Security Challenges Content
OT incident response is inherently different from IT incident response due to the different devices, communication protocols, and attack techniques used by threat actors to penetrate critical infrastructure environments. With regard to industrial control systems, any sort of disruption due to cyber attacks can be more than just lost revenue and system downtime. In these types of environments, human life and environmental safety can be at risk, which is why it is important to ensure that mission-critical infrastructure is secure and running properly.
It is typical to come across legacy equipment in industrial environments due to strict restrictions on the installation of software and hardware in OEM-supported systems that operate critical processes. This means that incident response teams must be prepared with the ability to collect traffic when Layer 2 switches are unmanaged, unavailable, or potentially need to utilize media that would otherwise be considered outdated.
Key Solution Benefits Content
For Assessment and Incident Response (IR) teams to have the equipment needed to perform a variety of detection, forensics response, and recovery activities, they turn to Fly-Away Kits stocked with Garland Technology Network TAPs and Aggregators, Sealing Technologies (SealingTech) servers, Intrusion Detection Software, and other best of breed tools to ensure the team can respond to any scenario they face.
When an IR team enters an ICS environment, they can use a Fly-Away Kit to not only detect and mitigate the effects of a cyber attack but also act as a temporary SEIM solution. The hardware is designed to provide the infrastructure and computing power needed to establish a basic level of cybersecurity that can last for months rather than just a few days or weeks. This allows organizations to analyze their environments and build and deploy a comprehensive cybersecurity solution across their enterprise. In addition, the kit brings additional value as IR teams can utilize it for future IR deployments, enhance a growing network, and add extra layers of protection when required.
Garland EdgeLens Solution
Garland’s EdgeLens series is an advanced bypass TAP with built-in packet broker functionality that centralizes network traffic, making network tools more efficient by sharing network traffic with monitoring and security tools. EdgeLens provides visibility for a hybrid configuration of an active, inline network device and out-of-band tools, such as LiveAction. EdgeLens provides identical network traffic streams through the active inline device and to the capture engine of LiveAction LiveWire or LiveCapture. The benefits of both devices seeing the same traffic are:
• Correlated data for real-time monitoring and root cause analysis using network packets.
• Historical look back and playback of the network traffic.
• Validating and updating network policy changes and spotting anomalies.
• Network data recording for compliance and security forensics.
• Root cause analysis for application and network related problems.
TAP -> TOOL
Network TAP Benefits
- Provide complete packet visibility with full-duplex copies of network traffic.
- Ensure no dropped packets while passing physical errors and support jumbo frames without delay or altering the data.
- Support speeds from 10/100M, 1G, 10G, 40G, 100G, and 400G are available in single-mode and multi-mode fiber or copper ethernet.
- Available in Tap ‘Breakout,’ aggregation, regeneration, bypass, and advanced filtering.
- Passive or failsafe – Does not affect the network.
- No IP address or MAC address, and cannot be hacked.
Our passive data collection approach protects networks without adding risk or workload. Designed for OT/ICS environments, it uses Garland Technology Network TAPs for 100% network traffic access, aggregated via a Network Packet Broker. Sensors preprocess data for real-time threat analysis and offload to analytic nodes for deeper analysis. This technique allows passive asset inventory and event identification, with full packet capture ensuring responders have access to crucial metadata and full payloads for thorough forensic analysis.
Why SealingTech & Garland Technology
By partnering with SealingTech and Garland Technology you can arm your teams with innovative edge-computing solutions tailored to their unique assessment, compliance and incident response needs. Our technology has been proven in the field in some of the most demanding cybersecurity missions, and we have leveraged our expertise to develop a range of industry-leading edge computing and purpose-built network devices, ready to handle the toughest tasks and ready to be deployed anywhere a cyber operation is needed.
- Enable rapid response by IR teams with pre-configured Fly-Away Kits
- Reduce travel costs by leveraging commercial travel options
- Reduce setup time and tear down time
- Guarantee 100% network traffic with no dropped packets
- Small form factor TAPs and Aggregators allow for complete solutions
- Purpose-built technology, Made in the USA
About SealingTech

(NYSE: PSN), rapidly delivers innovative cyber security solutions that modernize, protect, and defend the networks and systems of the Federal Government and private industries. Proudly veteran-founded, SealingTech uses vast cyberspace experience and knowledge to provide cutting-edge research, engineering, and integration services that support the United States and its allies. For additional information, visit sealingtech.com.
- How It Works
- Bypass TAP Benefits
- Full PDF Solution Brief
- How It Works
- How It Works
- How It Works
Bypass manages the availability of inline tools, preventing a single point of failure in the network by “bypassing” the device in the event it fails or needs to be updated. Reducing network downtime. Bypass is unique to the other TAP modes, as it is an inline use case not out-of-band.
• Keep up with Federal security mandates
• Expedited problem resolution
• Ability to pilot or deploy need security tools
• No maintenance windows
• Simple configuration ensures a quick set-up
• Zero subscription fees so O&M expenses don’t increase
■SOLUTION EDGESAFETM BYPASS TAP
• Install a Garland Technology Bypass TAP between Cisco Firepower and the network
• Bypass TAP manages the availability of Firepower at any time without having to take down the network
• Bypass TAP continuously checks the health of Firepower with heartbeat packets and the Bypass TAP will bypass Firepower to keep the network up-and-running in the event Firepower becomes unavailable
PROBLEM 1 PORT FAILURE | ||
■WITHOUT TAP • The network |
![]()
|
■WITH TAP • Uptime • Tool is bypassed while it is being updated |
PROBLEM 1 PORT FAILURE | ||
■WITHOUT TAP • The network |
![]()
|
■WITH TAP • Uptime • Tool is bypassed while it is being replaced |