Production networks you can actually see
In many plants nobody knows exactly what is on the network — until something stops. We make your OT network visible and segmented: with Cisco Cyber Vision, straight from the switches, without touching the machines.
- Passive discovery, zero plant risk
- Sensor in the switch, no appliances
- Zones per IEC 62443
- NIS2-ready inventory
Scope
From unknown network to governed zones
The path to an OT environment you know and control — made visible, contained in zones, operated audit-ready.
Asset inventory & communication map
Every PLC, HMI and fieldbus device with vendor, firmware and conversation partners — collected automatically, always current.
Vulnerabilities & risk picture
Known vulnerabilities per component, weighted by exposure and role in the plant — a working list, not a PDF graveyard.
Segmentation per IEC 62443
Zones and conduits derived from the real communication map — enforced with firewalls and Cisco ISE.
Sensor rollout in your estate
Enable Cyber Vision sensors on Catalyst IE switches and routers — no SPAN cabling, no additional appliances.
Hook-up to IT security
Events and asset context flow into ISE, firewall and SIEM — OT incidents land where your security team already works.
Operations & audit readiness
Runbooks, responsibilities and reports for audits: NIS2 reporting duties and 62443 evidence become routine instead of fire drills.
How we work
How we approach it
OT security rarely fails on technology — it fails on touching running plants. So everything starts passive, and every change knows its maintenance window.
Listen passively
Cyber Vision reads along inside the switch; the plant never notices. A complete first inventory stands within a few weeks.
Assess & prioritise
Vulnerabilities, legacy systems and risky connections ranked by impact — together with maintenance and production.
Build the zones
Segmentation in waves: non-critical areas first, then core processes — every rule checked against the real communication map beforehand.
Hand over operations
Alerts, baselines and reporting paths in steady state; your team takes over with runbooks, we stay on call.
In plain language
Why OT networks need their own security
Production networks follow different laws than office IT: availability beats everything, components live for decades, and a reboot costs real money. Put in context by engineers who know both worlds.
Why office-IT recipes fail on the factory floor
In the office the answer is: patch, reboot, replace the device if need be. In production, a controller often runs for ten or twenty years — on software that no longer receives updates, attached to machines that must not simply stop. A virus scanner on a PLC is not an option. OT security therefore works differently: it observes the network instead of touching endpoints, and protects legacy systems by controlling their surroundings — who may talk to whom, and who definitely may not.
How Cyber Vision sees without interfering
Classic OT monitoring needs mirror ports and dedicated collection appliances — effectively a second network just for watching. Cisco takes a different route: the sensor is software inside the network switch itself. Catalyst IE switches and routers observe traffic where it originates, decode more than 180 industrial protocols — from PROFINET and Modbus to OPC UA — and report only compact metadata to the central console. Your plant never notices.
Zones and conduits: segmentation per IEC 62443
IEC 62443 thinks of production networks in zones: areas with similar protection needs, connected through controlled transitions called conduits. It sounds abstract, but it is the most effective defence for the day something goes wrong — a compromised office PC simply must not reach a controller. We derive the zones from the real communication map rather than a whiteboard, and enforce them with firewall rules and Cisco ISE, step by step, without interrupting production.
What NIS2 demands from your production
The EU's NIS2 directive turns cybersecurity into a legal duty for many industrial and utility companies: risk management, a reliable picture of your own systems, reporting significant incidents within 24 hours — with management personally accountable. This is exactly where visibility pays off: an automatically maintained asset inventory and documented zones are the foundation of almost every NIS2 obligation. We build the technical base your evidence stands on.
Tools & platforms
- Cisco Cyber Vision
- Catalyst IE series
- Cisco ISE
- Cisco Secure Firewall
- Splunk / SIEM
- IEC 62443 & NIS2
FAQ
Frequently asked about OT security
Does the analysis disturb running plants?
No. Cyber Vision starts out purely passive: the sensors read along inside the switch and send only metadata to the console. Active discovery — targeted, protocol-conformant queries for extra detail — is only enabled deliberately, agreed with your maintenance team and never during critical process phases.
Do we need new switches for this?
Not necessarily. If Catalyst IE hardware already runs in your production, the sensor is enabled there as software. Elsewhere we start with a few sensor-capable switches at the most important points — often as part of modernisations that are due anyway. A separate collection network with its own appliances is not required.
What about legacy systems that never get updates?
They remain a reality — a fifteen-year-old controller does not become secure, it becomes protected. The tool is segmentation: the zone around the legacy system is drawn so tightly that only the necessary connections remain. Cyber Vision shows beforehand which ones those are — so no rule breaks production.
Does this concretely help with NIS2 or an IEC 62443 audit?
Yes, very directly: the automated asset inventory, the vulnerability overview and documented zones are exactly the evidence auditors ask for first — and they come from the live system instead of last quarter's spreadsheets. The organisational duties, like processes and reporting paths, we build on top of that together.
What role do ISE and the firewall play?
Cyber Vision sees and understands; enforcement happens elsewhere. Asset groups and zones flow into Cisco ISE and the firewall: ISE decides which device may join the network at all and which zone it belongs to, while the firewall controls the transitions between zones. That turns visibility into actual control.
How quickly do we see first results?
The first communication map appears within days of starting the sensors; a reliable inventory after two to four weeks of listening — depending on your plants' cycles. From then on we work with real data instead of assumptions.
Next step
Do you know what is on your OT network?
The first step is visibility — passive, with zero risk to the plant. After that, you decide on facts.
Ask about OT security
