Industries · Operational technology

OT security that leaves the machines alone

OT security is how you protect the equipment that runs a plant, a port or a utility when most of it can’t be patched, can’t run security software and was built before anyone planned to connect it. The approach that works is to leave the machines as they are and control everything around them.

What changes on site
Added

A gateway at the edge of the plant network, and segments you draw in one console.

Left alone

The controllers, their firmware and the vendor’s support terms.

Let in

Named people on enrolled devices, through a post-quantum tunnel.

Why OT is its own problem

Built to run for twenty years, not to sit on a network

Service life

Most OT equipment was bought to do one job for a very long time. A controller installed when the site opened can still be running twenty years later, having outlived three IT strategies and a change of company logo. It was designed for a closed world, long before anyone expected it to share a network with email.

Vendor support

Patching it isn’t simple either. Many equipment vendors tie their support to a configuration they’ve tested, so an update they haven’t approved can cost you the support contract the site depends on. The machine stays exactly as it was delivered, because that’s the version the vendor will stand behind.

Uptime

And the person in charge of the site is judged on uptime. A security project that needs a line stopped, even for an afternoon, has to win an argument it usually loses.

That's why modernising first is usually the wrong first move. The better question is what sits between that equipment and everything else.

What usually gets tried

Three fixes that stall at the plant fence

The office wants data out of the plant, and vendors want a way in for maintenance. Each request is reasonable. Here’s how the usual answers hold up.

Replace the equipment

It’s the right long-term plan and the wrong first step. A working controller only gets swapped during a shutdown, with everything around it tested again, so the project waits for the next big overhaul.

Install security software on it

There’s often nowhere to install it, and where there is, the vendor may not support it. Protection that can’t live on the equipment has to live next to it.

One firewall between office and plant

A good start that wears down. Every vendor visit and every new report adds an exception. A few years later nobody can say which rules still matter, or who can reach what.

How QS-WAN fits

Put the security around the equipment, not on it

QS-WAN gives your organisation its own private network, run from one console. On an OT site, that means a gateway at the edge of the plant network, and rules you can read on a map instead of in a spreadsheet.

Vendor laptop enrolled, on a schedule Office network reports, planning post-quantum tunnel closed unless allowed Gateway rules and segments Plant network Controllers Safety systems Engineering nothing installed here Vendor laptop enrolled, on a schedule Office network reports, planning post-quantum tunnel closed unless allowed Gateway rules and segments Plant network Controllers Safety systems Engineering nothing installed here

Diagram: a vendor laptop, enrolled and on a schedule, reaches the gateway through a post-quantum tunnel. The link from the office network is closed unless allowed. The gateway connects one way to three segments of the plant network: controllers, safety systems and engineering. Nothing is installed on the plant equipment.

Illustrative layout, not a customer network.

Segments you can see

Keep controllers, safety systems and office machines in separate segments. Links from a VLAN into an existing LAN run one way by construction, and a zero trust VLAN refuses anything it wasn’t told to allow.

Vendor access with limits

A maintenance contractor gets a profile and an enrolled device. Firewall rules per user, country and IP lists, weekly schedules and multi-factor authentication decide what they reach. Revoke the device and that way in closes. More in secure remote access.

Nothing installed on the machines

QNova Client goes on the laptops and phones of the people who need access. The controllers keep their firmware, their configuration and their support contract.

Post-quantum on every connection

Every connection between a device, the gateway and the console is post-quantum, in line with FIPS 203, FIPS 204 and CNSA 2.0. It’s hybrid by design, so it’s never weaker than the classic encryption it sits beside.

Deployment

Inside your boundary, or delivered ready to plug in

OT sites usually pick one of two. There’s a third if neither fits.

Or we host the console, and you manage the whole network from a browser.

A console inside your own boundary

The control plane runs inside your boundary, so managing an isolated plant network doesn’t need a path to the internet. Licensing and updates with no internet connection follow their own procedure. Ask us for it rather than assuming.

A gateway that arrives configured

For a remote site without a server rack or anyone from IT on hand, we ship a hardware gateway already set up. Everything after that is managed from the console.

Straight answers

What we don't do on an OT site

We don't watch your plant

You’re buying software, not a monitoring service. The console shows segments, rules, devices and a risk score, and your engineers or your chosen provider decide what to do about them.

We don't touch the controllers

No agent, no firmware change and no configuration pushed to the equipment itself.

We don't make you compliant

If you work to IEC 62443 or fall under NIS2, clear segments and a map of who can reach each one help you answer the questions. The compliance work stays yours.

See it on a network shaped like yours

Tell us roughly how the site is laid out, and we’ll walk you through where a gateway would sit and what stays exactly as it is. The demo is free.

Related use cases

NEWSLETTER

Get weekly tips, product news and early access, straight to your inbox.

Scroll to Top