
Data Diode Alternatives for Critical OT Environments
Data diodes have long been the default choice for isolating critical OT networks. Unidirectional by design, they physically guarantee that no traffic can enter the protected network from the exposed one. On paper, that is reassuring.
In the field, reality is more nuanced. Many OT use cases require bidirectional communication: SCADA system administration, file synchronization between zones, industrial protocols that rely on acknowledgments. This is where data diodes reach their structural limits. For more than ten years, Seclab has been developing a hardware-based isolation approach designed for these constraints, which works in both unidirectional and bidirectional modes. This article reviews the alternatives for OT network isolation, the criteria for choosing between them and how well they fit operational realities.
Key takeaways: data diode alternatives for OT
- Data diodes physically guarantee one-way traffic: that is their strength for feeding a SOC or a historian, and their limit as soon as bidirectional exchanges are needed.
- OT firewalls allow bidirectional traffic, but remain connected software components, exposed to zero-days and demanding in terms of updates.
- Hardware-based protocol break isolation removes all network connectivity between zones and lets only application data through.
- Seclab Xchange applies this principle in unidirectional (diode mode) or bidirectional mode, depending on the requirements of each environment.
- The right choice depends on the required flow direction, acceptable latency and tolerable maintenance workload.
What is a data diode and why is it used in OT?
A data diode (also called a network diode or unidirectional gateway) is a hardware device that enforces a strictly one-way transfer of information between two networks. This one-way flow is guaranteed by physics, usually through a link with no return path, rather than by software configuration. The NIST SP 800-82 Rev. 3 guide to OT security lists unidirectional gateways among the means of segmenting industrial networks.
In OT environments, diodes are used to send monitoring data (logs, SCADA metrics) to a SOC or a historian without opening a return channel. The nuclear, defense and energy sectors have deployed them for years for this reason.
The device addresses a specific need: one-way data flows. Constraints appear as soon as a use case requires protocol acknowledgments, bidirectional synchronization or remote administration of OT assets.
What are the limits of data diodes in industrial environments?
The first limit is structural. Industrial protocols such as Modbus TCP, OPC UA or S7comm rely on a request-response model that a diode cannot carry directly. Diode vendors work around this through replication: proxies poll the devices on the OT side and rebuild mirror servers (OPC, historian) on the IT side. This works for reading data, but it allows neither writing to devices nor acknowledging a command. To simulate bidirectional exchanges, some deployments combine two diodes in opposite directions with synchronization gateways, at the cost of higher latency and complex integration.
The second limit concerns application compatibility. These proxies and synchronization agents are additional software components: they widen the attack surface and increase the OT maintenance workload. For teams that are already stretched thin, every added component is one more operational risk.
Finally, content control depends on the functions added around the diode. Some offerings include file inspection or sanitization (CDR), while others only handle the transfer. The level of protocol filtering and file verification therefore varies widely from one product to another and needs to be assessed case by case.
Which criteria should you use to evaluate a data diode alternative?
Five operational criteria shape the choice of an OT network isolation solution:
- Flow direction: is one-way enough, or is bidirectional traffic required, today and tomorrow?
- Latency: what transit delay is acceptable for control and safety processes?
- Protocol break: does the solution really cut the TCP/IP stack between the two zones?
- Maintenance effort: how many updates per year does the device require?
- Legacy compatibility: does deployment require architecture changes to existing assets?
OT firewalls: a partial alternative to data diodes
Industrial firewalls provide configurable bidirectional network filtering. That is their main advantage over diodes. Filtering rules can be tailored to OT protocols (Modbus, EtherNet/IP, Profinet) and application compatibility is high.
A firewall nevertheless remains a software component connected to the network. A Seclab study of five OT firewall vendors puts the maintenance workload at 2 to 10 security patches per month. In OT environments, applying these patches requires maintenance windows that are rarely available.
A firewall compromised through one of its interfaces gives access to the different zones it separates. Its protection depends on the quality and constant updating of its rules, not on structural physical isolation.
Unidirectional gateways and hybrid solutions
Several approaches try to combine the diode principle with extended capabilities. Unidirectional gateways with built-in proxies can export files or SCADA data streams while keeping communication strictly one-way.
Hybrid solutions (dual diodes with a synchronization gateway) aim to simulate bidirectional communication. The trade-off lies in latency and complexity: each additional layer adds transit delay and another component to maintain. At PG&E, a US gas and electricity provider, this type of architecture pushed gas leak detection time beyond two minutes, which was deemed incompatible with safety requirements. In the same context, Electronic AirGap brings latency down to 2 to 4 milliseconds (see the PG&E case study).
Hardware protocol break isolation: how Electronic AirGap works
Electronic AirGap, a technology patented by Seclab, is based on a different principle. Rather than filtering traffic or restricting its direction, it terminates OSI layers 1 to 4 on each side: no TCP/IP stack and no network packet crosses the system. Only useful application data passes through, over a non-routable electronic bus.
The architecture relies on three independent processors, each dedicated to a distinct security function. Filtering is based on dual validation: two independent access controls, one at the input and one at the output, each hold half of the policy and are administered separately. A flow only passes if both allow it. The attack surface is therefore reduced by design, not by configuration.
Seclab Xchange, the appliance that embeds this technology, supports throughput of up to 1.2 Gbps with no additional software component on the network side. Files can be filtered in transit (extension, size, MIME type, signatures). Maintenance is limited to one software update per year on average.
The Electronic AirGap technology has been awarded CSPN certification by ANSSI, the French National Cybersecurity Agency, in version 3.4.0. The evaluation covered, among other things, the protocol break, compartmentalization, handling of malformed inputs and firmware signing. During the evaluation, evaluators were even given administrator rights on one of the access controls, without being able to get through the electronic isolation. Designed and assembled in France, it is a European alternative to the data diodes offered by US and Israeli vendors.
Unidirectional or bidirectional: Xchange adapts to your environment
– Unidirectional mode (diode mode): for flows that must remain strictly one-way (sending logs to a SOC, feeding a historian, transmitting metrics), Xchange operates in diode mode. Only useful data passes, in a single direction, with no possible return path.
– Bidirectional mode: for use cases that require an exchange (device administration, file synchronization, protocols with acknowledgments), the same appliance allows controlled bidirectional flows, at up to 1.2 Gbps.
In both cases, the same certified technology provides application filtering, file verification and dual validation of flows. An environment that starts in unidirectional mode can move to bidirectional without changing equipment.
Comparison of OT network isolation approaches
| Criterion | Electronic AirGap (Seclab Xchange) | Data diode | OT firewall |
|---|---|---|---|
| Communication direction | Unidirectional (diode mode) or bidirectional, as needed | Unidirectional (bidirectional simulated with dual diodes) | Bidirectional |
| One-way flow guaranteed by physics | Enforced by the architecture and the dual filtering policy | Yes (link with no return path) | No |
| Network connectivity between zones | None: layers 1 to 4 terminated on each side | None: protocols terminated by proxies on each side | Yes (filtered routing) |
| Resilience to compromise of its own components | High (3 compartmentalized processors, dual access control) | High for flow direction; proxies need securing | Low: possible access to the different zones |
| Latency | A few milliseconds | Low in one-way mode, high with dual diodes | Low |
| Maintenance effort | Very low (1 update per year on average) | Low for the diode, moderate for the proxies | High (2 to 10 patches per month*) |
| Application compatibility | High | Low to medium (replication via proxies) | High |
| File filtering and verification | Built in (extension, MIME type, signatures, application protocol filtering) | Varies by offering (inspection, CDR) | Varies by module |
| Dual-validation administration | Yes: each flow validated on two independent access controls | No | No |
* Seclab study of five OT firewall vendors.
What OT managers should assess before choosing
The choice of an isolation solution depends on the nature of the flows to protect. For strictly one-way data transfers to a SOC or a historian, a data diode remains a sound option. Xchange also covers this need in diode mode, adding filtering of application protocols such as Modbus, file verification and the ability to open bidirectional flows later without changing equipment.
As soon as flows become bidirectional (administration, file synchronization, protocols with acknowledgments), the diode reaches its limits. Hardware protocol break isolation covers these cases without bringing software components back into the isolation perimeter.
Regulatory compliance is also part of the equation. IEC 62443 organizes OT security into zones and conduits, each with a target security level (SL-T, from 1 to 4). Positioned as a conduit between a critical zone and an at-risk zone, Electronic AirGap helps achieve SL-T 3 or 4, the levels designed to counter intentional attacks carried out with sophisticated means. Under NIS2, Article 21 of the directive requires proportionate risk management measures. Requirements for network segmentation and compartmentalization are detailed in implementing texts: Implementing Regulation (EU) 2024/2690 for digital service providers and, in France, ANSSI’s ReCyF framework.
How can network isolation fit into a step-by-step approach?
Trying to protect everything at the same level is a dead end, and you cannot protect what you do not know. The most structured approach is to first identify the assets that are vital to production continuity, what Seclab calls the MVDI (Minimum Viable Digital Industry), and then focus physical isolation on that critical perimeter.
The Seclab Xcore platform organizes this progression into three phases: Discover (mapping assets and flows with Seclab Xplore), Isolate (physical isolation of critical assets with Seclab Xchange) and Detect (detecting anomalies and attacks in non-isolated zones). For details on each step, read our articles on OT mapping and on network and USB isolation.
This sequence fits the risk-based approach of NIS2 and IEC 62443, which favor a gradual increase in maturity tailored to each organization’s constraints.
What’s next?
Data diodes remain a benchmark for physically guaranteeing one-way traffic. For bidirectional use cases, they reach limits that gateways and firewalls can only overcome through trade-offs in latency, maintenance or attack surface.
Hardware protocol break isolation provides an architectural answer to both situations. Seclab Xchange operates in unidirectional mode when the environment requires it, or in bidirectional mode when operations call for it, with maintenance limited to one update per year on average.
The right approach: first identify the vital perimeter, then choose the isolation mode that fits your actual flows.
Want to go further? Download our white paper on OT network isolation or talk to a Seclab expert.
FAQ: data diode alternatives for critical OT
What is the difference between a data diode and Electronic AirGap?
A data diode uses physics to guarantee strictly one-way traffic. Seclab’s Electronic AirGap removes all network connectivity between zones through an electronic protocol break, and can operate in unidirectional mode (diode mode) as well as in bidirectional mode.
Can an OT firewall replace a data diode?
An OT firewall filters traffic according to configurable rules, but does not remove network connectivity between two zones. The TCP/IP stack remains active on both sides, leaving an attack surface that can be exploited, notably through zero-days.
Firewalls and diodes address different needs and are not interchangeable.
Why does hardware-based security matter in OT cybersecurity?
Segmentation technologies are often built from software components, which are inherently vulnerable. Keeping them effective requires frequent updates, and the required update frequency is likely to increase further with the rise of AI. Yet in OT, maintenance windows are rare. Hardware-based protection limits the maintenance effort that cybersecurity requires.
How do you choose between a data diode and a protocol break?
The main criterion is the required flow direction. For one-way data transfers (logs to a SOC), a diode meets the need. So does Xchange, in diode mode, with application filtering and file verification on top. As soon as bidirectional exchanges are needed (remote administration, file synchronization, protocols with acknowledgments), Xchange supports them without changing equipment.
Does OT network isolation help with NIS2 and IEC 62443 compliance?
Yes. IEC 62443 organizes OT security into zones and conduits, with target security levels (SL-T 1 to 4). Positioned as a conduit between zones, Electronic AirGap helps achieve SL-T 3 or 4.
NIS2 (Article 21) requires proportionate risk management; network segmentation is detailed in implementing texts, such as the ReCyF framework in France.
Sources
• NIST, SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security – https://csrc.nist.gov/pubs/sp/800/82/r3/final (September 2023)
• ANSSI, Certificate ANSSI-CSPN-2021/20, Secure Xchange Network (Sec-XN) version 3.4.0 – https://messervices.cyber.gouv.fr/visas/ANSSI-CSPN-2021-20-certificat.pdf (September 2021)
• Seclab, Increase Safety and Security of Gas Leak Detection Process at PG&E – https://www.seclab-security.com/en/2026/03/24/increase-safety-and-security-of-gaz-leak-detection-process-at-pge/
• Seclab, OT Network Segmentation with Physical Isolation (Seclab Xchange) – https://www.seclab-security.com/en/physical-network-isolation-ot/
• Official Journal of the EU, Directive (EU) 2022/2555 (NIS2) – https://eur-lex.europa.eu/eli/dir/2022/2555/oj (December 2022)
• Official Journal of the EU, Implementing Regulation (EU) 2024/2690 – https://eur-lex.europa.eu/eli/reg_impl/2024/2690/oj (October 2024)
