- Home
- Support
- Product Security
- General Security Guidance
This guidance provides supplemental instructions for protecting your SCIEX acquisition and processing computers. This guidance is intended to supplement rather than replace your current IT policies, requirements, and practices. We suggest that you consult with your IT department before implementing any of the recommended changes.
Although SCIEX computers are released with a general use operating system, we recommend that you treat the computer as a specialized system that is an extension of the instrument itself. To safeguard the computer, use the computer only to perform the steps required for your workflows, not for additional purposes. We recommend that you follow the security best practices outlined in this document for both acquisition and processing computers.
Obsolete operating systems have vulnerabilities and security gaps that can be exploited by attackers. To protect the computer, make sure that it is running a supported version of Windows 10 LTSC or Windows 11. These operating systems have enhanced security features.
USB devices can be programmed to spread viruses to any computer they touch. They can infect computers at the boot stage, before antivirus tools can intervene. To protect the computer, disable the USB ports on the front panel of the computer. Make sure that the USB ports on the back panel remain enabled for SCIEX Service Support use.
Browsing the Internet from your computer greatly increases the risk of a malware infection. Certain malware can automatically infect your computer by visiting a compromised website without any operator intervention. Downloading and installing applications from the Internet greatly increases the surface area of attack and is strongly discouraged.
Email is the number one vector of attack for delivering malware. Most malware is delivered via email attachments or malicious links within emails. Using email on the computer greatly increases the risk of a potential malware infection. We strongly recommend that no email activity be performed on the computer.
Installing additional software on your computer increases the attack surface for potential infections. Malware authors often exploit vulnerabilities in third-party applications (like Adobe Flash) to exploit the underlying operating system. We recommend that, whenever possible, you do not perform additional work on the acquisition computer. Instead, use a computer that is intended and protected for such use. If third-party applications must be installed, then we recommend that they be kept up-to-date with the latest security patches.
Some customers choose to connect their SCIEX environment to external third-party software or services - including, without limitation, third-party artificial intelligence platforms, large language model APIs, and other cloud-based tools (collectively, "External Software"). SCIEX does not provide, operate, endorse, or control any External Software.
Where a customer chooses to establish such a connection, the customer is solely and exclusively responsible for:
SCIEX expressly disclaims all liability for any loss, damage, regulatory fine, or other consequence arising from a customer's use of or connection to any External Software, including any failure, error, or security incident attributable to that External Software or to data processed through it.
We strongly recommend that customers consult with their IT, legal, and data protection teams before connecting any External Software to their SCIEX environment.
Make sure that your password is at least 14 characters long and a mixture of uppercase, lowercase, alphanumeric, and special characters. Enable a screen saver password and inactivity timeout. We recommend that the timeout be 10 minutes. Lock the computer when stepping away from it. Do not share your password with others.
Making sure that critical security patches are installed is essential to maintaining the security of the computer. Our recommended setting is to notify you about the availability of updates and to allow you to select which patches to install and when. This option provides the flexibility to ensure that the installation does not negatively affect acquisition from the instrument. Organizations must balance their security needs and risk tolerance with their need to apply usability patches immediately on release. However, we also recommend that you do not run any Windows updates during SCIEX software acquisition and data processing.
While it is a widely acknowledged good practice to employ antivirus and backup software, these applications can interfere with the real-time nature of the SCIEX acquisition software. Some antivirus and backup applications are configured by default to automatically scan and archive a file immediately after creation. Because SCIEX acquisition software can perform multiple writes to a single data file during an acquisition sequence, these real-time features must be disabled to prevent the antivirus or backup software from locking the data file while it is still needed by the SCIEX software application. Many widely-used applications can be configured to either disable real-time protection or ignore certain file-types and paths. Failure to do so might result in either failed acquisitions or acquisitions that take longer to complete than expected.
Follow these guidelines when configuring antivirus software on the acquisition computer:
Note: The default installation location for the Analyst Data folders is D:\. These folders might be installed on a different drive.
For users running IDA and Scheduled MRM workflow on TripleTOF, QTRAP, and X500 QTOF systems, antivirus software might interfere with data acquisition and cause delays with acquisition of data points. We recommend that either you disable real-time antivirus protection, antivirus scheduled scans, and other data-intensive background tasks for these acquisition scenarios or perform validation for your specific antivirus and use case scenarios. After acquisition is complete, re-enable the real-time antivirus.
For instructions on how best to configure your particular antivirus or backup software, contact your antivirus or backup software provider.
As an additional layer of security, we recommend that the Windows Firewall remain enabled. The Windows Firewall has been turned on by default and is set to allow only a minimal number of necessary Windows services.
The SCIEX computer comes with Adobe Reader to allow operators to view our guides and documentation. We recommend that updates be installed as required, to reduce possible attack vectors. We recommend that the user guides and documentation be viewed on a computer other than the acquisition computer.
Network discovery allows the computer to discover other computers on the network, but it also allows other computers to discover the computer. If the computer is discoverable, then it can be scanned for vulnerabilities. Keeping this setting disabled has little impact on your ability to access any resources.
Malware can take advantage of the AutoPlay (auto run) functionality as a mechanism to infect a computer. Because of the large-scale global outbreak of the Conflicker virus in 2008, Microsoft changed the behavior of AutoPlay for removable devices only. We recommend disabling AutoPlay for all media types, including removable and CD/DVD devices.
Cloud services provided by SCIEX that are customer-managed are configured to disable public access by default. Access is restricted to source IP addresses originating from the customer's intranet, ensuring that only authorized internal traffic can reach these services.
As a general rule, when deploying applications on public cloud platforms or internet-accessible servers, it is essential to implement firewall protections and IP address restrictions to safeguard against unauthorized access.
Customer responsibility for data. The customer is solely responsible for the protection, backup, and recovery of all data generated, stored, or processed on their SCIEX computer or within their SCIEX environment. SCIEX does not back up customer data and accepts no responsibility or liability for any loss, corruption, or unavailability of customer data, howsoever caused, including as a result of hardware failure, software failure, malicious attack, accidental deletion, or any other cause.
Backup frequency. The frequency of backup should be commensurate with the customer's organizational requirements and the criticality of the data generated. Ensuring that backups are functional and recoverable is a vital component of overall data management. Customers should test their backups regularly to verify that data can be successfully restored.
Backup configuration during acquisition. Do not back up the computer during data acquisition, or ensure that the acquisition file types listed in the antivirus section above are excluded from real-time backup activity. Backup software that scans or archives files immediately upon creation can interfere with ongoing acquisitions and result in failed or incomplete data captures.
Pre-update backups. We strongly recommend that a full backup of the computer be taken prior to the installation of any security updates. This will facilitate a rollback in the rare case that a security patch or service pack, including re-imaging, affects application functionality.
No SCIEX liability for data loss. To the fullest extent permitted by applicable law, SCIEX shall not be liable to the customer or any third party for any loss or corruption of data arising from the customer's failure to maintain adequate backups, or from any other cause related to data management on the customer's systems.
While we strongly recommend that Internet browsing not be conducted on the computer, if you choose to do so then you should enable security settings that will help to protect your computer. These include:
Security event log auditing is a powerful tool that logs and tracks system activity. The logs can be used to make sure that regulatory compliance requirements are met, to monitor critical user activity, to detect anomalous behavior, and more. Because auditing plays a key role in providing evidence for regulatory compliance, consult with the appropriate personnel prior to making any of the recommended changes. To provide a secure baseline, we recommend the following customized auditing settings:
Audit Policy Setting | Log on Success | Log on Failure |
Audit Credential Validation | Yes | Yes |
Audit Computer Account Management | Yes | No |
Audit Other Account Management Events | Yes | No |
Audit Security Group Management | Yes | No |
Audit Process Creation | Yes | No |
Audit Logoff | Yes | No |
Audit Logon | Yes | No |
Audit Policy Change | Yes | Yes |
Audit Security State Change | Yes | Yes |
Audit Security System Extension | Yes | Yes |
If you have any questions regarding the security of your system, please contact SCIEX Support at https://sciex.com/support
If you would like to arrange for SCIEX Service to perform on-site securing of your system, please email professionalservices@sciex.com