01 / TENSION02 / MANDATE03 / RISKS04 / PLATFORM05 / SCENARIOS06 / COMPLIANCE07 / VALIDATION08 / DEPLOY09 / CONTACT
Energy & OT Environments · Critical Infrastructure

Extending the principle of isolation -
without sacrificing it.

Modern energy and OT operations need more than one-way data flow. They need RDP to SCADA, SSH to production systems, real-time APIs across segmented zones - under unified identity and policy. truePass Gravity makes that possible, while preserving every architectural principle these environments are built on.

Trusted

Where trust is non-negotiable.

Aligned with NIST 800-82 · IEC 62443 · NERC CIP
Cooperation with Israel National Energy Lab (ICNL)
Deployed in national-critical environments
01 The operational shift

The diode isn't the problem. The operational reality is.

For decades, OT environments operated under one assumption: physical isolation with one-way data flow. For that world, data diodes were - and still are - the right tool. They enforce unidirectional communication with hardware-level guarantees that no software can match.

But modern energy, control, and industrial systems require something diodes were never designed to deliver: interactive application connectivity. RDP sessions to SCADA consoles. SSH to production servers. Real-time API integrations. Controlled vendor access. When operations push for these capabilities, organizations either layer multiple complementary products around the diode - increasing attack surface and operational complexity - or staff find "creative" workarounds that bypass security entirely.

The challenge is no longer whether the diode itself is secure. The challenge is what happens around it.
02 An honest framework

Not every environment needs to change. Here's how to know.

truePass Gravity isn't a replacement for every data diode deployment. It's a different architectural choice for a different operational need.

Keep your data diode

If your scenario is genuinely one-way.

  • One-way data replication is sufficient
  • Only Historian, Syslog, or UDP file copy required
  • No need for interactive sessions (RDP, SSH, Web)
  • No identity-aware policy at the boundary
  • Vendor access handled outside the diode path
Diodes deliver hardware-level isolation for genuinely one-way scenarios. Don't replace what works.
Consider truePass Gravity

If your operations need interactive connectivity.

  • Operations need RDP to SCADA / HMI consoles
  • SSH access to production servers required
  • Web applications and APIs span isolated zones
  • Vendor access requires per-user identity, MFA, audit
  • Compliance demands per-request policy and unified audit
  • Multiple point products around the diode are unmanageable
Gravity extends the isolation principle to interactive scenarios - under one Zero Trust policy.
03 What's breaking today

The operational gap shows up in four places.

When organizations push diodes beyond what they were designed for, these are the pain points that emerge - every time.

/ 01

No interactive application connectivity

The modern need to connect APIs, web services, and continuous data synchronization is not natively supported in one-way models. This limits operational capability - and often forces operators to find workarounds that bypass the very isolation the diode was meant to enforce.

/ 02

Growing architectural complexity

Bridging the gap means layering complementary products: proxy servers, dedicated communication components, embedded TCP connectors. The result is a distributed architecture that makes unified security policy management nearly impossible.

/ 03

Bidirectional communication challenges

Any scenario involving recurring interaction between systems - vendor maintenance, API responses, application acknowledgments - requires additional solutions on top of the diode. Each addition creates operational complexity and policy consistency gaps.

/ 04

No identity context at the access layer

Traditional separation mechanisms are infrastructure-level, not identity-level. They cannot enforce dynamic policy based on who the user is, what device they're on, or the context of their action. This is the foundation Zero Trust is built on - and it's missing.

05 Real operational scenarios

What modern Energy & OT teams can finally do.

Remote monitoring & maintenance of SCADA/ICS

Operators access HMI consoles and engineering workstations via RDP - from anywhere - under per-session MFA, clipboard controls, and full session recording. No VPN tunnels into OT. No exposed RDP gateways.

Controlled vendor & integrator access

Equipment vendors and system integrators access specific assets for time-limited, scoped maintenance windows. Per-user identity, MFA, and audit - without giving network-level access to the OT zone.

Real-time OT-to-IT data synchronization

Production data, historian replication, and API integrations between OT and IT zones operate under unified policy with full audit trail. Interactive where needed, one-way where appropriate.

Cross-zone file transfer with content control

Files moving between IT, DMZ, and OT zones pass through CDR sanitization, identity verification, and policy enforcement. Engineering files, configuration updates, operational documents - all controlled.

06 Regulatory alignment

Built to the standards your auditors expect.

truePass Gravity's architecture supports compliance with the frameworks governing Energy & OT environments worldwide.

NIST SP 800-82
Industrial Control Systems Security
IEC 62443
Industrial Automation & Control Systems
NERC CIP
Critical Infrastructure Protection (Electric)
NIST SP 800-207
Zero Trust Architecture

Per-request policy enforcement, unified audit trail, and identity-aware access - the architectural building blocks regulators require, delivered out of the box.

07 Technical validation

Validated where it matters most.

TerraZone is engaged in cooperation with the Israel National Energy, Control & Cyber Laboratory (ICNL) - a national research framework focused on advancing cybersecurity architectures for critical energy and control environments.

The collaboration explores secure connectivity architectures beyond traditional unidirectional models, validates interactive application access scenarios (SCADA, API, RDP) in isolated environments, and analyzes operational continuity under advanced threat scenarios - including Nation-State and APT actors.

ICNL Cooperation Topics
  • Advanced connectivity architectures for ICS/OT environments
  • Application access validation in isolated environments (SCADA, API, RDP)
  • Operational continuity under APT & Nation-State threat scenarios
  • Micro-segmentation & Zero Trust against breach propagation
  • SIEM/SOC integration for real-time anomaly detection
08 Time to value

No infrastructure changes. No firewall rule rewrites.

01

Architecture review

1–2 daysOur architects map your current OT environment, identify connectivity requirements, and define the right deployment topology.

02

Policy setup

DaysPolicy configuration with no changes to existing firewall rules. Native integration with Active Directory, Kerberos, NTLM, and existing SIEM/SOC.

03

Phased rollout

Weeks, not monthsSide-by-side operation alongside existing systems. Pilot, validate, expand. Production-ready quickly - with full rollback at every stage.

Bring modern connectivity

to your OT environment.

A 30-minute consultation with our security architects who specialize in Energy & OT. We'll review your current architecture, identify where Gravity extends your existing isolation strategy, and propose a tailored Proof of Concept.

Current-architecture review
Tailored Proof of Concept
No new inbound exposure
Talk to an architect

I agree to receive marketing communications from TerraZone ltd by email, SMS, WhatsApp and other electronic channels, in accordance with the Privacy Policy. I may unsubscribe at any time.