Machinery RegulationIEC 62443

Reduce the attack surface and the visibility of vulnerabilities

Edge Shield is a smart switch with a network probe and an intrusion detection system inside. Edge Shield protects a network portion by micro-segmenting the communication, while it inspects the traffic for malicious activity.

The Edge Shield models together: compact DIN-rail units, a fanless switch, a desktop switch and a 1U rack unit with a display.
What it does

Three devices in one box

A switch, a network probe and an intrusion detection system.

See

Traffic analysis displays the paths that data takes through the network, and the unexpected traffic. It unveils the communication that business continuity depends on.

Isolate

Every device and application is isolated from the rest of the network. Every packet is identified and validated before it reaches a micro-segment, so each data flow runs on its own path.

Inspect

Edge Shield analyses the traffic to detect attempts to exploit vulnerabilities. Every communication at the edge of the network is monitored, with care to avoid false positives.

Integrate

Physical or digital controls and standard third-party software. Switch security profiles with push buttons or the REST API. Send alerts to industrial signal lights or to your software.

Your network

Protect your network at any layer

Add device visibility and protection without touching the current network configuration. Edge Shield is a standard SDN layer 2 switch, transparent to the current VLANs, IP addressing and routing.

The layers of Edge Shield. Integration: the Edge SDN console and third-party software such as SIEM, SOC, NOC and SOAR. Digital commands: security profiles in and alerts out over REST API and industrial protocols. Physical commands: profiles from push buttons, alerts to signal lights. Analysis: intrusion detection over allowed and blocked IT and OT flows. Monitoring: asset inventory, connections and real-time sessions. Security: micro-segmentation of application flows on an OpenFlow 1.3 SDN switch. Fault tolerance: Ethernet bypass and power redundancy, depending on the model.
Operating profiles

The machine has different states. So does its protection.

In production the machine talks to the MES and to telemetry, and nothing else. During remote maintenance a VPN toward the supplier opens for a limited time.

Each state is a profile with its own allowed flows and its own target Security Level according to IEC 62443. IT designs the profiles. The operator applies them with a button.

Edge Shield sits between the plant network and the machine. Only declared flows pass.PLANT NETWORKMESTelemetrySupplier VPNUnknown hostEdgeShieldPLCHMIGatewayTHE MACHINE— allowed flow- - allowed only in maintenance profile✕ blocked and reported
Old machines

Protect what you cannot patch

A machine installed fifteen years ago may run an operating system that no longer receives updates. Edge Shield closes what it does not need, with a unit sized for one machine.

Read the use case
With the other products

One console, one attack surface

The Edge SDN console manages many Edge Shield units and the rest of the network. Shield Lifecycle uses the profiles as the attack surface of the machine: a blocked path turns a vulnerability into a mitigated one.

Each product also works on its own.

Models

Select the model that fits you

Edge Shield C6

Protect a small number of devices

Form factor
Desktop
Ethernet
6 × 2.5GbE RJ45
Mounting
DIN rail or wall
Security
IP30
Certification
EN 61000-6-2, EN 61000-6-4
Processor
Intel Atom x6413E
Memory
8 GB
Storage
64 GB
Power
9 to 36 V DC, 60 W
Dimensions
100 × 100 × 80 mm
Operating temperature
-20 to 50 °C
Datasheet (PDF)

Edge Shield P16

Protect small networks

Form factor
Desktop
Ethernet
16 × GbE RJ45
Mounting
DIN rail
Security
TPM 2.0
Network bypass
8 pairs
Processor
Intel Atom C3708
Memory
16 GB
Storage
120 GB
Power
12 to 48 V DC terminal block
Dimensions
250 × 240 × 40 mm
Operating temperature
-40 to 65 °C
Datasheet (PDF)

Edge Shield D12

Protect desktop environments

Form factor
Desktop
Ethernet
12 × GbE RJ45, 1 × GbE RJ45, 2 × SFP+ · PoE+ optional
Mounting
Desk or wall
Cooling
System fan
Certification
CE, FCC, LVD
Processor
Intel Atom C3758 or C3558
Memory
16 GB
Storage
128 GB
Power
65 W adapter, 110 to 220 V AC
Dimensions
217 × 168 × 44 mm
Operating temperature
0 to 40 °C
Datasheet (PDF)

Edge Shield M3

Protect large networks

Form factor
Rack 1U
Ethernet
8 to 24 × GbE RJ45, 2 × 10G SFP+
Mounting
Rack mount
Security
TPM 2.0 (optional)
Network bypass
2 segments
Certification
CE, FCC, UL, RCM, CB
Processor
Intel Core i7 (Comet Lake)
Memory
16 GB ECC
Storage
256 GB
Power
2 × 300 W redundant
Dimensions
438 × 508 × 44 mm
Operating temperature
0 to 40 °C
Datasheet (PDF)

Specifications can change. The datasheet of each model has the current version.

For machine builders

Deliver the protection with your machine

  • White labelHardware and software with your brand.
  • Warranty up to 5 yearsExtend hardware and software coverage.
  • 100+ IT and OT applicationsReady to use, plus your own extensions.
Regulations and standards

Where it helps you

  • Built for it
    Machinery RegulationRegulation (EU) 2023/1230

    A connection passes only on declared flows. Traffic analysis and IDS detect malicious attempts and keep a record. Annex III, 1.1.9 and 1.2.1

  • Helps with a part
    Cyber Resilience ActRegulation (EU) 2024/2847

    Reduces the attack surface of the product. Annex I, Part I, 2(j)

  • Helps with a part
    NIS2Directive (EU) 2022/2555

    Isolates machines that cannot be patched; its IDS helps incident handling. Article 21(2)(b), (e)

  • Helps with a part
    IEC 62443Standard series

    Zones and conduits for a single machine, a target Security Level per profile, IDS.

  • Helps with a part
    NIST SP 800-82Guide to OT security

    Segments and watches legacy devices.

  • Helps with a part
    ISO/IEC 27001Standard

    Segregation of single machines, monitoring with the IDS.

  • Helps with a part
    NIST Cybersecurity Framework 2.0Framework

    Protect and Detect for single machines.

FAQ

Questions about Edge Shield

Do I have to change IP addresses, VLANs or the PLC program?

No. Edge Shield works as a layer 2 switch and is transparent to the existing VLANs, IP addressing and routing. You do not touch the configuration of the network or of the machine.

What happens if the Edge Shield fails?

The P16 has 8 pairs of bypass ports and the M3 has bypass on 2 segments, designed to keep traffic flowing if the unit stops. The M3 also has redundant power supplies. Ask us which model fits the availability needs of your line.

Can the machine operator change the security profile?

Yes, in a controlled way. The IT administrator defines the profiles. The operator applies one with a physical push button or a digital one, for example to open remote maintenance for an hour. A REST API is also available, and alerts can drive an industrial signal light.

Do I need the Edge SDN platform to use Edge Shield?

No. Edge Shield can work on its own or together with third-party SDN switches. With the Edge SDN console you manage many units and the whole network from one place.

How does Edge Shield help with old machines?

A machine with an old operating system and open ports often cannot be patched. Edge Shield lets only the declared flows reach it and inspects them. Everything else is blocked. The machine keeps working and its exposure drops.

Can we sell Edge Shield with our own brand?

Yes. Hardware and software can carry your brand, so you deliver the protection with your machine, under your name.

Last updated

Show us the machine. We show you how to protect it.

Tell us which machine or cell you need to protect. We suggest the model, the profiles and the way to install it in a normal maintenance window.

Meet us at 35.BI-MU, fieramilano Rho, 13–16 October 2026