Security Challenges
While the convergence of IT and OT has been around for several years, there still exists a disparity between the technology, tools, and resources that are deployed in each type of network. IT teams often turn to traditional security vendors for NGFW, XDR, DDoS, and NDR tools, which don’t always work effectively in OT environments due to the different needs of SCADA and ICS systems.
On top of detection and response capabilities, GREYCORTEX brings powerful real-time network analytics that will show what is going on in networks ranging from small networks of just 100 devices to several hundreds of thousands of devices in geographically dispersed locations.
How the Solution works
The GREYCORTEX Mendel appliance sees and visualizes traffic in the context of time and events. But in order to see all the devices in a network, how they are communicating together, in the context of time and events, including L2 and L3 OT protocols and its application data, Mendel first needs complete visibility into the packets. That’s where Garland Technology comes in. Network TAPs are a tested and proven industry best practice to ensure complete network visibility for security and monitoring tools.
Garland EdgeLens Solution
Garland’s EdgeLens series is an advanced bypass TAP with built-in packet broker functionality that centralizes network traffic, making network tools more efficient by sharing network traffic with monitoring and security tools. EdgeLens provides visibility for a hybrid configuration of an active, inline network device and out-of-band tools, such as LiveAction. EdgeLens provides identical network traffic streams through the active inline device and to the capture engine of LiveAction LiveWire or LiveCapture. The benefits of both devices seeing the same traffic are:
• Correlated data for real-time monitoring and root cause analysis using network packets.
• Historical look back and playback of the network traffic.
• Validating and updating network policy changes and spotting anomalies.
• Network data recording for compliance and security forensics.
• Root cause analysis for application and network related problems.
TAP -> TOOL
Network TAP Benefits
- Provide complete packet visibility with full-duplex copies of network traffic.
- Ensure no dropped packets while passing physical errors and support jumbo frames without delay or altering the data.
- Support speeds from 10/100M, 1G, 10G, 40G, 100G, and 400G are available in single-mode and multi-mode fiber or copper ethernet.
- Available in Tap ‘Breakout,’ aggregation, regeneration, bypass, and advanced filtering.
- Passive or failsafe – Does not affect the network.
- No IP address or MAC address, and cannot be hacked.
Security Monitoring of IT + OT Infrastructure with a Single Pane of Glass
1. Within both IT and OT environments, data from the network segments are fed through Garland Technology Network TAPs mirroring the network traffic to provide 100% visibility across the environments.
2. In OT scenarios Garland commonly uses their specialized Industrial Network TAPs that are purpose-built for industrial, manufacturing, utility, and military environments.
3. Data from multiple Network TAPs are delivered to Garland’s PacketMAX™ Advanced Features to aggregate, filter, and load balance the mirrored traffic.
4. The aggregated traffic in each location is then delivered to GREYCORTEX Mendel’s sensor appliances with a central collector appliance that works both as a Network Detection and Response solution for the IT infrastructure and as an advanced industrial Intrusion Detection System (IDS) based on deep packet inspection of ICS and SCADA traffic.
Key Benefits
- Easy, simple to manage, and cost effective solution allowing the monitoring of IT, OT and IoT environments
- Gain 100% network visibility without added latency into active IT and OT asset inventory
- TAPs do not have an IP address, or MAC address and cannot be hacked
- Improve collaboration and break down silos across teams with deep visibility across all network and application layers and infrastructures
- Quick to implement within strict maintenance windows: Get the Garland and GREYCORTEX solution up and running in minutes
About GREYCORTEX

GREYCORTEX is one of the main providers of NDR (Network Detection and Response) security solutions for IT as well as OT (industrial) networks. We help organizations to make their networks secure and reliable. We dedicate our time and expertise to protecting your data, employees, and, most importantly, your business. For more information about how GREYCORTEX can protect your organization, visit greycortex.com.
Schedule Your Network Solution Call Today
- How It Works
- Bypass TAP Benefits
- Full PDF Solution Brief
- How It Works
- How It Works
- How It Works
Bypass manages the availability of inline tools, preventing a single point of failure in the network by “bypassing” the device in the event it fails or needs to be updated. Reducing network downtime. Bypass is unique to the other TAP modes, as it is an inline use case not out-of-band.
• Keep up with Federal security mandates
• Expedited problem resolution
• Ability to pilot or deploy need security tools
• No maintenance windows
• Simple configuration ensures a quick set-up
• Zero subscription fees so O&M expenses don’t increase
■SOLUTION EDGESAFETM BYPASS TAP
• Install a Garland Technology Bypass TAP between Cisco Firepower and the network
• Bypass TAP manages the availability of Firepower at any time without having to take down the network
• Bypass TAP continuously checks the health of Firepower with heartbeat packets and the Bypass TAP will bypass Firepower to keep the network up-and-running in the event Firepower becomes unavailable
PROBLEM 1 PORT FAILURE | ||
■WITHOUT TAP • The network |
![]()
|
■WITH TAP • Uptime • Tool is bypassed while it is being updated |
PROBLEM 1 PORT FAILURE | ||
■WITHOUT TAP • The network |
![]()
|
■WITH TAP • Uptime • Tool is bypassed while it is being replaced |