Network & Perimeter

Industrial (OT) Security OT/ICS

A security layer that passively discovers devices on production line, PLC, SCADA and building automation networks, detects abnormal commands and traffic, and separates the IT and OT networks.

When you need it

  • You have a production line, SCADA or PLCs
  • There is no separation, or an unclear one, between the OT network and the office network
  • Machine vendors connect to your network for remote maintenance
  • You are in a critical infrastructure sector such as energy, water, pharma or food

When you do not need it

  • Not needed if you have no industrial control systems.
  • At a small facility, the first step is not a product but network separation: isolate the OT network with a firewall and log remote maintenance access.

Passive monitoring on the OT network via switch mirroring (SPAN); a firewall and DMZ between IT and OT (Purdue model). Remote maintenance access goes through PAM/ZTNA.