Asset-side OT protection

Industrial Control System Protection

BlackPiQ physically locks an OT control system’s encrypted IPsec tunnel to the industrial controller, eliminating its local network security gap.

Cryptographic Authentication + Physical Enforcement for RJ45/OT Controller’s Ethernet Port

Add quantum-resistant key establishment with ML-KEM

BlackPiQ with a 24V DC female power input secured to an industrial controller Ethernet interface

Protected asset

Reachable only through its authorized tunnel

Protected industrial controllers

BlackPiQ locks IPsec tunnels onto Industrial Controllers

Siemens SIMATIC S7-1200 G2

PLC

Programmable logic controller

Siemens SIMATIC S7-1200 G2

SEL-751 protection relay — rear Ethernet port

IED

Intelligent electronic device

SEL-751 protection relay — rear Ethernet port

Schneider Electric SCADAPack 470

RTU

Remote terminal unit

Schneider Electric SCADAPack 470

Emerson PACSystems CPE400 series

PAC

Programmable automation controller

Emerson PACSystems CPE400 series

ABB AC 800M

DCS

Distributed control system controller

ABB AC 800M

Representative device examples. Photos courtesy of their respective manufacturers; inclusion does not imply endorsement or verified compatibility.

Operational Technology use cases

Oil & Gas operational technology environment

Oil & Gas

Protect controller access across production, processing, pipeline, and compressor-station operations.

Electric Power operational technology environment

Electric Power

Protect controllers supporting generation, substations, transmission, and distribution.

Water operational technology environment

Water

Protect controllers operating treatment plants, pump stations, distribution, and wastewater systems.

Manufacturing operational technology environment

Manufacturing

Protect controllers operating production lines, process equipment, and plant-floor machinery.

BlackPiQ at a glance

High-assurance protection at the controller interface.

BlackPiQ physically locks a standards-based encrypted conduit to an industrial controller, bringing network isolation, trusted access, and continuous accountability directly to the asset edge.

Authorized IPsec conduit

Restricts controller traffic to the approved encrypted tunnel.

Multi-vendor interoperability

Establishes standards-based IPsec with compatible third-party firewalls, VPN gateways, and Ethernet encryptors. The remote endpoint does not need to be another BlackPiQ.

Transparent OT deployment

Protects legacy OT equipment without modifying controller logic or changing the controller’s IP address.

Asset-side isolation

Prevents unauthorized local discovery, direct access, and east-west communication.

Zero-power lock retention

The bi-stable mechanical lock remains engaged if device power is lost.

Powered monitoring and alerting

While powered, BlackPiQ can report authentication failures, link loss, and tamper events to authorized operations.

Optional post-quantum protection

  • Hybrid key establishment: BlackPiQ combines classical cryptography with ML-KEM to strengthen IPsec connections against future quantum threats.
  • Compatible peers: Post-quantum protection requires a compatible peer.
  • Existing infrastructure: Conventional IKEv2 IPsec remains available for existing security infrastructure.

Legacy OT Vulnerabilities

A direct network path can become a direct command path.

Protocol-capable host with callouts showing exposed controller interfaces, unprotected last-foot traffic, command interception or manipulation, and east-west lateral movement

A compromised engineering workstation, transient cyber asset, or protocol-capable host can communicate with multiple reachable controllers when device authentication and asset-side isolation are absent.

East-west lateral movement

One compromised host or peer can become a route to other controllers on a shared OT segment.

Exposed controller interface

A reachable Ethernet port can provide a direct path to a critical control asset.

Unprotected last-foot traffic

Upstream segmentation can still leave the final local connection outside the protected conduit.

Interception and command manipulation

A hostile position on the local path may observe, redirect, or alter industrial communications.

East-west lateral movement

Stop lateral movement at the controller interface.

On a shared OT network, a compromised controller may attempt to discover and communicate directly with other reachable controllers.BlackPiQ places an authenticated IPsec boundary at each controller interface, blocking unauthorized direct peer communication.

Legacy OT segment

One compromised controller can manipulate its local peers.

Without asset-side enforcement, controllers on the same reachable network may communicate directly through the shared Ethernet switch.

BlackPiQ-protected segment

Each controller receives its own authenticated boundary.

Each BlackPiQ establishes its own encrypted path through the shared switch to an authorized IPsec peer serving the OT control system. Direct controller-to-controller communication is blocked.

Asset-side enforcement: each protected controller becomes its own authenticated boundary on the shared OT network.

The BlackPiQ fusion point

BlackPiQ brings the encrypted IPsec tunnel to the controller and locks it in place.

Active physical barrier

Strict access control

Intelligent tamper response

Secures RJ45 connectors with a tamper-reactive electronic lock that uses cryptographic multi-factor authentication to restrict access.

Cutaway of the motor-driven RJ45 locking mechanism

Bump-in-the-wire architecture

Carry the encrypted IPsec conduit to the controller.

BlackPiQ extends standards-based IPsec protection directly to the industrial controller’s Ethernet interface without modifying controller logic or changing its IP address.

IPsec tunnel from OT control systems through a compatible IPsec gateway and BlackPiQ to an industrial controller

Authorized OT control system ↔ compatible IPsec gateway ↔ encrypted IPsec tunnel ↔BlackPiQ ↔ industrial controller.

BlackPiQ supports both standard IPsec operating modes.

Transport mode

Encrypts the packet payload while retaining the original IP header.

Tunnel mode

Encrypts the entire original packet inside a new IP packet.

Standards-based IPsec interoperability

Connect BlackPiQ to compatible security infrastructure.

BlackPiQ uses standards-based IKEv2 IPsec, so the central OT IPsec gateway can be a compatible enterprise firewall, VPN gateway, or Ethernet encryptor; it does not have to be another BlackPiQ.

Standards-based cryptography

Built for IPsec interoperability.

BlackPiQ uses IKEv2 and standards-defined IPsec cryptography to establish authenticated, encrypted connections with compatible third-party firewalls, VPN gateways, and Ethernet encryptors.

AES-256-GCM

Provides authenticated encryption for IPsec traffic, protecting both confidentiality and packet integrity.

HMAC-SHA-256

Supports IKEv2 key derivation and authenticated negotiation using a standardized pseudorandom function.

Standard key exchange

Supports Curve25519, NIST P-256, P-384 and P-521, plus MODP 2048, 3072 and 4096, allowing deployments to select a profile supported by the remote IPsec peer.

Optional post-quantum key exchange

ML-KEM-512, ML-KEM-768 or ML-KEM-1024 can supplement classical key exchange when the remote peer supports the same IKEv2 extension.

Interoperability requires a shared configuration profile. Both endpoints must support and enable at least one compatible IKEv2/IPsec proposal.

OT control system connected to a 24V-powered BlackPiQ and protected controller through conventional IPsec with an optional inner quantum-resistant conduit

Optional post-quantum protection

Extend post-quantum protection to the controller interface.

BlackPiQ bridges legacy OT assets to quantum-resistant communications by securing the physical controller connection and orchestrating encrypted traffic without modifying the asset’s underlying logic.

  • Hardware-ready migration: An optional quantum-resistant layer can use ML-KEM for key establishment and LMS for digital signatures.
  • Outer tunnel: Conventional IKEv2 IPsec with AES-256-GCM preserves interoperability and supports existing electronic security perimeter designs.
  • Inner tunnel: An isolated quantum-resistant IPsec conduit protects traffic to the OT asset within a tunnel-within-a-tunnel architecture.

The layered design follows the architectural principle used by NSA CSfC solutions. Formal CSfC validation requires approved components and registration of the complete solution.

Device management and AAA

Control who can administer BlackPiQ.

BlackPiQ applies Authentication, Authorization, and Accounting to access to its device-management interface. These controls govern who can view device status, change configuration, and administer users; they are separate from the industrial traffic passing through the protected interface.

Authentication

Verify an authorized administrator before granting access to the BlackPiQ management interface.

Authorization

Map centralized privilege levels to BlackPiQ device-management roles.

Accounting

Associate management logins, administrative commands, and configuration activity with an authenticated identity.

BlackPiQ can use TACACS+ or RADIUS as the primary authentication service for login to its management interface. Optional local fallback can preserve administrative access if the remote service is unavailable, while centralized privilege information maps authenticated users to BlackPiQ device roles.

BlackPiQ management interface

Configure and monitor the protected interface from one console.

The browser-based management interface provides visibility into BlackPiQ device health, IPsec tunnel status, Ethernet interfaces, security state, active management sessions, and reported events.

TOTP authentication

One-time codes

Short-lived verification codes from an enrolled authenticator app.

Certificate authentication

Certificate-based identity

Client certificates establish identity through a configured trust chain.

CAC / PIV authentication

Smart-card identity

A workstation reader and middleware enable card-backed certificate authentication.

Authorization and roles

Permissions reflect administrative responsibility.

BlackPiQ provides two administrative roles: Admin for device administration and Super for device and user administration.

BlackPiQ Admin role for device administration and Super role for device and user administration

Monitoring and accountability

Turn device health, access, and physical state into actionable events.

While powered, BlackPiQ can monitor its protected connection, record security-relevant activity, and send configured notifications to authorized operations.

Device health

Monitor BlackPiQ availability, operating state, and reported faults.

Link status

Detect changes affecting the secure uplink or protected asset connection.

Security events

Report authentication, configuration, lock-state, and tamper conditions supported by the device’s configured monitoring profile.

SNMPv3 monitoring and traps

Send device and security events to authorized OT monitoring.

BlackPiQ can send SNMPv3 traps to configured network-management or security-monitoring systems. When authentication and privacy are enabled, SNMPv3 protects event reporting between BlackPiQ and the monitoring destination.

Administrators define SNMPv3 users, security settings, and trap targets through the management interface. The on-device trap log shows notification history for operational review and troubleshooting.

Trap targets are configured in the BlackPiQ management interface, while notification history remains available for operational review.

Live tamper response

Detect interference while it is happening.

A powered BlackPiQ combines mechanical locking with electronic tamper sensing to detect attempts to remove, disconnect, or bypass the protected controller interface. A confirmed event can trigger key sanitization, live notification, and a configured response.

BlackPiQ tamper event producing a live notification on a management workstation

Cryptographic security

Hardware-rooted protection for keys and secure sessions.

Beyond controlling who can reach the controller, BlackPiQ protects the cryptographic material used for authentication, secure management, and the encrypted IPsec conduit.

Secure Cryptographic Coprocessor

Secure cryptographic coprocessor assurance including FIPS 140-3, Common Criteria EAL4+, and TCG certification

Cryptographic assurance

Security grounded in certified cryptographic technology.

BlackPiQ uses a secure cryptographic coprocessor designed to provide hardware-rooted assurance for sensitive keys and cryptographic operations. Its underlying security foundation brings independently evaluated protections directly to the industrial controller boundary.

Hardware root of trust

Keys stay inside a hardware-protected boundary.

The Trusted Platform Module isolates stored key material and sensitive cryptographic operations from general-purpose software. Authentication credentials and the keys used by secure management and encrypted sessions remain protected within that boundary.

Four TPM-protected cryptography panels showing the TPM, stored keys, HTTPS and SSH keys, and the cryptographic boundary

Technical specifications

Compact hardware. Industrial deployment.

Designed for space-constrained cabinets and extreme operating environments.

BlackPiQ interfaces including a 24V DC female power input, host USB-C, industrial Ethernet, and locking RJ45

Asset interface

  • 10/100 Base-T Ethernet
  • Locking RJ45: Ramp & Clamp

Secure uplink

  • 10/100 Base-T Ethernet

Power

  • 24V DC: female power input
  • PoE: 802.3af Class 2 (alternative power source)

Cryptography

  • IKEv2 IPsec
  • AES-256-GCM
  • Optional post-quantum protection: ML-KEM for key establishment and LMS for digital signatures.

Management

  • Hardened browser interface
  • MFA: multi-factor authentication
  • RBAC: role-based access control
  • TACACS+ / RADIUS: centralized device authentication
  • SNMPv3: monitoring and notifications

Operating range

  • −40°C to +85°C

Dimensions

  • 2.2 in × 1 in × 1.5 in

Protect the asset edge

Bring high-assurance protection to the controller interface.

Discuss BlackPiQ fit, deployment architecture, and interoperability with Engage Black.

Engage logo 990000 rev 2.000
9565 Soquel Drive Dr,
Aptos, CA 95003
 
Telephone: +1-831-688-1021
Toll Free : +1-877-ENGAGE4
Designed, Fabricated, and Assembled
in America icon
Supported Worldwide

© 1989-2025 Engage Communication, Inc. All Rights Reserved.

Please publish modules in offcanvas position.