Asset-side OT protection
Industrial Control System Protection
BlackPiQ physically locks an OT control system’s encrypted IPsec tunnel to the industrial controller, eliminating its local network security gap.
Cryptographic Authentication + Physical Enforcement for RJ45/OT Controller’s Ethernet Port
Add quantum-resistant key establishment with ML-KEM

Protected asset
Reachable only through its authorized tunnel
Protected industrial controllers
BlackPiQ locks IPsec tunnels onto Industrial Controllers

PLC
Programmable logic controller
Siemens SIMATIC S7-1200 G2

IED
Intelligent electronic device
SEL-751 protection relay — rear Ethernet port

RTU
Remote terminal unit
Schneider Electric SCADAPack 470

PAC
Programmable automation controller
Emerson PACSystems CPE400 series

DCS
Distributed control system controller
ABB AC 800M
Representative device examples. Photos courtesy of their respective manufacturers; inclusion does not imply endorsement or verified compatibility.
Operational Technology use cases

Oil & Gas
Protect controller access across production, processing, pipeline, and compressor-station operations.

Electric Power
Protect controllers supporting generation, substations, transmission, and distribution.

Water
Protect controllers operating treatment plants, pump stations, distribution, and wastewater systems.

Manufacturing
Protect controllers operating production lines, process equipment, and plant-floor machinery.
BlackPiQ at a glance
High-assurance protection at the controller interface.
BlackPiQ physically locks a standards-based encrypted conduit to an industrial controller, bringing network isolation, trusted access, and continuous accountability directly to the asset edge.
Authorized IPsec conduit
Restricts controller traffic to the approved encrypted tunnel.
Multi-vendor interoperability
Establishes standards-based IPsec with compatible third-party firewalls, VPN gateways, and Ethernet encryptors. The remote endpoint does not need to be another BlackPiQ.
Transparent OT deployment
Protects legacy OT equipment without modifying controller logic or changing the controller’s IP address.
Asset-side isolation
Prevents unauthorized local discovery, direct access, and east-west communication.
Zero-power lock retention
The bi-stable mechanical lock remains engaged if device power is lost.
Powered monitoring and alerting
While powered, BlackPiQ can report authentication failures, link loss, and tamper events to authorized operations.
Optional post-quantum protection
- Standard Mode: Hybrid ML-KEM-768 or ML-KEM-1024 key exchange combines classical and post-quantum cryptography.
- Compatible peers: Both endpoints must support the selected hybrid key-exchange configuration.
- Existing infrastructure: Conventional IKEv2 IPsec remains available for existing security infrastructure.
- FIPS-mode : ML-KEM / ML-DSA
Legacy OT Vulnerabilities
A direct network path can become a direct command path.

A compromised engineering workstation, transient cyber asset, or protocol-capable host can communicate with multiple reachable controllers when device authentication and asset-side isolation are absent.
East-west lateral movement
One compromised host or peer can become a route to other controllers on a shared OT segment.
Exposed controller interface
A reachable Ethernet port can provide a direct path to a critical control asset.
Unprotected last-foot traffic
Upstream segmentation can still leave the final local connection outside the protected conduit.
Interception and command manipulation
A hostile position on the local path may observe, redirect, or alter industrial communications.
East-west lateral movement
Stop lateral movement at the controller interface.
On a shared OT network, a compromised controller may attempt to discover and communicate directly with other reachable controllers.BlackPiQ places an authenticated IPsec boundary at each controller interface, blocking unauthorized direct peer communication.
Legacy OT segment
One compromised controller can manipulate its local peers.
Without asset-side enforcement, controllers on the same reachable network may communicate directly through the shared Ethernet switch.
BlackPiQ-protected segment
Each controller receives its own authenticated boundary.
Each BlackPiQ establishes its own encrypted path through the shared switch to an authorized IPsec peer serving the OT control system. Direct controller-to-controller communication is blocked.
Asset-side enforcement: each protected controller becomes its own authenticated boundary on the shared OT network.
The BlackPiQ fusion point
BlackPiQ brings the encrypted IPsec tunnel to the controller and locks it in place.
Active physical barrier
Strict access control
Intelligent tamper response
Secures RJ45 connectors with a tamper-reactive electronic lock that uses cryptographic multi-factor authentication to restrict access.

Bump-in-the-wire architecture
Carry the encrypted IPsec conduit to the controller.
BlackPiQ extends standards-based IPsec protection directly to the industrial controller’s Ethernet interface without modifying controller logic or changing its IP address.

Authorized OT control system ↔ compatible IPsec gateway ↔ encrypted IPsec tunnel ↔BlackPiQ ↔ industrial controller.
Supported IPsec modes
BlackPiQ supports both standard IPsec operating modes.
Transport mode
Encrypts the packet payload while retaining the original IP header.
Tunnel mode
Encrypts the entire original packet inside a new IP packet.
Standards-based IPsec interoperability
Connect BlackPiQ to compatible security infrastructure.
BlackPiQ uses standards-based IKEv2 IPsec, so the central OT IPsec gateway can be a compatible enterprise firewall, VPN gateway, or Ethernet encryptor; it does not have to be another BlackPiQ.
Standards-based cryptography
Built for IPsec interoperability.
BlackPiQ uses IKEv2 and standards-defined IPsec cryptography to establish authenticated, encrypted connections with compatible third-party firewalls, VPN gateways, and Ethernet encryptors.
Standard Mode — Encryption & Integrity
Authenticated encryption: AES-256-GCM or ChaCha20-Poly1305.
Hash functions: SHA-256, SHA-384 and SHA-512.
FIPS Mode — Encryption & Integrity
Encryption: AES-256-CBC.
Integrity: HMAC-SHA-256, HMAC-SHA-384 or HMAC-SHA-512.
Standard Mode — Key Exchange & Authentication
Key exchange: Curve25519, Curve448, NIST P-384 and NIST P-521.
Authentication: ECDSA with NIST P-384 or P-521; RSA-3072 or RSA-4096.
Optional hybrid post-quantum key exchange: ML-KEM-768 or ML-KEM-1024, with PPK fallback.
FIPS Mode — Key Exchange & Authentication
Key exchange: NIST P-384 and NIST P-521.
Authentication: ECDSA with NIST P-384 or P-521; RSA-3072 or RSA-4096.
Post-quantum roadmap: ML-KEM / ML-DSA through a future firmware upgrade, subject to vendor availability and applicable validation. No release date is published.
Supported IPsec features: IKEv2 with tunnel and transport modes.
Interoperability requires a shared configuration profile. Both endpoints must support and enable compatible IKEv2/IPsec proposals. Hybrid post-quantum key exchange requires a compatible peer.

Optional post-quantum protection
Extend post-quantum protection to the controller interface.
BlackPiQ extends encrypted communications to legacy OT assets while securing the physical controller connection, without modifying the asset’s underlying logic. Standard Mode offers optional hybrid post-quantum key establishment.
- Hybrid key establishment: ML-KEM-768 or ML-KEM-1024 combines with classical key exchange to establish IPsec session keys.
- Compatible peers: Both endpoints must support and enable the selected hybrid key-exchange configuration.
- Existing infrastructure: Conventional IKEv2 IPsec remains available for compatible firewalls, VPN gateways, and Ethernet encryptors.
- FIPS-mode roadmap: ML-KEM / ML-DSA support is planned through a future firmware upgrade, subject to vendor availability and applicable validation. No release date is published.
Device management and AAA
Control who can administer BlackPiQ.
BlackPiQ applies Authentication, Authorization, and Accounting to access to its device-management interface. These controls govern who can view device status, change configuration, and administer users; they are separate from the industrial traffic passing through the protected interface.
Authentication
Verify an authorized administrator before granting access to the BlackPiQ management interface.
Authorization
Map centralized privilege levels to BlackPiQ device-management roles.
Accounting
Associate management logins, administrative commands, and configuration activity with an authenticated identity.
BlackPiQ can use TACACS+ or RADIUS as the primary authentication service for login to its management interface. Optional local fallback can preserve administrative access if the remote service is unavailable, while centralized privilege information maps authenticated users to BlackPiQ device roles.
BlackPiQ management interface
Configure and monitor the protected interface from one console.
The browser-based management interface provides visibility into BlackPiQ device health, IPsec tunnel status, Ethernet interfaces, security state, active management sessions, and reported events.
TOTP authentication
One-time codes
Short-lived verification codes from an enrolled authenticator app.
Certificate authentication
Certificate-based identity
Client certificates establish identity through a configured trust chain.
CAC / PIV authentication
Smart-card identity
A workstation reader and middleware enable card-backed certificate authentication.
Authorization and roles
Permissions reflect administrative responsibility.
BlackPiQ provides two administrative roles: Admin for device administration and Super for device and user administration.

Monitoring and accountability
Turn device health, access, and physical state into actionable events.
While powered, BlackPiQ can monitor its protected connection, record security-relevant activity, and send configured notifications to authorized operations.
Device health
Monitor BlackPiQ availability, operating state, and reported faults.
Link status
Detect changes affecting the secure uplink or protected asset connection.
Security events
Report authentication, configuration, lock-state, and tamper conditions supported by the device’s configured monitoring profile.
SNMPv3 monitoring and traps
Send device and security events to authorized OT monitoring.
BlackPiQ can send SNMPv3 traps to configured network-management or security-monitoring systems. When authentication and privacy are enabled, SNMPv3 protects event reporting between BlackPiQ and the monitoring destination.
Administrators define SNMPv3 users, security settings, and trap targets through the management interface. The on-device trap log shows notification history for operational review and troubleshooting.
Trap targets are configured in the BlackPiQ management interface, while notification history remains available for operational review.
Live tamper response
Detect interference while it is happening.
A powered BlackPiQ combines mechanical locking with electronic tamper sensing to detect attempts to remove, disconnect, or bypass the protected controller interface. A confirmed event can trigger key sanitization, live notification, and a configured response.

Cryptographic security
Hardware-rooted protection for keys and secure sessions.
BlackPiQ incorporates a cryptographic module validated to FIPS 140-3 Overall Level 2 under CMVP Certificate #5109, with Physical Security Level 3.
Cryptographic Module

Cryptographic assurance
Built on a FIPS 140-3 validated module
BlackPiQ incorporates the a cryptographic module, validated to FIPS 140-3 Overall Level 2 under CMVP Certificate #5109, with Physical Security Level 3.
The validation applies to the module when installed, configured, and operated in its approved mode as specified in its Security Policy. It does not represent validation of the complete BlackPiQ product.
Hardware root of trust
Hardware protection for cryptographic keys
The TPM provides a dedicated hardware boundary for TPM-managed keys and supported cryptographic operations, helping protect sensitive material from general-purpose software.
Standard Mode offers the broader algorithm selection described above.FIPS Mode uses a restricted cryptographic profile aligned with the module’s approved capabilities and configuration requirements.

Technical specifications
Compact hardware. Industrial deployment.
Designed for space-constrained cabinets and extreme operating environments.

Asset interface
- 10/100 Base-T Ethernet
- Locking RJ45: Ramp & Clamp
Secure uplink
- 10/100 Base-T Ethernet
Power
- 24V DC: female power input
- PoE: 802.3af Class 2 (alternative power source)
Cryptography
- IPsec: IKEv2; tunnel and transport modes.
- Standard Mode encryption: AES-256-GCM or ChaCha20-Poly1305.
- Standard Mode hash functions: SHA-256, SHA-384 and SHA-512.
- Standard Mode key exchange: Curve25519, Curve448, NIST P-384 and NIST P-521.
- FIPS Mode encryption and integrity: AES-256-CBC with HMAC-SHA-256, HMAC-SHA-384 or HMAC-SHA-512.
- FIPS Mode key exchange: NIST P-384 and NIST P-521.
- Authentication — both modes: ECDSA with NIST P-384 or P-521; RSA-3072 or RSA-4096.
- Optional post-quantum — Standard Mode: Hybrid ML-KEM-768 or ML-KEM-1024 key exchange, with PPK fallback. Requires compatible peer configuration.
- FIPS-mode post-quantum roadmap: ML-KEM / ML-DSA
Management
- Hardened browser interface
- MFA: multi-factor authentication
- RBAC: role-based access control
- TACACS+ / RADIUS: centralized device authentication
- SNMPv3: monitoring and notifications
Operating range
- −40°C to +85°C
Dimensions
- 2.2 in × 1 in × 1.5 in
Protect the asset edge
Bring high-assurance protection to the controller interface.
Discuss BlackPiQ fit, deployment architecture, and interoperability with Engage Black.









