SOLUTION BRIEF
Converged Network; TCP/IP Serial
and Analog Security Monitoring for
Industrial Control Systems
Extend visibility, situational awareness, and
threat detection across operational technologies
Cynalytica is critical in some
with Nozomi Networks and Cynalytica. of our largest accounts who
Organizations operating industrial control systems (ICS) are challenged rely on serial communications
with monitoring a diverse set of legacy and modern technologies. alongside Ethernet TCP/IP in
Adding to this complexity, security risks are increasing as both the their operational networks. Our
frequency and sophistication of cyberattacks on these OT systems combined visibility and threat
accelerate. While Nozomi Networks has developed a leading solution for detection—including intrusion
TCP/IP-based network traffic and threats, more is often required for non- detection via the AnalytICS
IP based serial bus and analog connections found in ICS environments Engine—ensures that all
which are essential for field-level connectivity and legacy systems. potential threats are captured
and simplifies remediation
For this reason, Cynalytica and Nozomi Networks have partnered
to introduce a solution for visibility and security monitoring of both efforts through our platform
Ethernet and non-IP systems. The joint solution’s key benefits are integrations. Cynalytica
effectiveness, deployment flexibility, and scalability, across all equipment providing both on-prem and
within a rapidly changing OT environment. The solution ensures SaaS serves as a fantastic
real-time visibility and anomaly detection that provides actionable fit with Nozomi Networks’
information to respond to incoming threats, no matter what class of flexibility of Guardian and
system is involved. Vantage platforms.
Chet Namboodri
SVP of Business Development,
Nozomi Networks
SOLUTION BRIEF
Converged Network; TCP/IP Serial and Analog Security Monitoring for Industrial Control Systems 1
Simplifying the Challenge of Addressing Security
Across Dynamic OT Environments with Both Legacy
and Modernized Technologies
Converged The convergence of IT and OT technologies and the explosion of IoT devices within the OT
Monitoring of environment pose an unprecedented risk for organizations to monitor from a central location,
Ethernet-based and including increased attack surface and lack of full visibility and control. The joint solution
Serial-based Systems allows for organizations to gain visibility and threat detection into Ethernet, analog and serial
communications that OT equipment runs on. The identified findings are aggregated into the
Nozomi Networks Central Management Console (CMC) or the Vantage SaaS-based security
platform and the Cynalytica AnalytICS Engine.
The combined visibility across network environments can simplify threat detection, monitoring
and remediation efforts, while ensuring a complete view across all assets.
Sample OT
Deployment – VANTAGE VANTAGE IQ
Nozomi Networks
and Cynalytica Level 5 Corporate
Workstations
Corporate
Server
Firewall SIEM SOC
Enterprise IT Networks
and Data Centers
Level 4 DNS, AV, DC, LOCAL NOZOMI AnalytICS
Historian, Patch NETWORKS CMC Site IT Site IT
Site IT Networks Engine User
Remote Access Optional Servers Workstations
Servers Platform
Level 3 and 3.5
Firewall
Site Operations Control and GUARDIAN Site Production
DMZ Switches
Control Systems
ICS-Demilitarized Zone (DMZ) Core Switches
Level 2 Line Operator
/ Engineering
Line Operator Supervisory
/ Engineering Workstations
Area Supervisory Control Workstations Workstations
Line REMOTE Line Line
GUARDIAN GUARDIAN
Switches COLLECTOR Switches Switches
Building
Level 1 PLCS / DCSs PLCS / RTUs Controllers
Control Network / NVRS
OTNetGuard
(Analog Module) SerialGuard
Level 0
Sensors Field IoT Devices
Field Network / Actuators Equipment
Line #1 Remote Line #2 Security Network
Sample Deployment Architecture for Substations SOC
SOLUTION BRIEF
Converged Network; TCP/IP Serial and Analog Security Monitoring for Industrial Control Systems 2
Converged Security Monitoring Across an
Unlimited Number of Facilities and Systems from a
Central Location
Anomaly Detection Nozomi Networks and Cynalytica improve operational resilience by monitoring process
and Corroboration variables sent between OT devices and alerting on any anomalous activity. The joint solution
of Process Variable can monitor process variables between Ethernet-based devices as well as analog and serial-
Values based controllers to identify when variables such as setpoints and flowrates shown to operators
do not match the commands being issued to running equipment.
The joint solution also flags when process variables deviate from normal ranges or if the process
values change unexpectedly, all of which can cause operational issues and be indicators of an
ongoing OT security incident or equipment malfunction.
Flexible and Scalable The joint solution is designed to deploy into all forms of OT environments and monitor an
On-Premises unlimited number of sensors, devices, and facilities. Nozomi Networks Guardian sensors can be
Monitoring with deployed as appliances, VMs or container applications to monitor Ethernet traffic in network
Centralized Alerts switches. Cynalytica OTNetGuardian and SerialGuard devices can be deployed where systems
use analog and serial communications for operations, and all sensor management and alerts
are consolidated into a single dashboard. Management can be from a corporate office, SOC
or in the cloud, giving organizations a scalable and flexible way to monitor all facilities and OT
equipment.
Let’s Get Started Schedule a demo with our experts to understand Book a Demo
how Nozomi Networks and Cynalytica can provide
nozominetworks.com/demo
full visibility and security monitoring for your
Ethernet and Legacy systems.
Nozomi Networks accelerates digital transformation by protecting the world’s critical infrastructure,
industrial and government organizations from cyber threats. Our solution delivers exceptional network
and asset visibility, threat detection, and insights for OT and IoT environments. Customers rely on us to
minimize risk and complexity while maximizing operational resilience.
© 2023 Nozomi
SOLUTION BRIEF Networks, Inc. | All Rights Reserved. nozominetworks.com
Converged Network; TCP/IP Serial and Analog Security Monitoring for Industrial Control Systems 3
NN-Cynalytica-SB-8.5x11-001