Skip to content
Cyber Security

OT / Industrial & IoT Security

Visibility, segmentation and 24×7 monitoring for plants, grids and utilities - passive asset discovery, IEC 62443 zoning, brokered remote access and a SOC that reads Modbus as fluently as HTTP.

OT / Industrial & IoT Security - Dollu
  • IEC 62443

    Zone-and-conduit model

  • 100%

    Passive discovery

  • 24×7

    OT-aware SOC

Overview

What is OT / Industrial & IoT Security?

Operational technology was built to run for decades in isolation. It now sits on routed networks, talks to cloud analytics platforms and is reachable by vendors over remote-access tools - while still running unpatched Windows HMIs, PLCs with no authentication and protocols such as Modbus, DNP3, PROFINET and IEC 104 that were never designed to be secured. Dollu’s OT / Industrial & IoT Security service brings visibility, segmentation, monitoring and response to plants, substations, water networks, ports and campuses without disrupting the processes they run.

We start with a passive discovery phase. SPAN or TAP feeds from your Purdue level 1–3 switches are analysed by protocol-aware sensors that build a live inventory of every controller, HMI, historian, engineering workstation and IoT gateway, the firmware it runs, who it talks to and over which protocol. Nothing is scanned or polled, so a 20-year-old PLC is never at risk of a watchdog reset. The resulting asset map, communication baseline and vulnerability list, matched against ICS-CERT advisories and vendor bulletins, become the foundation for a zone-and-conduit design aligned to IEC 62443-3-2.

Segmentation is delivered with our managed firewall and SD-WAN portfolio: an industrial DMZ between IT and OT, conduits between cells enforced by next-generation firewalls with DPI for industrial protocols, and unidirectional gateways where regulation demands them. Vendor and engineer access moves off shared VPN accounts and desktop-sharing tools onto a brokered secure remote access service with per-session approval, MFA, session recording and protocol-level command whitelisting. For private 5G, LoRaWAN and Wi-Fi sensor estates we add SIM and certificate-based device identity, private APNs and traffic policy so a compromised sensor cannot pivot toward the control layer.

Ongoing, our SOC monitors the OT baseline 24×7 for new devices, unusual function codes, firmware writes, configuration downloads and lateral movement, with playbooks written jointly with your engineering team so that response never means taking a line offline without a human decision. Reporting maps to IEC 62443, NIST SP 800-82, NIS2, NERC CIP and CEA (India) cyber-security guidelines, and quarterly reviews track remediation of the vulnerability backlog. The service is priced per site or per monitored asset and can be phased from a single pilot line to a multi-country plant estate.

Why Dollu

Why choose Dollu for ot & iot security.

The advantages of buying from a carrier that owns its network, interconnects and operations - rather than a reseller.

  • See every asset before an attacker does

    Most plants discover 30–50% more connected devices than their spreadsheets list. A live, protocol-derived inventory ends the guesswork about what is on the network and what it talks to.

  • Contain without downtime

    Segmentation is designed around the real communication baseline, staged in monitor-only mode and cut over during planned windows, so zoning never breaks a working process.

  • Take vendors off the VPN

    Every OEM and integrator session is approved, time-boxed, recorded and limited to the specific asset and protocol they need - with no standing credentials left on the network.

  • Response that respects the process

    Analysts trained on ICS protocols triage alerts against your playbooks; containment steps such as blocking a conduit are pre-agreed with plant engineering, not improvised at 3 a.m.

  • Audit-ready evidence

    Asset registers, risk assessments, segmentation diagrams and monitoring reports are produced in the structure regulators and insurers expect, cutting weeks from compliance cycles.

Capabilities

Capabilities in detail.

Everything included with OT / Industrial & IoT Security - the platform features, options and controls you get from day one.

  1. 01

    Passive asset discovery and inventory

    Protocol-aware sensors on SPAN/TAP feeds identify vendor, model, firmware, IP/MAC, Purdue level and communication partners for every device; optional safe active queries for assets that never speak unprompted.

  2. 02

    Industrial protocol monitoring

    Deep packet inspection of Modbus/TCP, DNP3, IEC 60870-5-104, IEC 61850 MMS/GOOSE, PROFINET, EtherNet/IP (CIP), S7comm, OPC UA and BACnet, with detection of writes, firmware uploads, mode changes and unauthorised masters.

  3. 03

    OT vulnerability and risk intelligence

    Inventory matched continuously against ICS-CERT advisories, vendor bulletins and known-exploited lists, scored by exposure and process criticality so engineering patches what matters first.

  4. 04

    Zone-and-conduit segmentation

    IEC 62443-3-2 zoning design, industrial DMZ, NGFW conduits with industrial DPI, micro-segmentation for cells and data diodes for one-way historian or safety-system exports.

  5. 05

    Secure remote access broker

    Clientless, browser-based access for staff and vendors with MFA, approval workflow, just-in-time credentials, RDP/SSH/VNC/HTTPS session recording and command-level restrictions per asset.

  6. 06

    Private-5G and IoT device security

    SIM and X.509 device identity, private APN with IPsec backhaul, per-device traffic policy, anomaly detection on sensor flows and quarantine of misbehaving endpoints, integrated with our private-5G and IoT connectivity services.

  7. 07

    OT SOC and incident response

    24×7 monitoring with detections mapped to MITRE ATT&CK for ICS, joint playbooks with plant engineering, on-call OT responders and forensic capture of PCAPs and controller logic for post-incident review.

  8. 08

    Compliance reporting and governance

    Evidence packs and dashboards aligned to IEC 62443, NIST SP 800-82, NIS2, NERC CIP and CEA guidelines; quarterly risk reviews and board-level summaries.

How it works

How it works.

From first conversation to live traffic - a tracked, engineer-led onboarding with a named owner at every step.

  1. Step 01

    Assess

    Site survey with your engineering team, network drawings review, SPAN/TAP placement plan and deployment of hardware or virtual sensors at each Purdue boundary.

  2. Step 02

    Baseline

    Thirty days of passive learning produces the asset inventory, communication map, vulnerability report and a proposed zone-and-conduit design with a risk-ranked remediation plan.

  3. Step 03

    Segment and secure

    Industrial DMZ, conduit firewalls and the remote access broker are staged in monitor mode, validated against the baseline and cut over in planned maintenance windows.

  4. Step 04

    Monitor and respond

    SOC onboarding, playbook sign-off, notification matrix and escalation paths go live; quarterly reviews track new assets, patch progress and changes to the threat picture.

Use cases

Who uses this and why.

Typical deployments across carriers, enterprises, platforms and contact centres.

  • Manufacturing plants

    Discrete and process manufacturers gaining an asset inventory, IT/OT DMZ and controlled OEM access across lines built by different integrators over many years.

  • Power generation and distribution

    Substation and plant monitoring of IEC 61850 and DNP3 traffic, NERC CIP or CEA-aligned reporting and secure access for protection engineers.

  • Water and wastewater utilities

    Distributed pumping and treatment sites monitored centrally over cellular or MPLS, with quarantine of remote RTUs that behave abnormally.

  • Oil, gas and mining

    Segmentation of safety, control and business networks at remote sites, with satellite or private-5G backhaul and unidirectional export of historian data.

  • Ports, airports and rail

    Cranes, baggage systems, signalling and building automation brought under one monitoring baseline with vendor access controlled per system.

  • Smart buildings and campuses

    BACnet, lighting, HVAC, CCTV and access-control networks discovered, segmented from corporate IT and watched for lateral movement.

Specifications

Technical & commercial specifications.

Key parameters at a glance. Ask us for the full service description and SLA document.

DiscoveryPassive via SPAN/TAP; optional safe active queries; no agents
ProtocolsModbus, DNP3, IEC 104, IEC 61850, PROFINET, EtherNet/IP, S7comm, OPC UA, BACnet
SensorsDIN-rail or 1U hardware, virtual appliance; ruggedised -40 to +70 °C option
SegmentationIEC 62443 zones and conduits, industrial DMZ, NGFW with industrial DPI, data diodes
Remote accessClientless broker; MFA, approval workflow, session recording, RDP/SSH/VNC/HTTPS
IoT / private 5GSIM and X.509 identity, private APN, IPsec backhaul, per-device policy
Monitoring24×7 SOC; MITRE ATT&CK for ICS detections; PCAP forensics
FrameworksIEC 62443, NIST SP 800-82, NIS2, NERC CIP, CEA (India) guidelines
CommercialsPer site or per monitored asset; 12–36 month terms; pilot available
Support24×7 NOC/SOC; P1 response ≤ 15 min; named account manager
Pricing model

How Security is priced.

Security services are priced per protected site or circuit, per user or per endpoint - and MDR by endpoint count or log volume. Assessments and penetration tests are fixed-scope projects.

We publish the model, not a public rate card - actual rates depend on destination, route class, volume and regulatory cost. See how every Dollu service is priced.

Monthly recurring · per site, user or endpoint
  • DDoS and managed firewall per protected site or circuit
  • SASE and zero trust per user
  • MDR per endpoint or by log volume
  • Assessments and penetration tests as fixed-scope projects
  • 12–36 month terms on managed services
Billing
Monthly recurring in advance; projects invoiced on milestones
Commitment
12–36 months for managed services; none for assessments
Talk to salesActual rates within one business day.
FAQ

OT & IoT Security - your questions answered.

The questions customers and carriers ask us most often before they interconnect. If yours is not here, our team answers within one business day.

Still have a question?

Ask our solutions team

No. Sensors receive a copy of traffic from a SPAN port or network TAP and never transmit onto the control network. There is no scanning, polling or agent installation by default, so fragile controllers, safety systems and legacy HMIs are unaffected. Where an asset never communicates unprompted, we can agree a limited set of vendor-approved active queries, run only in maintenance windows.

Let’s talk

Start with a passive site assessment.

Tell us the site, the number of controllers you think you have and how vendors currently connect, and we will scope a 30-day passive discovery pilot with a fixed price.

Abstract globe with connected network lines