Asset-side OT protection
Industrial Control System Protection
BlackPiQ physically locks an OT control system’s encrypted IPsec tunnel to the industrial controller, eliminating its local network security gap.
Cryptographic Authentication + Physical Enforcement for RJ45/OT Controller’s Ethernet Port
Add quantum-resistant key establishment with ML-KEM

Protected asset
Reachable only through its authorized tunnel
Protected industrial controllers
BlackPiQ locks IPsec tunnels onto Industrial Controllers

PLC
Programmable logic controller
Siemens SIMATIC S7-1200 G2

IED
Intelligent electronic device
SEL-751 protection relay — rear Ethernet port

RTU
Remote terminal unit
Schneider Electric SCADAPack 470

PAC
Programmable automation controller
Emerson PACSystems CPE400 series

DCS
Distributed control system controller
ABB AC 800M
Representative device examples. Photos courtesy of their respective manufacturers; inclusion does not imply endorsement or verified compatibility.
Operational Technology use cases

Oil & Gas
Protect controller access across production, processing, pipeline, and compressor-station operations.

Electric Power
Protect controllers supporting generation, substations, transmission, and distribution.

Water
Protect controllers operating treatment plants, pump stations, distribution, and wastewater systems.

Manufacturing
Protect controllers operating production lines, process equipment, and plant-floor machinery.
BlackPiQ at a glance
High-assurance protection at the controller interface.
BlackPiQ physically locks a standards-based encrypted conduit to an industrial controller, bringing network isolation, trusted access, and continuous accountability directly to the asset edge.
Authorized IPsec conduit
Restricts controller traffic to the approved encrypted tunnel.
Multi-vendor interoperability
Establishes standards-based IPsec with compatible third-party firewalls, VPN gateways, and Ethernet encryptors. The remote endpoint does not need to be another BlackPiQ.
Transparent OT deployment
Protects legacy OT equipment without modifying controller logic or changing the controller’s IP address.
Asset-side isolation
Prevents unauthorized local discovery, direct access, and east-west communication.
Zero-power lock retention
The bi-stable mechanical lock remains engaged if device power is lost.
Powered monitoring and alerting
While powered, BlackPiQ can report authentication failures, link loss, and tamper events to authorized operations.
Optional post-quantum protection
- Hybrid key establishment: BlackPiQ combines classical cryptography with ML-KEM to strengthen IPsec connections against future quantum threats.
- Compatible peers: Post-quantum protection requires a compatible peer.
- Existing infrastructure: Conventional IKEv2 IPsec remains available for existing security infrastructure.
Legacy OT Vulnerabilities
A direct network path can become a direct command path.

A compromised engineering workstation, transient cyber asset, or protocol-capable host can communicate with multiple reachable controllers when device authentication and asset-side isolation are absent.
East-west lateral movement
One compromised host or peer can become a route to other controllers on a shared OT segment.
Exposed controller interface
A reachable Ethernet port can provide a direct path to a critical control asset.
Unprotected last-foot traffic
Upstream segmentation can still leave the final local connection outside the protected conduit.
Interception and command manipulation
A hostile position on the local path may observe, redirect, or alter industrial communications.
East-west lateral movement
Stop lateral movement at the controller interface.
On a shared OT network, a compromised controller may attempt to discover and communicate directly with other reachable controllers.BlackPiQ places an authenticated IPsec boundary at each controller interface, blocking unauthorized direct peer communication.
Legacy OT segment
One compromised controller can manipulate its local peers.
Without asset-side enforcement, controllers on the same reachable network may communicate directly through the shared Ethernet switch.
BlackPiQ-protected segment
Each controller receives its own authenticated boundary.
Each BlackPiQ establishes its own encrypted path through the shared switch to an authorized IPsec peer serving the OT control system. Direct controller-to-controller communication is blocked.
Asset-side enforcement: each protected controller becomes its own authenticated boundary on the shared OT network.
The BlackPiQ fusion point
BlackPiQ brings the encrypted IPsec tunnel to the controller and locks it in place.
Active physical barrier
Strict access control
Intelligent tamper response
Secures RJ45 connectors with a tamper-reactive electronic lock that uses cryptographic multi-factor authentication to restrict access.

Bump-in-the-wire architecture
Carry the encrypted IPsec conduit to the controller.
BlackPiQ extends standards-based IPsec protection directly to the industrial controller’s Ethernet interface without modifying controller logic or changing its IP address.

Authorized OT control system ↔ compatible IPsec gateway ↔ encrypted IPsec tunnel ↔BlackPiQ ↔ industrial controller.
Supported IPsec modes
BlackPiQ supports both standard IPsec operating modes.
Transport mode
Encrypts the packet payload while retaining the original IP header.
Tunnel mode
Encrypts the entire original packet inside a new IP packet.
Standards-based IPsec interoperability
Connect BlackPiQ to compatible security infrastructure.
BlackPiQ uses standards-based IKEv2 IPsec, so the central OT IPsec gateway can be a compatible enterprise firewall, VPN gateway, or Ethernet encryptor; it does not have to be another BlackPiQ.
Standards-based cryptography
Built for IPsec interoperability.
BlackPiQ uses IKEv2 and standards-defined IPsec cryptography to establish authenticated, encrypted connections with compatible third-party firewalls, VPN gateways, and Ethernet encryptors.
AES-256-GCM
Provides authenticated encryption for IPsec traffic, protecting both confidentiality and packet integrity.
HMAC-SHA-256
Supports IKEv2 key derivation and authenticated negotiation using a standardized pseudorandom function.
Standard key exchange
Supports Curve25519, NIST P-256, P-384 and P-521, plus MODP 2048, 3072 and 4096, allowing deployments to select a profile supported by the remote IPsec peer.
Optional post-quantum key exchange
ML-KEM-512, ML-KEM-768 or ML-KEM-1024 can supplement classical key exchange when the remote peer supports the same IKEv2 extension.
Interoperability requires a shared configuration profile. Both endpoints must support and enable at least one compatible IKEv2/IPsec proposal.

Optional post-quantum protection
Extend post-quantum protection to the controller interface.
BlackPiQ bridges legacy OT assets to quantum-resistant communications by securing the physical controller connection and orchestrating encrypted traffic without modifying the asset’s underlying logic.
- Hardware-ready migration: An optional quantum-resistant layer can use ML-KEM for key establishment and LMS for digital signatures.
- Outer tunnel: Conventional IKEv2 IPsec with AES-256-GCM preserves interoperability and supports existing electronic security perimeter designs.
- Inner tunnel: An isolated quantum-resistant IPsec conduit protects traffic to the OT asset within a tunnel-within-a-tunnel architecture.
The layered design follows the architectural principle used by NSA CSfC solutions. Formal CSfC validation requires approved components and registration of the complete solution.
Device management and AAA
Control who can administer BlackPiQ.
BlackPiQ applies Authentication, Authorization, and Accounting to access to its device-management interface. These controls govern who can view device status, change configuration, and administer users; they are separate from the industrial traffic passing through the protected interface.
Authentication
Verify an authorized administrator before granting access to the BlackPiQ management interface.
Authorization
Map centralized privilege levels to BlackPiQ device-management roles.
Accounting
Associate management logins, administrative commands, and configuration activity with an authenticated identity.
BlackPiQ can use TACACS+ or RADIUS as the primary authentication service for login to its management interface. Optional local fallback can preserve administrative access if the remote service is unavailable, while centralized privilege information maps authenticated users to BlackPiQ device roles.
BlackPiQ management interface
Configure and monitor the protected interface from one console.
The browser-based management interface provides visibility into BlackPiQ device health, IPsec tunnel status, Ethernet interfaces, security state, active management sessions, and reported events.
TOTP authentication
One-time codes
Short-lived verification codes from an enrolled authenticator app.
Certificate authentication
Certificate-based identity
Client certificates establish identity through a configured trust chain.
CAC / PIV authentication
Smart-card identity
A workstation reader and middleware enable card-backed certificate authentication.
Authorization and roles
Permissions reflect administrative responsibility.
BlackPiQ provides two administrative roles: Admin for device administration and Super for device and user administration.

Monitoring and accountability
Turn device health, access, and physical state into actionable events.
While powered, BlackPiQ can monitor its protected connection, record security-relevant activity, and send configured notifications to authorized operations.
Device health
Monitor BlackPiQ availability, operating state, and reported faults.
Link status
Detect changes affecting the secure uplink or protected asset connection.
Security events
Report authentication, configuration, lock-state, and tamper conditions supported by the device’s configured monitoring profile.
SNMPv3 monitoring and traps
Send device and security events to authorized OT monitoring.
BlackPiQ can send SNMPv3 traps to configured network-management or security-monitoring systems. When authentication and privacy are enabled, SNMPv3 protects event reporting between BlackPiQ and the monitoring destination.
Administrators define SNMPv3 users, security settings, and trap targets through the management interface. The on-device trap log shows notification history for operational review and troubleshooting.
Trap targets are configured in the BlackPiQ management interface, while notification history remains available for operational review.
Live tamper response
Detect interference while it is happening.
A powered BlackPiQ combines mechanical locking with electronic tamper sensing to detect attempts to remove, disconnect, or bypass the protected controller interface. A confirmed event can trigger key sanitization, live notification, and a configured response.

Cryptographic security
Hardware-rooted protection for keys and secure sessions.
Beyond controlling who can reach the controller, BlackPiQ protects the cryptographic material used for authentication, secure management, and the encrypted IPsec conduit.
Secure Cryptographic Coprocessor

Cryptographic assurance
Security grounded in certified cryptographic technology.
BlackPiQ uses a secure cryptographic coprocessor designed to provide hardware-rooted assurance for sensitive keys and cryptographic operations. Its underlying security foundation brings independently evaluated protections directly to the industrial controller boundary.
Hardware root of trust
Keys stay inside a hardware-protected boundary.
The Trusted Platform Module isolates stored key material and sensitive cryptographic operations from general-purpose software. Authentication credentials and the keys used by secure management and encrypted sessions remain protected within that boundary.

Technical specifications
Compact hardware. Industrial deployment.
Designed for space-constrained cabinets and extreme operating environments.

Asset interface
- 10/100 Base-T Ethernet
- Locking RJ45: Ramp & Clamp
Secure uplink
- 10/100 Base-T Ethernet
Power
- 24V DC: female power input
- PoE: 802.3af Class 2 (alternative power source)
Cryptography
- IKEv2 IPsec
- AES-256-GCM
- Optional post-quantum protection: ML-KEM for key establishment and LMS for digital signatures.
Management
- Hardened browser interface
- MFA: multi-factor authentication
- RBAC: role-based access control
- TACACS+ / RADIUS: centralized device authentication
- SNMPv3: monitoring and notifications
Operating range
- −40°C to +85°C
Dimensions
- 2.2 in × 1 in × 1.5 in
Protect the asset edge
Bring high-assurance protection to the controller interface.
Discuss BlackPiQ fit, deployment architecture, and interoperability with Engage Black.









