predator deployment?

Predator Software can help customers review the application, server, database and CNC connectivity requirements for their environment.

security@predator-software.eu