ATEON

OT and Critical Infrastructure Security

File, network and access security solutions for industrial and critical infrastructure environments.

OT and Critical Infrastructure Security
OT and Critical Infrastructure Security
OPSWAT

Opswat MetaDefender Kiosk

MetaDefender Kiosk is a dedicated hardware or software-based media security station used to scan and sanitize USB drives, external disks, SD cards and similar portable media before they enter secure zones.

MetaDefender Kiosk is a dedicated hardware or software-based media security station used to scan and sanitize portable media such as USB drives, external disks and SD cards before they enter secure zones. Using multiscanning, Deep CDR and file validation technologies, it inspects the content on the media and allows only approved files into the critical environment.

In air-gapped or high-security networks, portable media is often a necessary but risky way of moving data. Kiosk takes that process out of the user's hands and turns it into a standard, logged and auditable security control. It reduces the risk of malware being carried into manufacturing, defence or critical infrastructure systems over USB while maintaining the controlled data flow operations require.

OPSWAT

Opswat MetaDefender Drive

MetaDefender Drive is a portable security device that scans a computer's disk and memory for malicious software, either while the operating system is running or from a trusted boot environment.

MetaDefender Drive is a portable security device that plugs into a computer and scans the machine's disk and memory for malware, either while the operating system is running or from a trusted boot environment. It allows devices such as contractor laptops, maintenance systems and new workstations that connect temporarily to the network to be verified before they are admitted to the critical environment.

Being able to scan without installing a permanent agent on the target system makes it easier to check devices under different ownership or of operational sensitivity. In OT and air-gapped environments in particular, it detects threats that could be carried in through the supply chain before they reach the network. With the central reporting option, the scans carried out become demonstrable, maintenance processes are standardized, and the risk arising from untrusted temporary devices is reduced.

OPSWAT

Opswat MetaDefender NetWall

MetaDefender NetWall is a data diode and secure gateway product family that enables controlled data flow between IT and OT networks of differing trust levels.

MetaDefender NetWall is a family of data diode and secure gateway products that provides controlled data flow between IT and OT networks of differing trust levels. With hardware-based one-way communication, protocol brokering and secure file transfer options, it allows data out of the critical network while blocking the return path from the external network physically or architecturally.

One-way data flow helps eliminate the risk of a connection back into the critical network through firewall rule errors or compromised external systems. SOC logs, production data or replication traffic can be transferred securely to external systems while OT isolation is preserved. The organization meets its need for visibility and operations alongside a high security requirement, and strengthens its compliance with critical infrastructure regulations.

OPSWAT

Opswat MetaDefender OT Security

MetaDefender OT Security is an OT security platform that discovers PLCs, HMIs, engineering workstations and other OT assets on industrial networks through passive or safe methods, and monitors their communications and risks.

MetaDefender OT Security is an OT security platform that discovers PLCs, HMIs, engineering workstations and other OT assets on industrial networks using passive or safe methods, and monitors their communications and risks. It centrally provides asset inventory, network visibility, vulnerability and patch information, configuration change tracking, threat detection and compliance reporting.

Knowing which devices are on the production network and what normal communication between them looks like means unexpected connections or changes are noticed early. Security teams can prioritize risks without disrupting operations and make exposure from legacy systems and missing patches visible. Central inventory and reports support compliance with frameworks such as IEC 62443 while establishing a shared language of risk between OT and IT teams.

OPSWAT

Opswat MetaDefender Industrial Firewall

MetaDefender Industrial Firewall is a ruggedized OT firewall that understands industrial protocols in operational technology networks and provides segmentation, access control and intrusion prevention.

MetaDefender Industrial Firewall is a ruggedized OT firewall that provides segmentation, access control and intrusion prevention on operational technology networks by understanding industrial protocols. It can inspect commands in Modbus and similar control protocols, allowing only permitted devices, directions and operations through, and so protecting critical control systems from unauthorized or mistaken actions.

Protocol awareness means you can control which industrial command may be executed, going beyond classic IP and port rules. Separating critical PLCs and control devices into small security zones limits the spread of an incident along the production line. The organization adds compensating controls for legacy or unpatchable OT assets, reducing the risk of misconfiguration, unauthorized change and network-based attack while preserving operational continuity.

OPSWAT

Opswat MetaDefender OT Access

MetaDefender OT Access is a secure access solution that governs remote or local access to critical OT systems by employees and third-party maintenance teams through identity, device compliance and policy controls.

MetaDefender OT Access is a secure access solution that governs how employees and third-party maintenance teams reach critical OT systems, remotely or locally, through identity, device compliance and policy controls. Before a connection is made it assesses the device's security posture, limits access to the assets and time period required, and makes the activity carried out auditable.

Running third-party access through a controlled gateway, rather than granting it directly with VPNs and shared accounts, reduces the attack surface. Devices that are non-compliant or carry a malware risk can be blocked before they reach the critical network. Time-limited authorization, logging and central policy provide accountability without disrupting maintenance operations, and lower the security and compliance risks arising from supplier connections.