
OT Network and USB Isolation: effectively protecting critical assets
Mapping is essential. But knowing your assets and detecting threats is not enough to protect them. Once critical systems have been identified, the next step is to isolate them. Not logically, not through software configuration. But physically, through hardware mechanisms that make reconnaissance phases and lateral movement structurally impossible. In this article, we cover the challenges of isolation in OT environments and how to address them with Seclab Xchange, Seclab Xport and Seclab Xlocker (coming soon).
Key takeaways
- Physical isolation is fundamentally different from logical segmentation: a firewall filters flows, an electronic air gap eliminates all direct network connectivity between the two sides.
- The electronic core of Seclab Xchange is immune by design to zero-days and software vulnerabilities: there is no software stack to attack.
- Even if one side of the appliance is compromised, the other remains unreachable: no transport layer can be exploited for lateral movement.
- USB vectors account for a significant share of OT incidents: Xport and Xlocker address this vector through hardware mechanisms, with no installation required on the endpoint.
- Use cases cover the entire industrial perimeter: OT isolation, production lines, legacy systems, third-party interconnections, cyber-resilient backups, and SOC connectivity for critical infrastructure operators.
A reminder: the five-step OT security methodology
Faced with the rising threat to OT environments, regulations and field experience converge on the same sequence:
- inventory assets and network flows,
- reduce the attack surface by removing what is unnecessary,
- identify critical systems and physically isolate them,
- put the infrastructure under continuous monitoring,
- secure backups with physical isolation. The first article in this series covered inventory and mapping with Seclab Xplore. This article addresses the third step: isolation.
The first article in this series covered inventory and mapping with Seclab Xplore. This article addresses the third step: isolation.
Why logical segmentation is no longer enough
Isolation is one of the most effective defensive tools against cyberattacks in OT environments. But not all forms of isolation are equal. Logical segmentation via firewall or VLAN relies on software. And software means vulnerabilities, and vulnerabilities mean time-consuming patch cycles.
In the current context, where AI is compressing the window between vulnerability disclosure and exploitation to a matter of hours, relying on a software-based solution to protect the most critical assets means accepting permanent residual exposure and a continuous patch management race. Fortinet, Palo Alto, and Cisco already rank among the vendors with the most exploited vulnerabilities according to ENISA. Segmentation appliances have themselves become risk vectors.
The answer to this equation cannot be purely software-based. Physical isolation, built on hardware mechanisms, offers a structural guarantee that software alone cannot provide. This is the founding principle of Seclab’s Electronic AirGap technology. Originally deployed in the most critical environments (nuclear power plants, defense…), this mechanism has become essential to ensuring the protection of operational and industrial systems.
Seclab Xchange: air gap delivered through electronics
Seclab Xchange is a network isolation appliance based on a unique concept and patented technology. The electronic air gap concept is a Seclab invention: there is no network between the two sides of the appliance. Electronic mechanisms allow application data to transit from one network to the other, but without any network layer physically connecting the two ends.
Xchange is bidirectional by nature, which sets it apart from network diodes. It supports connection-oriented communications such as TCP, which can be initiated from either side of the appliance without constraint.
An architecture built on three independent electronic boards
The appliance is made up of three distinct components:– A network termination on the IT side
– A central electronic core, acting as an uncrossable barrier between the two ends
– A network termination on the OT side
Only data from explicitly authorized flows can transit through this core. The protocol break principle renders the networks on each side invisible to the other: all reconnaissance phases typically exploited during the preliminary stages of an attack become inoperative.
The direct consequence of this architecture is significant: even if one side of the appliance were to be compromised, the other side would remain unreachable. The electronic core is impervious to attack, making lateral movement and reconnaissance phases impossible. And in the absence of any network, there is no transport layer for an attacker to exploit.
Beyond isolation, Xchange embeds advanced filtering capabilities: file filtering, application layer inspection, and DPI (deep packet inspection). It is notably possible to exchange files between two unconnected networks while applying precise control over content in transit.
The appliance also requires dual administration: to authorize a flow or a file to cross, a separate administrative action must be performed independently on each side of the appliance. Until both actions have been completed, nothing passes. If an administrator were to act maliciously, they would not be able to open a flow unilaterally.
Operational and security maintenance (MCO/MCS) is kept to a minimum. Seclab publishes approximately two updates per year, primarily functional in nature, with no impact on the appliance’s security level. This is a considerable operational advantage in environments where every intervention is planned, costly, and potentially a source of downtime.
Use cases covered by Xchange
Xchange technology covers the full range of isolation scenarios encountered in industrial environments:
- IT/OT isolation: the foundational use case, corresponding to the ICS DMZ in the Purdue model (layer 3.5). Deployed at SNCF to isolate their certified industrial network, which carries signaling and energy management, from their central information system.
- Operational system isolation: protection of production line components (PLCs, controllers, actuators). A concrete example: at a pharmaceutical group, a production line that could not meet the group’s required security level was made completely invisible to the rest of the information system through the deployment of an Xchange appliance at the head of the line.
- Industrial information system administration and supervision: securing exchanges between safety controllers and process controllers, to ensure that the compromise of one cannot lead to the compromise of the other. Deployed with Schneider Electric and Yokogawa.
- Legacy systems: the original use case for Xchange technology. The industrial world contains many systems that can be neither patched, nor updated, nor equipped with security tools. EDF uses it in its nuclear power plants for two distinct purposes: isolating command and control from the rest of the information system, and protecting PLCs during USB media updates.
- Third-party network interconnection: securing exchanges between industrial networks and the networks of external maintainers or partners. Example: TotalEnergies and Natran, for exchanges between compression controllers in liquefied natural gas facilities.
- Backup and cyber resilience: Seclab is working with Dell on an offering designed to secure the last backup tier. Xchange is used for administration of the backup vault and for data exchanges between production sites and that vault.
- SOC interconnection for critical infrastructure operators: for organizations subject to a PDIS SOC requirement, Xchange enables geographically distributed systems of vital importance (SIV) to be connected to a centralized PDIS SOC, with controlled forwarding of the logs, alerts, and information required by the analyst.
Seclab Xport and Xlocker: isolation extended to USB vectors
The network is not the only threat introduction vector in industrial environments. USB ports, ubiquitous on OT equipment, represent a major and frequently under-controlled entry point. Seclab addresses this vector with two complementary products: Xport and Xlocker.
Xport is an appliance the size of an external hard drive that sits between the USB port of a device and the USB media. Its role is to physically protect the port, and therefore the machine, via Electronic AirGap technology. It blocks two categories of attacks:
- USB Killer-type attacks, which exploit an electrical surge to physically destroy the machine.
- Software attacks via HID-spoofing USB devices (Bash USB, Bash Bunny), which simulate a keyboard or execute a malicious script upon connection.
Xport also integrates an integrity verification mechanism based on digital file signing. If an unsigned or malicious element is presented to the appliance, it is absorbed and discarded. If a legitimate file accompanied by its valid signature is presented, it is transmitted to the device. Xport is a universal safeguard against any uncontrolled USB media.
Xlocker (coming soon) addresses a different need: managing a fleet of devices with numerous USB ports, in a simple and traceable way. Born from a requirement expressed by a customer in the defense sector, it replaces blanket prohibition policies with case-by-case exceptions, which generate significant administrative overhead.
The appliance connects to the USB port and blocks access electronically. A user with a badge can unlock access and use the port normally. This provides precise traceability on who accesses the port and in what context. The entire fleet and USB port access rights are centrally managed. The appliance also features a tamper detection mechanism: as soon as a port lock is removed without authorization, an audible alarm is triggered and an alert is sent to the administration console. The whole system operates wirelessly.
To discover Seclab Xchange, Seclab Xport and Seclab Xlocker, watch this excerpt from our June 2026 webinar replay
Learn more about Electronic AirGap
Discover our white paper on Electronic AirGap isolation.
What now?
Physical isolation of critical assets is the step that structurally changes the risk level of an OT environment. It does not eliminate the need to monitor and detect, but it radically reduces the attack surface reachable by an attacker who has already penetrated the IT network.
Seclab Xchange, Seclab Xport and Seclab Xlocker are the isolation building blocks of the Seclab Xcore platform. In the next article in this series, we will cover the following step: detecting anomalous behavior on the industrial network.
