OT CYBERSECURITY · BLACKBEAR DATA DIODES

Let data leave the control network. Let nothing back in.

Every outbound link from a substation, water works or rail network is also a way in. A firewall can be misconfigured, bypassed or turned around. A hardware data diode cannot: one-way data flow enforced in physics, not policy, so telemetry reaches IT while attacks never reach OT.

Powered by BlackBear Cyber Security 30+ yrs on critical infrastructure
IEC 62443-4-1NERC-CIPNISTTAICSEAL-class
LIVE
DATA DIODE / UNIDIRECTIONAL GATEWAY
09:15:04
OUTBOUND FLOWS
1,284
ONE-WAY OT → HIST
INBOUND BLOCKED
100%
AT HARDWARE LAYER
DIODE THROUGHPUT
38.0Mb/s
BLOCKED COUNT
0
4 PROTECTED ZONES ••••
DIODE THROUGHPUT · 24H drag to scrub

The reason IT security does not fit

OT and IT defend opposite things.

Drop an IT firewall onto a control network and it fights the wrong battle. OT cannot tolerate downtime, runs decade-old protocols on devices that were never built to be patched, and treats availability as sacred. The boundary has to respect that.

Availability, keep it runningBusiness priorityConfidentiality of data
Cannot tolerate downtimeMajor focusData integrity
A few, specified, decades oldProtocolsHundreds, constantly changing
PLC, HMI, RTU, metersProtected assetsComputers, servers, data
Rarely, often impossiblePatch / AV installedYes, continuously

OT threat assessment

Why a closed network is no longer closed.

Industry 4.0 made remote access to OT inevitable, and the assets on the other side were never designed to survive it.

01

Exposed assets

Access to once-isolated assets is now inevitable: IIoT and remote monitoring opened the closed network.

02

Legacy devices

Outdated firmware with no secure software protection, running long past any patch.

03

Easily compromised

Legacy systems carry known, published vulnerabilities and a wide attack surface.

04

Vertical propagation

Hidden malicious code in OT devices reaches up and attacks the IT network.

05

Horizontal propagation

A single compromised host spreads sideways and can take down the production line.

06

24/7 attack window

Continuous operation means an endless, uninterrupted window for an attacker to work in.

The defensible boundary

A diode, not a policy you can get wrong.

A firewall is a rule set, and 99% of firewall breaches come down to a misconfiguration. A hardware data diode removes the rule set: data physically can only travel one way, OT to IT, enforced in the silicon. Telemetry, syslog, files and video flow out to your historian, SOC and cloud. Commands, malware and lateral movement have no path back.

  • One-way by physics. Virus and malware prevention by the law of physics, not a signature list.
  • Physical isolation. Network segmentation at the physical layer, with patented horizontal and vertical protection.
  • Seamless to OT. Plug-and-run after configuration. Zero changes to the existing OT environment, zero impact on install.
  • All-in-one. Built-in proxies for DNP3, IEC 61850, OPC-UA, MQTT, Modbus and ONVIF. No extra proxy server, licence or subscription.
98% of the 295 ICS incidents reported to ICS-CERT in FY2014-15 were preventable by application whitelisting. A data diode supports the CISA seven steps to defend industrial control systems.
OT to IT architecture: industrial network, DMZ with data diode and firewall, enterprise network with OT IDS and SOC monitoring, under IEC 62443 framework compliance
One-way flow from the industrial network, through a diode-guarded DMZ, to IT monitoring, aligned to IEC 62443.

The kit · BlackBear Intelligent Gateway

The BIG range, sized to the boundary.

One family of FPGA data diodes, from a DIN-rail gateway at a remote substation to a simple one-way fibre link. The BIG9000 gateway is an all-in-one: switch, proxies and diode in a single device.

BlackBear BIG9000I intelligent unidirectional gateway

BIG9000

DIN-rail data diode

The workhorse. 1Gbps line speed, up to 8 OT devices, FPGA diode, built-in proxies and ACL/port-isolation. Built for simpler topologies and fast install on a DIN rail.

  • 1Gbps line speed
  • 8 OT ports
  • FPGA diode
  • -40 to +70°C
BlackBear DD9000I data diode

DD9000I

Data diode

The diode on its own: FPGA one-way transfer with protocol proxies either side and one 1Gbps port each side, in a fanless DIN-rail housing.

  • 1Gbps line speed
  • 1 OT / 1 IT port
  • FPGA diode
  • -40 to +70°C
BlackBear UMC24

UMC24

Unidirectional media converter

A cost-effective one-way optical link. UDP over fibre up to 1Gbps and 10km, DIN-rail or wall mount, for nuclear, water, transport, enterprise and finance.

  • Fibre ≤10km
  • ≤1Gbps
  • SC/ST/LX
  • IP30 · DIN/wall

Where it runs

Proven across the Purdue model.

From field bus to business management, the diode sits on the boundary that matters, in production today across critical infrastructure.

Purdue-model network: field bus, supervision and monitoring, operations and business management, with BlackBear diodes placed at substation, chemical factory and surveillance boundaries
Substation

Secure network tapping: SCADA/HMI traffic mirrored to the SOC IDS, MACsec-protected, pure data diode.

Central bank

Secured syslog transmission, carried one way from the operational network to security monitoring.

Offshore mining

Secured Modbus and OPC-UA collection, with a reversed-diode channel for command transmission.

Solar farm

Floating solar field monitoring: OPC-UA data collection diode-forwarded to the cloud.

Certified and tested

Built to the standard, then attacked on purpose.

Manufactured to IEC 62443-4-1, designed by IEC 62443-certified consultants, and put through independent penetration testing in lab after lab, with no vulnerabilities left after revisit.

TaiwanThailandSingaporeJapanFrance
  • IEC 62443-4-1Secure product development lifecycle, certified
  • IEC 62443-4-2Component security, in assessment (France)
  • OWASP IoT Top 10Cleared, plus OWASP Top 10 and CWE/SANS
  • Achilles Lv2Industrial robustness pentest, Singapore
  • NERC-CIP · NISTFramework compliance for North American utilities

Put a diode on the boundary that matters.

Tell us the site, the protocols and what has to leave the control network. You get an architecture and a bill of materials, with a straight answer within one working day.

Talk to a security engineer The OT security solution