ICS security: protection that lives in the network
A controller cannot run an agent, and the next chance to touch it may be a year away. So ICS security has to sit around the control system rather than inside it. QS-WAN puts each cell behind a gateway, draws every permitted path on one map, and gives each engineer one way in that can be revoked without visiting the plant.
Whatever answers those questions has to be the network it sits on.
The device cannot be the place you defend
An industrial control system is built to do one thing for twenty years without stopping. That is a virtue on the plant floor and a problem on the network. There is no room for an agent, often no user account worth the name, and no appetite for anything that adds a millisecond to a control loop.
The maintenance window that would let you change something comes once a year, sometimes less, and it is already full of mechanical work. Anything that needs a controller to be rebooted competes with production, and production wins.
So the honest question is not how to harden the controller. It is what you put around it, and how little that thing needs from the controller to work.
The protocols were built to trust
Fieldbus and supervisory protocols were designed for a closed cell where every device was friendly. They carry no identity worth checking, so the only place to decide who may speak to whom is the path between them.
Zones and conduits are the model
IEC 62443 describes a plant as zones with conduits between them, and asks you to say what may cross each conduit. That is a network drawing before it is a security control, which is why it drifts the moment somebody adds a temporary link.
The integrator needs a way in
The people who know the machine best do not work for you. Vendor engineers connect for commissioning and for the odd fault, usually in a hurry, and usually with whatever tool they brought.
A gateway at the edge of the cell, and nothing asked of the controller
QS-WAN runs a private network from one console, and QNova Client puts that network on the devices that can take it, which in a plant means laptops, engineering workstations and phones, not the controller. Three things do the work.
A gateway at the boundary
The cell sits behind its own gateway, a hardware box or software on a host you already run, with its own VLANs, address space and firewall rules. It goes in beside the switching you have, so the control network keeps its addresses and its behaviour.
Paths you can see and switch off
In the Network Map, a permitted path between two segments is an edge you turn on or off. A VLAN set to zero trust stays default deny whatever tunnel mode it uses, so a conduit that was opened for a commissioning job does not quietly stay open for years.
One way in per person, revocable from the console
An engineer, yours or a vendor’s, reaches the cell through a device that carries a certificate for that gateway and nothing else. Revoking it is one action in the console, not a visit to the plant and not a shared password that somebody has to remember to change.
Post-quantum by default
Everything between a device, a gateway and the control plane is post-quantum by default, aligned with FIPS 203, FIPS 204 and CNSA 2.0, and hybrid by design. Plant data has a long life, and so does anything captured today.
Runs where you decide
License QS-WAN onto your own infrastructure, take a gateway we ship configured, or let us host it. A plant that is not allowed to touch the public internet keeps the console inside the boundary too. More on running a network that never touches the internet.
The four questions an assessor asks about a cell
Whether the visitor is an IEC 62443 assessor, an insurer or your own auditor, the questions land in the same order, and the answers live in the console rather than in somebody’s memory.
What is inside this zone?
The gateway, its VLANs and LANs, and the address space reserved for the cell, drawn in the Network Map instead of described in a document.
What may cross the conduit?
The edges on that map, each one one way, two way, disabled or zero trust, plus the firewall rules set per gateway and per user.
Who reached it, and from what?
Each user profile, its devices, and one certificate per gateway membership, with a CSV export for the file.
Is it checked or only configured?
Automated assessments on each gateway return pass, fail, partially satisfied or not tested, next to a risk score built from 19 indicators.
One honest caveat. A green confirmation means the change was recorded. A gateway that was offline applies it when it reconnects, which in a plant can be the next shift, so check the gateways are online before calling the record current.
What this does not do in a plant
ICS security products often promise the whole plant. This one covers the network around the control system, and it is worth being plain about the edges.
The controller itself
Nothing is installed on a PLC, an RTU or an HMI appliance, so nothing here patches them, reads their firmware or watches their process values.
Process safety
Safety instrumented systems and the engineering behind them are a separate discipline with its own standards. This is network security, not functional safety.
Watching your plant
Nobody at QuantumNova sits in your control room. The platform produces the risk score and the evidence, and your people, or your integrator, read them.
Networks it does not run
A VLAN on a switch the platform does not manage is outside its view, so it cannot vouch for that separation.
Start with the cell that worries you most
Most plants have one area where the drawing and the reality parted company years ago. That is the useful place to begin, and a demonstration is free.
NEWSLETTER
Get weekly tips, product news and early access, straight to your inbox.