NIS2IEC 62443

Segment the OT network on the switches you already have

Edge SDN finds what is exposed in your IT and OT network and protects it. Micro-segmentation of devices and communication, with no IP change, no VLAN change and no new firewall.

The Edge SDN console on a monitor: switches, hosts, deployed profiles, security events and the security level of two zones over time.
A single Central Management Console can manage multiple sites

Seeing is not enough. Edge SDN finds the security issues and protects you from them.

How it works

A security cycle that runs every day

Each step feeds the next. The longer it runs, the more accurate it gets.

  1. Probe

    Discover

    OT-safe scanning for asset inventory and passive probe for traffic analysis and IDS.

  2. Console

    Assessment

    A complete overview of the vulnerabilities, with a full risk analysis and a detailed view of communications between networks and to the Internet.

  3. Console

    Protection design

    Security zones, conduits and profiles for production, maintenance and backup, each with its risk.

  4. Your switches

    Enforce

    Micro-segmentation applied on the switches you already have.

  5. 24/7

    Monitor

    Current risk against residual risk, timeline and alerts. Information for your SOC.

  6. Reports

    Prove

    Reports and statistics that keep the evidence of how you manage security. NIS2, IEC 62443, NIST CSF, NIST SP 800-82.

Enforce, our difference

Protection on the network you already have

  • No IP changeEvery device keeps its address.
  • No VLAN changeThe network design stays as it is.
  • No new firewallSegmentation runs on the switches.
  • Your switchesCisco, Aruba, HPE, Allied Telesis, OpenFlow 1.3, Edge Shield.

Through OpenFlow, NETCONF/YANG, REST API or CLI over SSH. More switch vendors are coming.

IT designs, OT decides

Network segmentation changes with a click

Profiles enable or disable network segmentation, internet communications, maintenance, protection of end-of-life devices, IEC 62443 security zones and conduits.

A tablet shows four network profiles: Emergency, Local maintenance, MES connection (active) and Remote maintenance, with an Apply profiles button.
Authorised users can adjust the network's visibility level, from fully open to segmented and secured, based on operational needs.
Without Edge SDN
  • A ticket to IT to open the firewall
  • Hours or days of waiting
  • Rules often too wide
  • Rules left open afterwards
  • No audit trail
With Edge SDN
  • OT activates "Maintenance L2" from a tablet
  • Only Line 2 opens, at once
  • Precise rules, designed in advance
  • Off again with one tap
  • Full log with user and time
Edge Probe

One hardware, two probes

Installed in your plant, rack 1U. The software makes it Standard or Advanced.

Edge Probe, a black 1U rack unit with a console port, two USB ports and eight Ethernet ports ETH0 to ETH7.
Standard
Rack 1U · one per rack
  • Passive traffic analysis
  • Communication between security zones
  • IDS with IT and OT rules
Advanced
Rack 1U · one per network
  • Everything in Standard
  • Active, OT-safe asset inventory
  • Vulnerabilities with CVE, CVSS and KEV
Prove

Keep the evidence for your audits

Edge SDN keeps the reports and statistics that document how you manage security: asset inventory, vulnerabilities, communication matrix, IDS events, risk before and after segmentation, and the history of every profile.

The reports support your audit. They do not replace it.

The Edge SDN console, Create Report: the documents to include, grouped as overview (executive summary, system security plan, IEC 62443 and NIS2 mapping, NIST CSF 2.0 profile) and architecture and network (asset inventory, communication matrix, process definition).
Regulations and standards

Where it helps you

  • Built for it
    NIS2Directive (EU) 2022/2555

    Segmentation and access control; asset inventory and vulnerability scanning with the Advanced probe; IDS for incident handling; NIS2 reports as evidence. Article 21(2)(a), (b), (e), (i)

  • Built for it
    IEC 62443Standard series

    Plant-wide zones and conduits, restricted data flow, monitoring, asset inventory with the Advanced probe; IEC 62443 reports as evidence.

  • Built for it
    NIST SP 800-82Guide to OT security

    Defense in depth and segmentation, OT asset inventory and monitoring.

  • Built for it
    ISO/IEC 27001Standard

    Network security and segregation; inventory and technical vulnerabilities with the Advanced probe; monitoring.

  • Built for it
    NIST Cybersecurity Framework 2.0Framework

    Identify with the Advanced probe, Protect, Detect.

FAQ

Questions about Edge SDN

Do I have to replace my switches?

No. Edge SDN applies micro-segmentation on Cisco, Aruba, HPE and Allied Telesis switches, on any SDN switch compatible with OpenFlow 1.3 and on Edge Shield units. More vendors are coming.

Will segmentation stop my production?

No. Every activity is planned, authorised and supervised. The segmentation runs on the existing switches, so IP addresses and VLANs stay as they are.

Can it run without an internet connection?

Yes. The console runs on-premises, on two virtual machines. Updates can come through an internal staging server, with no outbound connection.

What happens if the console goes offline?

The switches keep the segmentation that was applied. A break-glass procedure restores communication in an emergency.

Can Edge SDN feed our SOC?

Yes. Alerts, events and network information reach your SOC or SIEM through Syslog and REST API.

Who uses it, IT or OT?

Both. IT designs the zones and the profiles. OT activates a prepared profile from a tablet, when production needs it.

Last updated

See your OT network as it really is

In a first call we look at your network, the switches you have and the zones you need. You leave with a first outline of the zones and the next steps.

Meet us at 35.BI-MU, fieramilano Rho, 13–16 October 2026