Case studies without auto template – Waterfall Security Solutions https://waterfall-security.com Unbreachable OT security, unlimited OT connectivity Tue, 09 Sep 2025 08:18:20 +0000 en-US hourly 1 https://wordpress.org/?v=6.8.2 https://waterfall-security.com/wp-content/uploads/2023/09/cropped-favicon2-2-32x32.png Case studies without auto template – Waterfall Security Solutions https://waterfall-security.com 32 32 Cybersecurity for Government Networks https://waterfall-security.com/ot-insights-center/government-and-defense/cybersecurity-for-government-networks/ Mon, 19 Feb 2024 12:40:46 +0000 https://waterfall-security.com/?p=19819 Securing a classified/high-security network with a Unidirectional Security Gateway, ensuring continuous and secure cross-domain data flow, while preventing sensitive data from leaking into or being exfiltrated from external, low-security/unclassified networks.

The post Cybersecurity for Government Networks appeared first on Waterfall Security Solutions.

]]>

Cybersecurity for Government Networks

Defending Critical Government Operations From Cyber Threats
Government Network Cybersecurity
Customer:

A Government Security Agency in Asia-Pacific

Customer Requirement:

Enable real-time transfer of arbitrary files into a secure network environment from open-source networks via file transfer, HTTP and email transports, while providing absolute protection from online data leakage and data exfiltration attacks from the secure network.

Waterfall’s Unidirectional Solution:

Secures the classified/high-security network with a Unidirectional Security Gateway, ensuring continuous and secure cross-domain data flow, while preventing sensitive data from leaking into or being exfiltrated from external, low-security/unclassified networks.

Preventing Data Exfiltration Attacks on High-Security Networks

Government security agencies, public utilities, financial institutions and other sensitive sites world-wide are vulnerable to online cyber attacks aiming to exfiltrate sensitive data. As all software can be hacked, protecting an organization’s most sensitive information with only software and firewalls is not sufficient from a national security standpoint. Software and firewalls can be exploited by malicious and sophisticated adversaries seeking to gain access to sensitive data stored in high-security networks.

The Challenge icon
The challenge

Seamlessly and efficiently transfer files from an open source network into a highly-sensitive secure network, while removing embedded malware from the files and preventing absolutely any data exfiltration back into the source network. Support file movement via HTTP, file transfer and emailed transports.

Waterfall solution - icon
Waterfall solution

A Waterfall Unidirectional Gateway was installed to transmit files from the low-security to the high-security network. Unidirectional Gateway software connectors gather files in real time from the low-security network and populate those files into file and email servers in the high security network. Government and law enforcement applications and personnel can interact normally and bi-directionally with the copies on the secure network, while the Unidirectional Gateway hardware physically prevents any data leakage back into the low-security network.

Results and benefits - icon
Results & benefits

Hardware-Enforced Security: The classified/high-sensitivity network is now physically protected from online data exfiltration attacks.

Seamless Integration: with a wide variety of CDR solutions

Common Criteria Certification: for the utmost in assurance of resistance to cyber attacks

Network Appliance: with web-based user interface for all administration, monitoring, management and even troubleshooting activities, with no additional software required to be installed on source or destination networks or servers.

vertical red line
Theory of Operation
Cybersecurity for Government Networks
Click to enlarge

Waterfall Unidirectional Security Gateways replace one layer of firewalls in the defensive design of classified high-security network environments, providing absolute protection from online data exfiltration attacks. Unidirectional Gateways contain both hardware and software components. Unidirectional Gateway technology represents a plug-and-play replacement for firewalls, without the vulnerabilities and maintenance issues that accompany firewall deployments.

vertical red line
Unidirectional Security Gateways Benefits:

arrow red right Safe cross-domain integration of classified and non-classified networks

arrow red rightEliminates any risk of online data leakage through the gateway from classified and other high-security networks

arrow red rightSimplifies compliance with even the most demanding cybersecurity regulations, standards and best-practice guidance, including USDHS, ANSSI, Australian Government Information Security, and more

arrow red rightSimplifies audits and change reviews

arrow red rightReplacing at least one of the layers of firewalls in a defense-in depth architecture with Unidirectional Security Gateways disables online data exfiltration attacks

vertical red line
Global Certifications and Compliance:

Certified: Common Criteria EAL 4+, ANSSI CSPN, NITES Singapore

Assessed by: US DHS SCADA Security Test Bed & Japanese Control Systems Security Center Bed, Idaho National Labs, Digital Bond Labs, GE Bently Nevada Systems Labs, and NISA Israel

Complies with: global ICS Standards & Regulations, NERC CIP, IEC 62443, NRC 5.71, NIST 800-82r2, CFATS, ISO, IIC SF, ANSSI, Australian Signals Directorate, and many more

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Cybersecurity for Government Networks appeared first on Waterfall Security Solutions.

]]>
UAE Based Oil & Gas Refinery  https://waterfall-security.com/ot-insights-center/oil-gas/case-study-uae-based-oil-gas-refinery/ Tue, 09 Jan 2024 10:13:20 +0000 https://waterfall-security.com/?p=17367 How a UAE-based refinery was able to protect their legacy system to the extent it could safely be connected to the internet, IT networks, and the Cloud.

The post UAE Based Oil & Gas Refinery  appeared first on Waterfall Security Solutions.

]]>

UAE Based Oil & Gas Refinery 

Defending a refinery's legacy OT systems

UAE based oil and gas refinery
The Challenge icon
Customer:

arrow red right A Leading Oil & Gas refinery in Dubai, United Arab Emirates

The Challenge icon
Challenge:

arrow red right The refinery needed to maintain secure access to plant data while facing increased cyber threats on their ICS

arrow red right Their legacy Wonderware Historian (AVEVA System Platform) was out-of-support, requiring a Unidirectional Gateway solution that integrated seamlessly without modifications.

Waterfall solution - icon
Waterfall’s Unidirectional Security Gateway Solution:

arrow red right Offered native integration with Wonderware AVEVA System Platform.

arrow red right Waterfall’s R&D team customized the integration connector to work flawlessly with the out-of-support legacy system, avoiding any modifications.

arrow red right Provided a continuously updated replica of the Historian server on the commercial IT network, ensuring the actual production server remained isolated and data flowed one-way (From OT to IT).

Unidirectional security gateway instead of a data diode for a legacy wonderware historian server for OT

Click to enlarge
Results and benefits - icon
Results & benefits

arrow red right100% Secure OT Network: Unbreachable by remote cyber threats.

arrow red rightReal-time Data Visibility: Full and secure access to real-time production data.

arrow red rightLegacy System Unaltered: No modifications required to the customer’s legacy systems.

arrow red rightScalability: The refinery’s success led to them ordering additional Waterfall Unidirectional Security Gateways for further applications.

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post UAE Based Oil & Gas Refinery  appeared first on Waterfall Security Solutions.

]]>
Securing a European TSO https://waterfall-security.com/ot-insights-center/power/cybersecurity-for-a-european-tso/ Mon, 04 Dec 2023 07:28:37 +0000 https://waterfall-security.com/?p=14308 Protecting a regional Transmission System Operator (TSO) in Europe from outside cyber threats.

The post Securing a European TSO appeared first on Waterfall Security Solutions.

]]>

Securing a European TSO

Defending a regional TSO in Europe from cyber threats
European TSO Case Study
Customer:

A leading European TSO

Customer Requirement:

Cybersecurity protection of critical industrial equipment and controls systems within a highly sensitive operating environment involving the regional transmission of electricity. The solution must also secure the collection, storage, and transfer of data from OT to IT and the cloud, as well as secure connectivity to 3rd party solutions such as those providing real-time holistic monitoring and asset management.

Waterfall’s Unidirectional Solution:

Waterfall’s Unidirectional solutions secure a grid’s industrial cyber perimeter from external threats while providing real-time enterprise visibility. Waterfall’s Unidirectional Security Gateways protect all industrial control systems (IED, Protective Relays, RTUs in Substations, SCADA DMS/EMS) with an impassable physical barrier to external network threats, while enabling enterprise access to real-time production data.

Transmitting Electricity While Containing Remote Cyber Threats

The energy industry has become increasingly prone to cyber attacks. Remote cyber attacks on electric transmission infrastructure can result in severe disruptions to society, as well as create life threatening scenarios to hospitals and urgent care facilities. Repeat disruptions can severely damage economic confidence and hurt a region’s world image.

The Challenge icon
The challenge

Protecting industrial control systems from external cyber threats without hindering access to real-time operational data, with the end-goal of securing the safe, reliable, and continuous operation of regional electrical transmission.

Waterfall solution - icon
Waterfall’s solution

A Waterfall Unidirectional Security Gateway was installed between the PI Production Server and the PI Server on the Commercial IT network.

European TSO Case Study - Replicated Pi Server
Click to enlarge

The Unidirectional Security Gateway provides a continuously updated replica of the PI Production server, so that the PI Server on the commercial IT network is only accessing the replica copy of the PI Production server. The actual PI Production server itself has no direct contact with the commercial IT network and data only flows out of the PI Production Server.

Results and benefits - icon
Results & benefits
  • 100% Security: With Unidirectional Security Gateways, the PI Production Server is now physically protected from any threats emanating from the regular IT network or the cloud.

  • 100% Real-time Data Visibility: The commercial IT network continues to operate as if nothing has changed. Instead of accessing servers on the critical operational network, users on the commercial IT network now access real-time data from replicated servers, with all the informational and analytical requirements.
Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Securing a European TSO appeared first on Waterfall Security Solutions.

]]>
Cybersecurity for LNG Ports https://waterfall-security.com/ot-insights-center/oil-gas/cybersecurity-for-lng-ports/ Mon, 16 Oct 2023 19:48:18 +0000 https://waterfall-security.com/?p=12844 Protect liquefied natural gas (LNG) infrastructure from external cyber threats while complying with local cybersecurity regulations.

The post Cybersecurity for LNG Ports appeared first on Waterfall Security Solutions.

]]>

Cybersecurity for LNG Ports

Defending Critical LNG Import Terminals From Cyber Threats
Cybersecurity For LNG Ports
Customer/ Partner:
European LNG Import Terminal
Customer Requirement:
Protect LNG infrastructure from remote cyber attack while complying with local cybersecurity regulations
Waterfall’s Unidirectional Solution:
Secures control system network perimeters from external threats with Unidirectional Security Gateways, enabling enterprise-wide visibility for operations status and key performance indicators, as well as safe ICS network monitoring from a central enterprise SIEM.
Cybersecurity Is A Business Imperative For Lng Ports And Terminals
Because LNG infrastructure is highly visible and handles sensitive materials, the infrastructure can be vulnerable to targeted cyber attacks. With the growing global threat of sophisticated attacks and targeted ransomware, LNG facilities must protect industrial operations from attacks propagating from IT to OT networks. Cyber compromise can result in potentially catastrophic consequences to critical assets, the environment and even human life
The Challenge icon
The challenge
Protect industrial control systems from remote cyber attacks to allow reliable and efficient operations, while enabling safe monitoring and optimization of operations. In addition, comply to current and anticipated local regulatory requirements for critical infrastructure networks
Waterfall solution - icon
Waterfall solution
A Waterfall Unidirectional Security Gateway was installed connecting the port’s control system networks to the port’s IT network. Unidirectional Gateway software replicates OPC-DA servers from the control network to the enterprise network where PI Servers query and otherwise interact normally with the OPC replica server. Unidirectional Gateway hardware physically prevents cyber threats from reaching sensitive industrial control networks. Syslog, SNMP trap and other security monitoring data is also forwarded unidirectionally into a central Security Operations Center (SOC). Remote Screen View enables remote support.
Results and benefits - icon
Results & benefits

100% Security: The LNG terminal network is now physically protected from threats emanating from external, less-trusted, Internet- exposed networks.

100% Visibility: The enterprise network benefits from real-time, comprehensive operational data. Instead of directly accessing servers on the critical operational network, external users access replica servers to meet business requirements.

100% Compliance: Unidirectional Gateways simplify compliance with global industrial control system cybersecurity standards and regulations by virtue of the strength of network protection they provide.

vertical red line
Theory of Operation
Click to enlarge
Waterfall Unidirectional Security Gateways replace firewalls in industrial network environments, providing absolute protection to control systems and industrial control networks from attacks emanating from external less-trusted networks. Waterfall Gateways contain both hardware and software components. The hardware components include a TX Module, containing a fiber-optic transmitter/ laser, and an RX Module, containing an optical receiver, but no laser. The gateway hardware can transmit information from an industrial network to an external network, but is physically incapable of propagating any virus, DOS attack, human error or any cyber attack at all back into the protected industrial network. The gateways enable control-system intrusion detection, vendor monitoring, industrial cloud services, and visibility into operations for modern enterprises and customers. Unidirectional Gateways replicate servers, emulate industrial devices and translate industrial data to cloud formats. Unidirectional Gateway technology represents a plug-and-play replacement for firewalls, without the vulnerabilities and maintenance issues that accompany firewall deployments
vertical red line
Unidirectional Security Gateways Benefits:

arrow red rightSafe transmission of OPC data to external networks without risk to critical networks

arrow red rightSafe monitoring of control system networks from external security operations centers

arrow red rightSafe remote supervision of changes to protected systems

arrow red rightSimplifies compliance to local cybersecurity regulations and best practices

vertical red line
Global Cybersecurity Standards Recommend Unidirectional Security Gateways

Waterfall Security is the market leader for Unidirectional Gateway technology with installations at critical infrastructure sites across the globe. The enhanced level of protection provided by Waterfall’s Unidirectional Security Gateway technology is recognized as best practice by leading industry standards bodies and authorities such as NIST, ANSSI, NERC CIP, the ISA, the US DHS, ENISA and many more.

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Cybersecurity for LNG Ports appeared first on Waterfall Security Solutions.

]]>
Unidirectional Protection For Railway Signaling Networks https://waterfall-security.com/ot-insights-center/transportation/unidirectional-protection-for-railway-signaling-networks/ Thu, 08 Sep 2022 13:55:00 +0000 https://waterfall-security.com/?p=9895 Enabling 100% secure remote monitoring of rail signaling and control networks, enabling SOC and corporate IT systems with secure visibility into signaling networks.

The post Unidirectional Protection For Railway Signaling Networks appeared first on Waterfall Security Solutions.

]]>

Unidirectional Protection For Railway Signaling Networks

Protecting Rail Signaling Networks From External Cyber Threats
Unidirectional Protection For Railway Signaling Networks
Customer/ Partner:

North American metro and regional rail operator.

Customer Requirement:

Enable 100% secure monitoring and protection of rail signaling and control networks, to allow SOC and corporate IT systems visibility into signaling networks connected to safety requirements.

Waterfall’s Unidirectional Solution:

Secure and physically protect control and signaling system network perimeters from external threats with Unidirectional Security Gateways, enabling enterprise-wide and vendor visibility for operations status, as well as safe OT network monitoring from a central enterprise SOC.

Protecting Rail Signaling Networks From External Cyber Threats

With cyber attacks on railway networks speckling the globe in recent years, the growth in rail cyber security awareness is on the rapid uptick. Signaling and rail control networks, such as CBTC in metro networks, and PTC and ETCS in North American and European Railways are becoming increasingly vulnerable to remote cyber sabotage. Modern cyber threats cannot be defeated reliably by common IT security such as firewalls. Hardware-based Unidirectional Security Gateways enable the digital efficiencies of a modern connected rail system, while providing the strongest protection for signaling systems from online attacks.

The Challenge icon
The challenge

Provide secure, real-time access to signaling data for the IT corporate network, including logs, alert messages, train location data and scheduling and other security data needed by the SOC. The console screen of the signaling system must be remotely visible from the corporate
network.


As the signaling network contains vital systems  ecessary for the correct operation of the rail system, including safety rated systems, that network should be physically protected from all outside networks.

Waterfall solution - icon
Waterfall solution

Waterfall Unidirectional Gateways were deployed to replicate SYSLOG for logs, SMTP for specialized alert systems, XML files for signal status. Waterfall Remote Screen View was deployed to provide secure remote access to the signaling system for enterprise users. Unidirectional Gateways provide physical, hardware-enforced protection for the signaling network, while allowing the corporate SOC and other monitoring networks to access realtime data, and to respond rapidly to alerts coming from the signaling system.

Results and benefits - icon
Results & benefits
  • Enables 100% secure integration of signaling networks with corporate networks
  • Provides visibility from the corporate network into real-time signaling status information
  • Prevents all attacks, no matter how sophisticated from reaching signaling systems from the Internet
  • Maintain safety requirements for safety systems with hardware-enforced security
  • Signaling networks are protected absolutely from any threat propagating via connections to the Internet, to 3rd parties, or to vendors.
vertical red line
Theory of Operation
Click to enlarge

Waterfall Unidirectional Security Gateways replace firewalls in industrial network environments, providing absolute protection to safety critical and control system networks from attacks emanating from external less-trusted networks. Waterfall Gateways contain both hardware and software components. The hardware includes a TX Module, containing a fiber-optic transmitter/laser, and an RX Module, containing an optical receiver, but no laser. The gateway hardware can transmit information from a critical network to an external network, but is physically incapable of propagating any virus, DOS attack, human error or any cyber attack at all back into protected safety-critical and control networks. Unidirectional Gateway software replicates database servers and other systems unidirectionally. The replica databases on the IT networks provide IT users, customers and passengers with the same data as would have been sourced from control-critical databases, without ever sending even one message from IT networks back into control-critical networks. It does not matter how sophisticated attacks become or how clever attackers are – if no information or attacks can enter control-critical networks. Modern rail system operators embrace both increased efficiencies and reduced risk by deploying physical, unidirectional protections from cyber attacks as part of on-going automation improvements. 

vertical red line
Unidirectional Security Gateways Benefits

arrow red rightEnable 100% secure, real-time reporting of metro car or EMU location, tracks, and operational status to passengers, business management, track technicians, infrastructure partners, and other rail operators.

arrow red rightProtect the reliability of operations, the safety of worker, and the public
safety from external cyber-attacks.

arrow red rightSafe remote supervision of changes to protected systems.

arrow red rightProtect rail operators from brand and reputational damage due to service outages.

vertical red line
Global Cybersecurity Standards Recommend Unidirectional Security Gateways

Waterfall Security is the market leader for Unidirectional Gateway technology with installations at critical infrastructure sites across the globe. The enhanced level of protection provided by Waterfall’s Unidirectional Security Gateway technology is recognized as best practice by leading industry standards bodies and authorities such as NIST, ANSSI, NERC CIP, the ISA, the US DHS, ENISA and many more.

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Unidirectional Protection For Railway Signaling Networks appeared first on Waterfall Security Solutions.

]]>
Enabling The Digital Refinery https://waterfall-security.com/ot-insights-center/oil-gas/enabling-the-digital-refinery/ Thu, 08 Sep 2022 10:59:00 +0000 https://waterfall-security.com/?p=10502 Protecting critical equipment of a highly sensitive petrochemicals processing plant, while improving production performance with real-time, actionable, and predictive analytics.

The post Enabling The Digital Refinery appeared first on Waterfall Security Solutions.

]]>

Enabling The Digital Refinery

Protecting The Refining & Petrochemical Industry From Evolving Cyber Threats
Enabling The Digital Refinery
Customer/ Partner:

North American Petrochemical Refinery.

Customer Requirement:

To protect critical equipment and on-going productivity of a highly sensitive production environment involving the processing of petrochemicals, while at the same time improve the performance of plant production with real-time, actionable and predictive analytics.

Waterfall’s Unidirectional Solution:

Secure the production environment perimeter from external threats and provide real-time enterprise visibility – Unidirectional Security Gateways protect all industrial control systems (DCS, individual controllers and logic controllers) with an impassable physical barrier to external network threats, while enabling enterprise access to real-time production data.

Refining & Petrochemicals Processing Modernization And Containing Remote Cyber Threats

The energy industry has become the second most prone to cyber attacks with nearly three-quarters of U.S. oil & gas companies experiencing at least one cyber incident. Remote cyber attacks on oil and gas refining & production can result in severe consequences to human and environmental safety in the form of ruptures, explosions, fires, releases, and spills. In addition, disruption of service and deliverability can be devastating for key infrastructure end users such as power plants, airports or national defense.

The Challenge icon
The challenge

To secure the safe, reliable and continuous operation of oil & gas processing control and safety networks from threats emanating from less trusted external networks. At the same time provide real-time access to operations data to the enterprise users and applications, as well as provide periodic and on-demand inbound access for anti-virus and other updates to turbine vendors and other third parties.

Waterfall solution - icon
Waterfall solution

A Waterfall Unidirectional Gateway was installed between the process control network (PCN) and the enterprise network. Unidirectional Gateway software connectors replicate OSISoft PI, GE OSM and ICCP servers from the PCN to the enterprise network where enterprise clients can interact normally and bi-directionally with the replicas. A file server replication connector was also deployed, to eliminate the routine use of USB drives and other removable media. A Waterfall FLIP, a hardware-enforced Unidirectional Security Gateway whose orientation is reversible, was also installed between the PCN and IT networks. By schedule, or by exception, an independent control mechanism inside the protected OT network triggers the FLIP hardware to change orientation, allowing information to flow back into the protected OT network as needed.

Results and benefits - icon
Results & benefits
  • 100% Security: With the gateways, the PCN is now physically protected from threats emanating from external, less-trusted networks. The FLIP permits disciplined, on-demand and scheduled updates of plant systems, without introducing firewall vulnerabilities.
  • 100% Visibility: The enterprise network continues to operate as if nothing has changed. Instead of accessing servers on the critical operational network, users on the external network now access real-time data from replicated servers for all informational and analytical requirements.
  • 100% Compliance: Unidirectional Gateways are recognized manufacturing cyber security standards as well as by global industrial control system cyber security standards and regulations.
vertical red line
Theory of Operation
Click to enlarge

Waterfall Unidirectional Security Gateways replace firewalls in industrial network environments, providing absolute protection to control systems and operations networks from attacks originating on external networks. The Gateways enable vendor monitoring, industrial cloud services, and visibility into operations for modern enterprises and customers. Unidirectional Gateways replicate servers, emulate industrial devices and translate industrial data to cloud formats. As a result, Unidirectional Gateway technology represents a plug-andplay replacement for firewalls, without the vulnerabilities and maintenance issues that always accompany firewall deployments. Unidirectional Gateways contain both hardware and software components. The hardware components include a TX Module, containing a fiber-optic transmitter/ laser, and an RX Module, containing an optical receiver, but no laser. The gateway hardware can transmit information from an industrial network to an external network, but is physically incapable of propagating any virus, DOS attack, human error or any cyber attack at all back into the protected network.

vertical red line
Unidirectional Security Gateways Benefits

arrow red rightSafe, continuous monitoring of critical systems

arrow red rightProtects product quality, safety of personnel, property and the environment

arrow red rightProtects safety and preventative maintenance systems of physical assets from remote Internet-based threats

arrow red rightSimplifies audits, change reviews, and security system documentation

arrow red right
Disciplined, on-demand and scheduled updates of plant systems, without introducing firewall vulnerabilities

arrow red rightReplaces at least one layer of firewalls in a defense-in-depth architecture thereby breaking the chain of infection and pivoting attacks

vertical red line
Global Cybersecurity Standards Recommend Unidirectional Security Gateways

Waterfall Security is the market leader in Unidirectional Gateway technology with installations at critical infrastructure sites across the globe. The enhanced level of protection provided by Waterfall’s Unidirectional Security Gateway technology is recognized as best practice by many leading industry standards bodies such as NIST, ANSSI, NERC, the IEC, the US DHS, ENISA and may more.

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Enabling The Digital Refinery appeared first on Waterfall Security Solutions.

]]>
Securing Pharmaceutical Manufacturing Systems and Intellectual Property https://waterfall-security.com/ot-insights-center/manufacturing/securing-pharmaceutical-manufacturing-systems-and-intellectual-property/ Thu, 08 Sep 2022 09:34:00 +0000 https://waterfall-security.com/?p=10495 Securing enterprise-wide access to real-time data while protecting manufacturing operations and product recipes from cyber attacks.

The post Securing Pharmaceutical Manufacturing Systems and Intellectual Property appeared first on Waterfall Security Solutions.

]]>

Securing Pharmaceutical Manufacturing Systems and Intellectual Property

Building Pharmaceutical’s Immunity Against Intellectual Property Theft
Securing Pharmaceutical Manufacturing Systems And Intellectual Property
Customer/ Partner:

European pharmaceutical manufacturer.

Customer Requirement:

To provide enterprise-wide access to real-time data while protecting manufacturing operations and product recipes from cyber attacks.

Waterfall’s Unidirectional Solution:

Deploy Unidirectional Security Gateways as safe network integration between manufacturing systems and IT systems, enabling real-time, enterprise-wide monitoring of operations while preventing remote access to product recipes in manufacturing control systems

Cyber Risks To Pharmaceutical Manufacturing

Manufacturing network digitization is either underway or in the planning phase at most pharmaceutical manufacturing facilities. The benefits of enterprise-wide access to real-time data from industrial control systems are undeniable, but the risks are considerable as well. Modern cyber attacks can breach firewalls and other software security systems to steal product recipes and other vital intellectual property and threaten to interfere with industrial control operations as well.

The Challenge icon
The challenge

To secure the production network from intellectual property (IP) theft and cyber-sabotage from threats emanating from less trusted external networks, yet still provide safe, real-time access to live operations data for the corporate network. Modern industrial attacks routinely defeat firewalls, encryption, anti-virus systems, security updates, intrusion detection systems and other software protections. Protecting pharmaceutical critical assets with firewalls and other software security measures is not enough.

Waterfall solution - icon
Waterfall solution

A Waterfall Unidirectional Gateway was installed to replicate the control system historian database to an enterprise historian. Unidirectional Gateway hardware makes online attacks on ICS networks from external networks physically impossible. To protect product recipes and other trade secrets, the Unidirectional Gateway was configured to replicate only those historian tags that are safe to share with the enterprise network. Tags containing recipes, formulas and other intellectual property were left untouched in the control system historian.

Results and benefits - icon
Results & benefits
  • 100% Security: Production processes and intellectual property are now physically protected from any attacks originating on external networks.
  • 100% Visibility: Enterprise users and applications have access to all permitted real-time data via the enterprise historian.
  • 100% Compliance: Unidirectional Gateways simplify compliance with global regulations, standards and best practice guidance for industrial cybersecurity.
vertical red line
Theory of Operation
Click to enlarge

Waterfall Unidirectional Security Gateways replace firewalls in pharmaceutical manufacturing network environments, providing absolute protection to manufacturing control systems from attacks emanating from external networks. Unidirectional Gateways contain both hardware and software components. The hardware components include a TX Module, containing a fiber-optic transmitter/laser, and an RX Module, containing an optical receiver, but no laser. The gateway hardware can transmit information from the manufacturing network to the external network, but is physically incapable of propagating any virus, DOS attack, human error or any cyber attack at all back into the protected network. The Gateways enable vendor monitoring, industrial cloud services, and visibility into operations for modern enterprises and manufacturers. Unidirectional Gateways replicate entire servers or selected subsets, emulate industrial devices and translate manufacturing data to cloud formats. As a result, Unidirectional Gateway technology represents a plug-and-play replacement for firewalls, without the vulnerabilities and maintenance issues that accompany firewall deployments.

vertical red line
Unidirectional Security Gateways Benefits

arrow red rightUltimate protection from remote attack consequences, including IP theft, damage to devices and manufacturing process disruption.

arrow red rightSmart devices and control systems are securely integrated with external networks.

arrow red rightSimplifies audits, change reviews, and security system documentation.

arrow red rightPrevents all remote access to production recipes stored in manufacturing control systems.

arrow red rightReplaces at least one layer of firewalls in a defense-in-depth architecture, breaking the chain of infection and pivoting attacks.

vertical red line
Security And Compliance

Certification: Common Criteria EAL 4+, ANSSI CSPN, NITES Singapore, CCC China


Assessments: US DHS SCADA Security Test Bed & Japanese Control Systems Security Center Bed, Idaho National Labs, Digital
Bond Labs, GE Bently Nevada Systems Labs, and NISA Israel


Complies with: Global ICS Standards & Regulations, including NERC CIP, IEC 62443, NRC 5.71, NIST 800-82r2, CFATS, ISO, IIC SF,
ANSSI, and many more

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Securing Pharmaceutical Manufacturing Systems and Intellectual Property appeared first on Waterfall Security Solutions.

]]>
Protecting the GIPL pipeline https://waterfall-security.com/ot-insights-center/oil-gas/protecting-the-gipl-pipeline/ Thu, 08 Sep 2022 08:36:00 +0000 https://waterfall-security.com/?p=4860 Protecting operational data within the gas transmission SCADA system, while enabling safe visibility and exchange of operational data for both pipeline partners.

The post Protecting the GIPL pipeline appeared first on Waterfall Security Solutions.

]]>

Protecting the GIPL pipeline

Waterfall teams with ELSIS TS to reinforce cybersecurity at gas interconnection Poland and Lithuania facilities
Customer/ Partner:

Lithuanian-based ICT and OT company ELSIS TS at GIPL sites

Customer Requirement:

Protecting operational data exchange within the gas transmission SCADA system, while enabling safe visibility and exchange of operational data for both pipeline partners.

Waterfall’s Unidirectional Solution:

Secures control system network perimeters from external threats with Unidirectional Security Gateways, enabling enterprise-wide visibility for operations status and key performance indicators as well as safe ICS network monitoring from a central enterprise SIEM.

Cross border pipeline infrastructure is facing real cyber threats

The Colonial Pipeline incident, Russian actions in the Ukraine, targeted ransomware actors and other threats have raised serious concerns about the cybersecurity of critical national infrastructures. This deployment of Unidirectional Gateways provides the world’s strongest protection from online attacks to this important natural gas interconnection.

The Challenge icon
The challenge

Secure the automation processes of the GIPL pipeline for the safe exchange of operational data between the gas transmission systems of the two countries, without posing risk to reliable, uninterrupted and efficient operation of the complex, transnational pipeline infrastructure. In addition, enable a central dispatch centre to remotely monitor and control process operations.

Waterfall solution - icon
Waterfall solution

Waterfall integrated Unidirectional Security Gateways to unidirectionally replicate gas metering and pressure reduction data between Polish and Lithuanian sites, without posing risk to process control networks. Unidirectional Gateways replicate industrial data to a central dispatch center to enable the safe exchange of data between geographically dispersed sites.

Results and benefits - icon
Results & benefits

Security: Unidirectional Gateways enabled the secure exchange of multisite operational data between countries. OT data replication provides strong assurance that no attack from the IT network can enter the operational network.

Simplicity: Unidirectional server replication makes the gateways easy to use. The unidirectional replicas are realtime participants in both source and destination networks.

Performance: Safe industrial data exchange for international pipeline infrastructure, not only optimizes business efficiencies, but ensures the security of critical resources.

vertical red line
Theory of Operation
Click to enlarge

Waterfall Unidirectional Security Gateways replace firewalls in industrial network environments, providing absolute protection to control systems and industrial control networks from attacks originating from external less-trusted networks. Unidirectional Gateways contain both hardware and software components. The hardware components include a TX Module, containing a fiber-optic transmitter/ laser, and an RX Module, containing an optical receiver, but no laser. The gateway hardware can transmit information from an industrial network to an external network, but is physically incapable of propagating any virus, DOS attack, human error or any cyber attack at all back into the protected industrial network.

This deployment used two Unidirectional Security Gateways to enable safe control-system data exchange, external monitoring, and visibility into operations for the GIPL sites. Unidirectional Gateways replicate servers, emulate industrial devices and translate industrial data to cloud formats. Unidirectional Gateway technology represents a plug-and-play replacement for firewalls, without the vulnerabilities and maintenance issues that accompany firewall deployments.

vertical red line
Unidirectional Security Gateways Benefits

arrow red rightSafe operational data exchange between geographically disparate facilities

arrow red rightSecure monitoring of operational data from less-secure, Internet-based networks

arrow red rightStrongest industrial security for automation processes and systems

arrow red rightSafe replication of critical data to enhance operational efficiencies

vertical red line
Global Cybersecurity Standards Recommend Unidirectional Security Gateways

Waterfall Security is the market leader for Unidirectional Gateway technology with installations at critical infrastructure sites across the globe. The enhanced level of protection provided by Waterfall’s Unidirectional Security Gateway technology is recognized as best practice by leading industry standards bodies and authorities such as NIST, ANSSI, NERC CIP, the ISA, the US DHS, ENISA and many more.

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Protecting the GIPL pipeline appeared first on Waterfall Security Solutions.

]]>
Cybersecurity For Data Centers https://waterfall-security.com/ot-insights-center/facilities/cybersecurity-for-data-centers/ Thu, 08 Sep 2022 07:08:00 +0000 https://waterfall-security.com/?p=10043 Enabling security monitoring and management of multiple segmented operational networks without adding any cyber risk.

The post Cybersecurity For Data Centers appeared first on Waterfall Security Solutions.

]]>

Cybersecurity For Data Centers

Protecting data center operational networks from evolving cyber threats
Cybersecurity For Data Centers
Data Center Security Solutions

Data center security solutions protect physical and digital assets by combining access control, video surveillance, fire suppression, encryption, and network monitoring. These solutions prevent unauthorized access, detect intrusions, and ensure compliance with regulatory standards like ISO/IEC 27001 and SOC 2.

Customer/ Partner:

A large, multi-site data center corporation in Asia Pacific.

Customer Requirement:

Enable security monitoring and management of multiple segmented operational networks without putting these protected networks at risk.

Waterfall’s Unidirectional Solution:

The Waterfall Unidirectional Security Gateway enables the safe monitoring and remote management of operational networks without risk that enterprise connectivity will “leak” attacks back into protected operational control networks.

Data Centers Growing Need To Protect Physical Operations

Enable safe access to OT files, OPCUA data, Syslog alerts, and OT emailed updates for external IT services. Enable the access for an off-site Security Operations Center which the data for security monitoring purposes, and for other IT systems, which use the operations data for a variety of business automation purposes. Enable all of these integrations safely, without risk to physical operations at the data center.

The Challenge icon
The challenge

Waterfall’s Unidirectional Security Gateways were deployed to protect building automation, access control and electrical systems at a fleet of data centers. Each gateway protects multiple data center operational networks and replicates OPC UA, Syslog and other data through unidirectional hardware. In addition, Waterfall’s Remote Screen View enables off-site management and updates of OT systems without enabling risky remote desktop connections.

Waterfall solution - icon
Waterfall solution

Waterfall’s Unidirectional Security Gateways were deployed to protect building automation, access control and electrical systems at a fleet of data centers. Each gateway protects multiple data center operational networks and replicates OPC UA, Syslog and other data through unidirectional hardware. In addition, Waterfall’s Remote Screen View enables off-site management and updates of OT systems without enabling risky remote desktop connections.

Results and benefits - icon
Results & benefits

Security: No attack from any external, third-party or Internet network can leak back into protected operational networks through the unidirectional gateway hardware.

Simplicity: Unidirectional server replication and emulation make Waterfall’s gateways easy to use. The unidirectional replicas are normal participants in external IT networks.

Efficiencies: By securely enabling access to OT data, the gateways help the business realize SOC-based visibility into OT networks and other business automation and efficiencies – safely.

vertical red line
Theory of Operation
Click to enlarge

Waterfall Unidirectional Security Gateway solutions replace firewalls in industrial network environments, providing absolute protection to control systems and operations networks from attacks emanating from external less-trusted networks. Waterfall Gateways contain both hardware and software components. The gateway hardware can transmit information from an industrial network to an external network, but is physically incapable of propagating any virus, DOS attack, human error or any cyber attack at all back into the protected industrial network. Unidirectional Gateway software makes copies of industrial servers, enabling external IT and Internet users to connect the replica servers for access to real-time operational information. At this customer, the Unidirectional Security Gateway copies standard OPC-UA servers, Syslog servers, SMTP servers and file servers from operational networks to the IT network where SOC systems and analysts, as well as other IT business automation systems can access the replicas and their OT data normally. The gateway is also equipped with unidirectional Remote Screen View to enable remote vendor support personnel to see the screen of the Engineering Workstation in order to assist site personnel in diagnosing, adjusting and correcting software and hardware problems.

vertical red line
Unidirectional Security Gateway Benefits:

arrow red rightSafe IT/OT integration, providing access to operations data, without risk of compromise of critical data center operations networks.

arrow red rightSafe unidirectional data transfer to offsite or less trusted networks without introducing cyber threats to the OT environment.

arrow red rightSupports 100+ industrial protocols & applications; from legacy systems to cloud-based platforms.

arrow red rightNo attack, no matter how sophisticated or malicious, can enter the unidirectionally protected network.

arrow red rightEnables secure deployment of IT and outsourced SIEM, SOC, NOC & security monitoring solutions.

vertical red line
Global Cybersecurity Standards Recommend Unidirectional Security Gateways

Waterfall Security is the market leader for Unidirectional Gateway technology with installations at critical infrastructure sites around the world. The level of protection provided by Waterfall’s Unidirectional Security Gateway technology is recognized as best practice by leading industry standards bodies and authorities such as NIST, ANSSI, NERC CIP, ISA / IEC 62443, the US DHS & CISA, ENISA, TS50701 and many others.

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Cybersecurity For Data Centers appeared first on Waterfall Security Solutions.

]]>
Food And Beverage Manufacturing https://waterfall-security.com/ot-insights-center/manufacturing/food-and-beverage-manufacturing/ Thu, 08 Sep 2022 06:47:00 +0000 https://waterfall-security.com/?p=9935 Enabling secure, cloud-based operational equipment effectiveness (OEE) monitoring without introducing any new cyber risks to the OT network.

The post Food And Beverage Manufacturing appeared first on Waterfall Security Solutions.

]]>

Food And Beverage Manufacturing

Protecting Operational Networks In The Food And Beverage Industry From Evolving Cyber Threats
Food And Beverage Manufacturing
Customer/ Partner:

A large, global food and beverage company.

Customer Requirement:

Enable secure, cloud-based operational equipment effectiveness (OEE) monitoring without introducing cyber risk to the OT network.

Waterfall’s Unidirectional Solution:

The Waterfall Unidirectional Cloud Gateway provides the benefits of connections to industrial cloud services, without the risk that cloud or Internet connectivity will “leak” attacks back into protected industrial control systems.

Food & Beverage Manufacturing – Today’s Cyber Threat Environment

Food & Beverage operators have suffered large scale ransomware attacks in recent years, triggering costly production shut-downs. Looking forward, manufacturers are concerned about even worse outcomes – cyber attackers could tamper with production processes to contaminate foodstuffs, with recipes to impair product quality and with batch records to render large volumes of product un-marketable. The threat is compounded when production lines are connected to Internet-based cloud services – a compromised cloud could compromise hundreds or thousands of connected industrial clients, simultaneously.

The Challenge icon
The challenge

Enable safe deployment of the RedZone platform for multi-site OEE monitoring, actionable insights and productivity improvements. In particular, enable safe Amazon AWS cloud connectivity for the RedZone platform, without introducing cyber risk to critical manufacturing networks. Do all this with minimal changes to existing Purdue-Model / ISA 62443 security measures

Waterfall solution - icon
Waterfall solution

The customer deployed Waterfall’s Unidirectional Cloud Gateways at multiple sites. The Gateways replicated OPC servers and their data through unidirectional hardware. RedZone equipment used the replica OPC servers normally, to connect to the RedZone AWS infrastructure. No change to existing control system designs or security systems were needed, beyond installation and configuration of RedZone and Waterfall equipment.

Results and benefits - icon
Results & benefits

Security: No attack from any external, cloud or Internet network can leak back into protected control systems through any Unidirectional Cloud Gateway.

Transparency: Unidirectional Cloud Gateways enable safe cloud connectivity without changes to existing firewalls, networks or security monitoring systems.

Performance: By securely enabling the OEE application, Waterfall’s Unidirectional Cloud Gateway helps the business realize an 8% increase in plant productivity.

vertical red line
Theory of Operation
Click to enlarge

Waterfall Unidirectional Cloud Gateway solutions replace firewalls in industrial network environments, providing absolute protection to control systems and industrial control networks from attacks emanating from external less-trusted networks. Waterfall Gateways contain both hardware and software components. The hardware components include a TX Module, containing a fiber-optic transmitter/laser, and an RX Module, containing an optical receiver, but no laser. The gateway hardware can transmit information from an industrial network to an external network, but is physically incapable of propagating any virus, DOS attack, human error or any cyber attack at all back into the protected industrial network. Unidirectional Cloud Gateway software makes copies of industrial servers. External IT and Internet users connect normally to the replica servers and access data there normally.

At this customer, the Unidirectional Cloud Gateway was deployed to copy a standard OPC-UA server from the industrial network to the IT network where a RedZone RZLogger was deployed. The logger connected to both the OPC-UA replica server and to RedZone services in the Amazon AWS cloud. The deployment was completely safe, because no attack is able to penetrate the Unidirectional Cloud Gateway hardware to reach into the Industrial Network to put physical operations or any data management systems in that network at risk.

vertical red line
Unidirectional Cloud Gateways Benefits:

arrow red rightPhysically prevents cloud/Internet-based attacks from infecting the protected industrial network.

arrow red rightAll the benefits of cloud-connected infrastructure to industrial operations, without the risks of cloud connectivity.

arrow red rightSupports 100+ industrial protocols & applications; from legacy systems to cloud-based platforms.

arrow red rightSafe cloud vendor supply chain integration, big data analysis, cross-site and cross-application analysis, and correlations.

arrow red rightEnables secure deployment of IT and outsourced SIEM, SOC, NOC & security monitoring solutions.

vertical red line
Global Cybersecurity Standards Recommend Unidirectional Security Gateways

Waterfall Security is the market leader for Unidirectional Gateway technology with installations at critical infrastructure sites around the world. The level of protection provided by Waterfall’s Unidirectional Security Gateway technology is recognized as best practice by leading industry standards bodies and authorities such as NIST, ANSSI, NERC CIP, ISA / IEC 62443, the US DHS & CISA, ENISA, TS50701 and many others.

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Food And Beverage Manufacturing appeared first on Waterfall Security Solutions.

]]>