- Critical OT & Industry 4.0
- Aveva Pi
Case Study: Aveva Pi Historian OT to IT Convergence for Downstream Control
Leading Refining Company in the Middle-East (GCC)
Replicate up to 100,000 PI tags per second without performance degradation
Preserve PI archives and historical data integrity during replication
Maintain strict OT–IT isolation while enabling continuous historian synchronization
Ensure zero unplanned downtime and extremely low maintenance in critical downstream operations
Need / Problem / Context
Protecting oil refining operations while enabling Aveva PI data analytics
A leading refinery in the Middle East needed to expose operational data from multiple distributed OT PI Historian servers to a centralized IT data lake used for analytics, performance monitoring, and long-term operational optimization.
While the analytics platform required continuous access to large volumes of time-series data, the OT environment hosting the PI servers controlled critical downstream operations and had to remain strictly isolated from the corporate IT network. Any direct connectivity would have introduced unacceptable cyber risk and potential disruption worth hundreds of millions of dollars per day of downtime.
The challenge was therefore to replicate historian data from multiple OT Aveva PI servers to a central IT PI server at high throughput — up to 100,000 tags per second — while preserving the integrity of PI archives, maintaining uninterrupted refinery operations, and ensuring a strict one-way security boundary between OT and IT environments.
Solution Deployed
Cyberium deployed a resilient unidirectional gateway architecture to enable secure, high-throughput replication of historian data while preserving strict OT–IT separation. The solution ensures continuous synchronization from distributed OT PI servers to the centralized IT environment without introducing any inbound connectivity risk.
4x OWA 3U pack @ 1 Gbps
Four security gateways were deployed to sustain continuous high-volume historian replication while preserving strict separation between OT and IT environments.
Standard (SFTP/Syslog)
+ SMTP Connectors
Required files and operational messaging are exported through standard secure protocols, enabling reliable integration with enterprise monitoring and analytics platforms.
High-Availability℗ Setup
The architecture incorporates Cyberium patented High Availability mechanisms, ensuring uninterrupted data replication and eliminating any single point of failure for this critical operational data flow.
How It Works — Architecture Overview
Outcomes & benefits
The new architecture provides a stable and efficient historian replication environment, simplifying operations while significantly improving system reliability and reducing overall operational costs.
50% reduction in Aveva PI licensing cost
Replaced an unstable legacy system that required monthly reboots and caused frequent data loss
Running flawlessly since 2017 with zero maintenance issues
More use cases
- Critical OT & Industry 4.0
- OWA 2U/3U
- Custom SCADA, Siemens WinCC
- SQL Databases Agent
- Critical OT & Industry 4.0
- OWA 2U/3U
- Custom SCADA
- OPC UA Agent
- Critical OT & Industry 4.0
- OWA 2U/3U
- Cisco Splunk
- HTTP/S API, Syslog
- Critical OT & Industry 4.0
- OWA 2U/3U
- Custom SCADA
- SQL Databases Agent
- Critical OT & Industry 4.0
- OWA 2U/3U
- Hexagon PAS
- File Transfer Agent, SMTP
- Critical OT & Industry 4.0
- OWA 2U/3U
- GE OSM (On-Site Manager)
- File Transfer Agent, SFTP, FTP/S/ES
We secure the Critical
— connecting what should stay isolated.
Latest blog entries
- AI & Cybersecurity, Threat Landscape
Most cyberattacks on industrial infrastructure don’t start in the plant. They start in the office. A phishing email reaches an (…)
- AI & Cybersecurity, Threat Landscape
In 2025, the baseline assumption of industrial cybersecurity broke. For twenty years, defenders had one reliable edge over attackers: time. (…)
- OT Cybersecurity Best Practices, Threat Landscape
Every documented OT breach in the past five years started at the same place: an internet-facing asset that operators believed (…)
- OT Cybersecurity Best Practices, Regulations & Compliance, Threat Landscape
In every major OT cyberattack of the past decade, firewalls were present. In each case, they failed. Not because they (…)
- Architecture Design Patterns, Engineering Insights
Industrial cybersecurity starts with a simple reality: you cannot detect threats if you cannot see what happens inside your OT (…)