Services

SCADA & DCS Integration (ICSS)

Integrated Control and Safety System architecture: one operator interface across fire and gas, ESD and process control, with the safety layer independent underneath.

An operator facing an incident should not have to correlate three screens to understand what is happening. Fire and gas on one system, emergency shutdown on another, process control on a third — each with different graphics conventions, alarm philosophies and navigation — is an architecture that adds cognitive load at precisely the moment it can least be afforded.

An Integrated Control and Safety System resolves this: one coherent operator interface across control and safety, with the safety layers remaining functionally independent underneath. That last clause is the whole engineering problem. Integration must not become interconnection.

Independence and integration

IEC 61511 requires the safety instrumented system to be independent of the basic process control system, so a control system failure cannot defeat the protective layer. Integration must therefore be at the presentation layer, not the execution layer. In practice:

  • Safety logic executes on certified safety controllers, physically and logically separate from process control logic
  • Data flows from the safety layer to the control layer for display; commands do not flow the other way
  • Where any write access exists it is strictly limited, explicitly justified, access-controlled and logged
  • Communication faults degrade the display, never the protective function
  • The independence boundary is documented and demonstrable to an auditor

Scope

Architecture design — topology, network segmentation, controller allocation, redundancy strategy, explicit definition of the safety/control boundary.

Communication integration — Modbus TCP/RTU, Profibus, PROFINET, HART, Foundation Fieldbus, OPC UA and proprietary manufacturer protocols. Mapping, addressing, scaling and exception handling defined and tested.

Cause-and-effect configuration — the approved matrix implemented in safety controller logic, with voting, delays, inhibits and degraded-mode behaviour configured exactly as specified and verified line by line.

HMI and graphics — operator displays following a consistent hierarchy from plant overview through area to device detail, with fire and gas status readable at a glance and rapid navigation from an alarm to the affected device and its consequences.

Alarm management — rationalisation per EEMUA 191 and IEC 62682 principles. Prioritisation reflecting genuine consequence severity, suppression of known-consequential alarms, shelving with controls. An operator receiving hundreds of alarms during an upset is an operator receiving none.

Historian and reporting — trending, event logging, sequence-of-events recording with time synchronisation accurate enough for post-incident reconstruction.

Cybersecurity

Connecting a safety system to a network extends its attack surface. We design to IEC 62443 principles: zone and conduit segmentation, enforced trust boundaries, unidirectional data flow where achievable, hardened controller and workstation configuration, controlled and logged access, and a patch management approach that does not compromise platform safety certification.

Brownfield integration

Most integration work involves connecting new safety equipment to a legacy DCS, or bringing standalone fire and gas panels into a modern control room. Common constraints: obsolete protocols with no modern equivalent, controllers at their I/O or memory limit, undocumented existing configuration, and no available shutdown window. We survey the existing system before committing to an approach, and where necessary use protocol gateways to bridge generations without replacing what still works.

Frequently asked questions

Can fire and gas share a controller with process control?
Technically possible on some platforms, but it materially complicates the independence demonstration required by IEC 61511, and we would advise against it in most cases. Where a client requires it, the justification and compensating measures must be documented explicitly.

Can you integrate systems you did not supply?
Yes. Integration of third-party equipment is the majority of this work.