Get a Quote
Home Resources SCADA Private APN vs VPN for Industrial SCADA Security

Private APN vs VPN for Industrial SCADA Security

07 May 2026 — 3 min read — By Peter Green

Connecting SCADA systems over cellular WAN raises a straightforward question: how do you secure the connection? Two approaches dominate industrial deployments in the UK – private APN and VPN tunnels. Understanding the difference matters more than it might seem, because the right choice depends on your specific threat model, your network architecture, and the practical constraints of each site.

Network security architecture

What a Standard Cellular Connection Looks Like

Without any security measures, a SIM in a router connects through the mobile network to the public internet. The router gets a dynamic IP address from the operator. Any device on the public internet can potentially attempt connections to it. For most industrial applications, this is not acceptable.

How a Private APN Works

A private APN (Access Point Name) is a dedicated network gateway provided by the mobile operator that bypasses the public internet entirely. SIM traffic is routed directly from the mobile network to your private IP network via a dedicated connection – typically an MPLS circuit or a VPN maintained by the operator between your site and the mobile network core. The SIM traffic never touches the public internet. Devices on the private APN can only communicate with other devices on the same APN or with systems reachable via the private connection to your network.

How VPN Tunnels Work

A VPN (Virtual Private Network) creates an encrypted tunnel between the router at the remote site and a VPN concentrator at the control centre. Traffic traverses the public internet (or the mobile network) but is encrypted end-to-end. An attacker intercepting the traffic cannot read or modify it without the encryption keys. The Milesight UR75 supports OpenVPN, IPsec, L2TP and WireGuard, which covers the requirements of most industrial deployments.

Private APN vs VPN – The Key Differences

Private APN provides network isolation – the traffic is on a separate network segment and never exposed to the public internet. VPN provides encryption – the traffic is encrypted but may traverse shared infrastructure. For the highest security requirements (critical national infrastructure, IEC 62443 compliance), a combination of both is the standard approach: private APN plus VPN tunnel provides both isolation and encryption. For most utility and industrial monitoring applications, a well-configured VPN over a standard APN with fixed IP SIM provides adequate security at lower cost.

Practical Recommendation

For most UK remote monitoring deployments: use a fixed IP SIM with a VPN tunnel to your control centre. For critical infrastructure, utilities operating under Ofwat/Ofgem regulations, or organisations with specific IEC 62443 requirements: combine a private APN with VPN encryption. The Milesight UR75 supports all common VPN protocols and can be configured for either approach.

TALK TO SOMEONE WHO KNOWS THE KIT.

No ticket system. No offshore support. A direct conversation about your application.