OT / Industrial & IoT Security
Visibility, segmentation and 24×7 monitoring for plants, grids and utilities - passive asset discovery, IEC 62443 zoning, brokered remote access and a SOC that reads Modbus as fluently as HTTP.

IEC 62443
Zone-and-conduit model
100%
Passive discovery
24×7
OT-aware SOC
What is OT / Industrial & IoT Security?
Operational technology was built to run for decades in isolation. It now sits on routed networks, talks to cloud analytics platforms and is reachable by vendors over remote-access tools - while still running unpatched Windows HMIs, PLCs with no authentication and protocols such as Modbus, DNP3, PROFINET and IEC 104 that were never designed to be secured. Dollu’s OT / Industrial & IoT Security service brings visibility, segmentation, monitoring and response to plants, substations, water networks, ports and campuses without disrupting the processes they run.
We start with a passive discovery phase. SPAN or TAP feeds from your Purdue level 1–3 switches are analysed by protocol-aware sensors that build a live inventory of every controller, HMI, historian, engineering workstation and IoT gateway, the firmware it runs, who it talks to and over which protocol. Nothing is scanned or polled, so a 20-year-old PLC is never at risk of a watchdog reset. The resulting asset map, communication baseline and vulnerability list, matched against ICS-CERT advisories and vendor bulletins, become the foundation for a zone-and-conduit design aligned to IEC 62443-3-2.
Segmentation is delivered with our managed firewall and SD-WAN portfolio: an industrial DMZ between IT and OT, conduits between cells enforced by next-generation firewalls with DPI for industrial protocols, and unidirectional gateways where regulation demands them. Vendor and engineer access moves off shared VPN accounts and desktop-sharing tools onto a brokered secure remote access service with per-session approval, MFA, session recording and protocol-level command whitelisting. For private 5G, LoRaWAN and Wi-Fi sensor estates we add SIM and certificate-based device identity, private APNs and traffic policy so a compromised sensor cannot pivot toward the control layer.
Ongoing, our SOC monitors the OT baseline 24×7 for new devices, unusual function codes, firmware writes, configuration downloads and lateral movement, with playbooks written jointly with your engineering team so that response never means taking a line offline without a human decision. Reporting maps to IEC 62443, NIST SP 800-82, NIS2, NERC CIP and CEA (India) cyber-security guidelines, and quarterly reviews track remediation of the vulnerability backlog. The service is priced per site or per monitored asset and can be phased from a single pilot line to a multi-country plant estate.
Why choose Dollu for ot & iot security.
The advantages of buying from a carrier that owns its network, interconnects and operations - rather than a reseller.
See every asset before an attacker does
Most plants discover 30–50% more connected devices than their spreadsheets list. A live, protocol-derived inventory ends the guesswork about what is on the network and what it talks to.
Contain without downtime
Segmentation is designed around the real communication baseline, staged in monitor-only mode and cut over during planned windows, so zoning never breaks a working process.
Take vendors off the VPN
Every OEM and integrator session is approved, time-boxed, recorded and limited to the specific asset and protocol they need - with no standing credentials left on the network.
Response that respects the process
Analysts trained on ICS protocols triage alerts against your playbooks; containment steps such as blocking a conduit are pre-agreed with plant engineering, not improvised at 3 a.m.
Audit-ready evidence
Asset registers, risk assessments, segmentation diagrams and monitoring reports are produced in the structure regulators and insurers expect, cutting weeks from compliance cycles.
Capabilities in detail.
Everything included with OT / Industrial & IoT Security - the platform features, options and controls you get from day one.
- 01
Passive asset discovery and inventory
Protocol-aware sensors on SPAN/TAP feeds identify vendor, model, firmware, IP/MAC, Purdue level and communication partners for every device; optional safe active queries for assets that never speak unprompted.
- 02
Industrial protocol monitoring
Deep packet inspection of Modbus/TCP, DNP3, IEC 60870-5-104, IEC 61850 MMS/GOOSE, PROFINET, EtherNet/IP (CIP), S7comm, OPC UA and BACnet, with detection of writes, firmware uploads, mode changes and unauthorised masters.
- 03
OT vulnerability and risk intelligence
Inventory matched continuously against ICS-CERT advisories, vendor bulletins and known-exploited lists, scored by exposure and process criticality so engineering patches what matters first.
- 04
Zone-and-conduit segmentation
IEC 62443-3-2 zoning design, industrial DMZ, NGFW conduits with industrial DPI, micro-segmentation for cells and data diodes for one-way historian or safety-system exports.
- 05
Secure remote access broker
Clientless, browser-based access for staff and vendors with MFA, approval workflow, just-in-time credentials, RDP/SSH/VNC/HTTPS session recording and command-level restrictions per asset.
- 06
Private-5G and IoT device security
SIM and X.509 device identity, private APN with IPsec backhaul, per-device traffic policy, anomaly detection on sensor flows and quarantine of misbehaving endpoints, integrated with our private-5G and IoT connectivity services.
- 07
OT SOC and incident response
24×7 monitoring with detections mapped to MITRE ATT&CK for ICS, joint playbooks with plant engineering, on-call OT responders and forensic capture of PCAPs and controller logic for post-incident review.
- 08
Compliance reporting and governance
Evidence packs and dashboards aligned to IEC 62443, NIST SP 800-82, NIS2, NERC CIP and CEA guidelines; quarterly risk reviews and board-level summaries.
How it works.
From first conversation to live traffic - a tracked, engineer-led onboarding with a named owner at every step.
- Step 01
Assess
Site survey with your engineering team, network drawings review, SPAN/TAP placement plan and deployment of hardware or virtual sensors at each Purdue boundary.
- Step 02
Baseline
Thirty days of passive learning produces the asset inventory, communication map, vulnerability report and a proposed zone-and-conduit design with a risk-ranked remediation plan.
- Step 03
Segment and secure
Industrial DMZ, conduit firewalls and the remote access broker are staged in monitor mode, validated against the baseline and cut over in planned maintenance windows.
- Step 04
Monitor and respond
SOC onboarding, playbook sign-off, notification matrix and escalation paths go live; quarterly reviews track new assets, patch progress and changes to the threat picture.
Who uses this and why.
Typical deployments across carriers, enterprises, platforms and contact centres.
Manufacturing plants
Discrete and process manufacturers gaining an asset inventory, IT/OT DMZ and controlled OEM access across lines built by different integrators over many years.
Power generation and distribution
Substation and plant monitoring of IEC 61850 and DNP3 traffic, NERC CIP or CEA-aligned reporting and secure access for protection engineers.
Water and wastewater utilities
Distributed pumping and treatment sites monitored centrally over cellular or MPLS, with quarantine of remote RTUs that behave abnormally.
Oil, gas and mining
Segmentation of safety, control and business networks at remote sites, with satellite or private-5G backhaul and unidirectional export of historian data.
Ports, airports and rail
Cranes, baggage systems, signalling and building automation brought under one monitoring baseline with vendor access controlled per system.
Smart buildings and campuses
BACnet, lighting, HVAC, CCTV and access-control networks discovered, segmented from corporate IT and watched for lateral movement.
Technical & commercial specifications.
Key parameters at a glance. Ask us for the full service description and SLA document.
| Discovery | Passive via SPAN/TAP; optional safe active queries; no agents |
|---|---|
| Protocols | Modbus, DNP3, IEC 104, IEC 61850, PROFINET, EtherNet/IP, S7comm, OPC UA, BACnet |
| Sensors | DIN-rail or 1U hardware, virtual appliance; ruggedised -40 to +70 °C option |
| Segmentation | IEC 62443 zones and conduits, industrial DMZ, NGFW with industrial DPI, data diodes |
| Remote access | Clientless broker; MFA, approval workflow, session recording, RDP/SSH/VNC/HTTPS |
| IoT / private 5G | SIM and X.509 identity, private APN, IPsec backhaul, per-device policy |
| Monitoring | 24×7 SOC; MITRE ATT&CK for ICS detections; PCAP forensics |
| Frameworks | IEC 62443, NIST SP 800-82, NIS2, NERC CIP, CEA (India) guidelines |
| Commercials | Per site or per monitored asset; 12–36 month terms; pilot available |
| Support | 24×7 NOC/SOC; P1 response ≤ 15 min; named account manager |
How Security is priced.
Security services are priced per protected site or circuit, per user or per endpoint - and MDR by endpoint count or log volume. Assessments and penetration tests are fixed-scope projects.
We publish the model, not a public rate card - actual rates depend on destination, route class, volume and regulatory cost. See how every Dollu service is priced.
- DDoS and managed firewall per protected site or circuit
- SASE and zero trust per user
- MDR per endpoint or by log volume
- Assessments and penetration tests as fixed-scope projects
- 12–36 month terms on managed services
- Billing
- Monthly recurring in advance; projects invoiced on milestones
- Commitment
- 12–36 months for managed services; none for assessments
OT & IoT Security - your questions answered.
The questions customers and carriers ask us most often before they interconnect. If yours is not here, our team answers within one business day.
Still have a question?
Ask our solutions teamRelated services.
Services customers commonly combine with OT / Industrial & IoT Security.
Start with a passive site assessment.
Tell us the site, the number of controllers you think you have and how vendors currently connect, and we will scope a 30-day passive discovery pilot with a fixed price.
