Access my OT networks, safely
Traditional remote access is high risk for OT networks. Vendors don’t always have sufficient background checks, some of the existing passwords may be weak or already stolen, and always-on remote access systems often have known and zero-day vulnerabilities that can be compromised at an attacker’s convenience.
Waterfall’s Unidirectional Security Gateways deliver secure access to OT networks, while remaining unbreachable to cyber attackers.
With Waterfall you get
Unidirectional Remote Screen View (RSV) sends a video feed of engineering workstation and other industrial screens through Unidirectional Gateway hardware to a web server for use by remote 3rd parties, such as vendors. 3rd parties can see mouse movements and screen activity and can provide real time analysis and advice via phone to site engineers and technicians. Site engineers ask questions and take notes before accepting any advice from vendors. Unidirectional hardware means no stolen passwords or two-factor vulnerabilities can put operations at risk.
Waterfall's Secure Bypass (SBP) unit can be installed in parallel with a Unidirectional Gateway. When the SBP unit is activated by a key, it creates a temporary 1Gbps bi-directional connection into the protected network. After a pre-programmed period, typically 30-90 minutes, the unit physically disconnects the remote access connection, and no remote commands or attack information can enter the protected network anymore. SBP gives industrial sites physical control over remote access by trusted insiders.
Waterfall's Unidirectional Gateways make copies of equipment monitoring and diagnostic servers for use by equipment vendors. The vendors use the IT copies of their servers to diagnose problems and recommend maintenance. All this while no ransomware or stolen password or other attack can penetrate the Unidirectional Gateway hardware to put physical operations, workers or equipment at risk.
Vendor Access
Unidirectional Remote Screen View (RSV) sends a video feed of engineering workstation and other industrial screens through Unidirectional Gateway hardware to a web server for use by remote 3rd parties, such as vendors. 3rd parties can see mouse movements and screen activity and can provide real time analysis and advice via phone to site engineers and technicians. Site engineers ask questions and take notes before accepting any advice from vendors. Unidirectional hardware means no stolen passwords or two-factor vulnerabilities can put operations at risk.
Insider Access
Waterfall's Secure Bypass (SBP) unit can be installed in parallel with a Unidirectional Gateway. When the SBP unit is activated by a key, it creates a temporary 1Gbps bi-directional connection into the protected network. After a pre-programmed period, typically 30-90 minutes, the unit physically disconnects the remote access connection, and no remote commands or attack information can enter the protected network anymore. SBP gives industrial sites physical control over remote access by trusted insiders.
Continuous Vendor Monitoring
Waterfall's Unidirectional Gateways make copies of equipment monitoring and diagnostic servers for use by equipment vendors. The vendors use the IT copies of their servers to diagnose problems and recommend maintenance. All this while no ransomware or stolen password or other attack can penetrate the Unidirectional Gateway hardware to put physical operations, workers or equipment at risk.
Remote Access Solutions
Waterfall provides a variety of remote access solutions designed to cater to different customer requirements and architectures, all while prioritizing safety and security.
Flip
The FLIP reverses a built-in Unidirectional Security Gateway allowing scheduled updates.
Secure Bypass
The Secure Bypass Module enables on-site, physical control over remote access connections.
Waterfall’s Industry-Specific Solutions
Cybersecurity for power plants
Power utilities rest easy knowing that remote cyber attacks cannot reach through their Unidirectional Gateways to mis-operate control systems responsible for worker and public safety, for preventing damage to long-lead time turbines and other equipment, or for assuring continuous and efficient production of electric power.
Cybersecurity for oil & gas
Owners and operators of offshore platforms, pipelines and refineries rest easy knowing that no cyber-sabotage attack is able to penetrate Unidirectional Gateway hardware to put at risk worker or public safety, the environment, long-lead-time equipment and reliable production and operation, without unplanned shutdowns.
Cybersecurity for rails
Rail and metro system operators rest assured when Unidirectional Gateways are deployed to protect vital networks including switching systems, electric power systems and operations control centers from cyber attacks originating on IT or Internet networks, no matter how sophisticated such attacks are now, or might become in the future.
Cybersecurity for facilities
Data centers, airports, government and military campuses and other very important facilities operators sleep well knowing that Unidirectional Gateways are unbreachable in the face of attacks traversing Internet-exposed IT networks to put public safety, important equipment and continuous & connect operations at risk
Cybersecurity for water Treatment
With Unidirectional Gateways deployed, municipal leaders can be confident of continuous and correct operation of their automation systems and water treatment infrastructure , even in the face of the most sophisticated of attacks coming across the Internet, both today and long into the future.
Cybersecurity for manufacturing
Nobody wants to be in next week's headlines explaining how another dozen plants were taken down by ransomware or other cyber attacks. Neither ransomware nor the most sophisticated of the Internet's attacks can breach Waterfall's Unidirectional Gateways to pose any threat to product quality or to continuous, and correct manufacturing operations,