Solutions
Our solutionsTechnology we install to protect your control network.

We are vendor neutral and choose the technology that suits each plant. Four of the solutions below close a specific route into the control network. The fifth, network monitoring, detects activity on routes that have not yet been identified.

Solution 01
Zone Boundary ProtectionSecuring the link to the business network
View solution: Zone Boundary ProtectionMost plants are connected to the office network through a link that has not been reviewed in years. We install a boundary at that link that allows only the traffic the process needs. Where data should only flow out of the plant, we install a data diode, which has no physical return path.
- What we install
- Industrial firewalls, and hardware data diodes where traffic must only flow one way
- Where it sits
- The boundary between IT and OT, and the DMZ between them
- Recommended by
- IT and OT Network Architecture Design

Solution 02
Secure Remote AccessControlled access for vendors and remote engineers
View solution: Secure Remote AccessA shared, always-on VPN account gives every vendor the same permanent access to your plant, and there is no record of who used it. We replace it with individual sessions that are opened only for approved work and close automatically.
- What we install
- A brokered access path with named sessions, least privilege access and a record of each session
- Where it sits
- Between external networks and the DMZ, never directly into the process network
- Recommended by
- Gap Assessment

Solution 03
Removable Media SanitizationScanning USB drives before they enter the plant
View solution: Removable Media SanitizationUSB drives remain one of the most common ways malware reaches a control network, because they are carried in by people. A scanning station at each entrance checks every drive before it reaches plant equipment.
- What we install
- Scanning and decontamination stations that issue a clean transfer medium
- Where it sits
- Plant entrances, contractor gates and control room doors
- Recommended by
- SCADA and DCS Health Check

Solution 04
Endpoint SecurityProtection for HMIs, workstations and servers
View solution: Endpoint SecurityStandard office antivirus can disrupt an HMI and stop production. We install protection designed for control systems, and we confirm that it meets your control system vendor’s support requirements before installation.
- What we install
- Endpoint protection designed for OT, application allow listing and device control
- Where it sits
- HMIs, engineering workstations, historians and operator stations
- Recommended by
- SCADA and DCS Health Check

Solution 05 · monitoring
Network Visibility and MonitoringPassive monitoring of your control network
View solution: Network Visibility and MonitoringNo list of entry routes is ever complete, so continuous monitoring is needed. Passive monitoring builds an inventory of the devices on your network, learns its normal traffic and alerts you to changes. It reads a copy of the traffic and does not interfere with the process.
- What we install
- Passive OT monitoring, asset inventory and anomaly detection
- Where it sits
- A mirror port, outside the process path
- Recommended by
- Risk Assessment
Next step

