OT security that leaves the machines alone
OT security is how you protect the equipment that runs a plant, a port or a utility when most of it can’t be patched, can’t run security software and was built before anyone planned to connect it. The approach that works is to leave the machines as they are and control everything around them.
A gateway at the edge of the plant network, and segments you draw in one console.
The controllers, their firmware and the vendor’s support terms.
Named people on enrolled devices, through a post-quantum tunnel.
Built to run for twenty years, not to sit on a network
Service life
Most OT equipment was bought to do one job for a very long time. A controller installed when the site opened can still be running twenty years later, having outlived three IT strategies and a change of company logo. It was designed for a closed world, long before anyone expected it to share a network with email.
Vendor support
Patching it isn’t simple either. Many equipment vendors tie their support to a configuration they’ve tested, so an update they haven’t approved can cost you the support contract the site depends on. The machine stays exactly as it was delivered, because that’s the version the vendor will stand behind.
Uptime
And the person in charge of the site is judged on uptime. A security project that needs a line stopped, even for an afternoon, has to win an argument it usually loses.
That's why modernising first is usually the wrong first move. The better question is what sits between that equipment and everything else.
Three fixes that stall at the plant fence
The office wants data out of the plant, and vendors want a way in for maintenance. Each request is reasonable. Here’s how the usual answers hold up.
Replace the equipment
It’s the right long-term plan and the wrong first step. A working controller only gets swapped during a shutdown, with everything around it tested again, so the project waits for the next big overhaul.
Install security software on it
There’s often nowhere to install it, and where there is, the vendor may not support it. Protection that can’t live on the equipment has to live next to it.
One firewall between office and plant
A good start that wears down. Every vendor visit and every new report adds an exception. A few years later nobody can say which rules still matter, or who can reach what.
Put the security around the equipment, not on it
QS-WAN gives your organisation its own private network, run from one console. On an OT site, that means a gateway at the edge of the plant network, and rules you can read on a map instead of in a spreadsheet.
Diagram: a vendor laptop, enrolled and on a schedule, reaches the gateway through a post-quantum tunnel. The link from the office network is closed unless allowed. The gateway connects one way to three segments of the plant network: controllers, safety systems and engineering. Nothing is installed on the plant equipment.
Segments you can see
Keep controllers, safety systems and office machines in separate segments. Links from a VLAN into an existing LAN run one way by construction, and a zero trust VLAN refuses anything it wasn’t told to allow.
Vendor access with limits
A maintenance contractor gets a profile and an enrolled device. Firewall rules per user, country and IP lists, weekly schedules and multi-factor authentication decide what they reach. Revoke the device and that way in closes. More in secure remote access.
Nothing installed on the machines
QNova Client goes on the laptops and phones of the people who need access. The controllers keep their firmware, their configuration and their support contract.
Post-quantum on every connection
Every connection between a device, the gateway and the console is post-quantum, in line with FIPS 203, FIPS 204 and CNSA 2.0. It’s hybrid by design, so it’s never weaker than the classic encryption it sits beside.
Inside your boundary, or delivered ready to plug in
OT sites usually pick one of two. There’s a third if neither fits.
Or we host the console, and you manage the whole network from a browser.
A console inside your own boundary
The control plane runs inside your boundary, so managing an isolated plant network doesn’t need a path to the internet. Licensing and updates with no internet connection follow their own procedure. Ask us for it rather than assuming.
A gateway that arrives configured
For a remote site without a server rack or anyone from IT on hand, we ship a hardware gateway already set up. Everything after that is managed from the console.
What we don't do on an OT site
We don't watch your plant
You’re buying software, not a monitoring service. The console shows segments, rules, devices and a risk score, and your engineers or your chosen provider decide what to do about them.
We don't touch the controllers
No agent, no firmware change and no configuration pushed to the equipment itself.
We don't make you compliant
If you work to IEC 62443 or fall under NIS2, clear segments and a map of who can reach each one help you answer the questions. The compliance work stays yours.
See it on a network shaped like yours
Tell us roughly how the site is laid out, and we’ll walk you through where a gateway would sit and what stays exactly as it is. The demo is free.
NEWSLETTER
Get weekly tips, product news and early access, straight to your inbox.