CyberDragon Core is live — indigenous SIEM/SOAR with Edge protocol capture. Start a 7-day free trial on your own traffic →
Glossary

The OT security vocabulary, without the hand-waving.

Shared language for CISOs, SOC analysts, and plant engineers evaluating industrial cyber defense.

Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now

Purdue

L0–L5 on the topology board

  • Terms on this page match the Edge topology UI.
  • Edge = L3 / industrial DMZ.
  • Telemetry up. Command into L0–L2: none.
Zone and Purdue topology
Protocol reference

What each industrial protocol exposes.

ProtocolWhere it runsWhy it matters to a defender
Modbus TCP / RTUManufacturing, water, building automationUnauthenticated register writes can change process setpoints.
DNP3Electric and water utilitiesControl commands and unsolicited responses can be spoofed without secure authentication.
OPC-UAModern IIoT and MES integrationTag harvesting and session abuse expose process structure to an attacker.
MQTTIIoT sensor fleets and edge gatewaysWildcard subscriptions leak telemetry across zones that should stay isolated.
S7commSiemens PLC estatesProgram upload and download operations are high-impact and rarely monitored.
IEC 60870-5-104European grid SCADATelecontrol commands cross the DMZ with limited native authentication.
BACnetBuilding automation and facilities OTBroadcast discovery and unauthenticated writes can affect HVAC and access-control points.
EtherNet/IP (CIP)North American manufacturing and robotics cellsCommon Industrial Protocol messages can reconfigure I/O without native authentication.

PQC

Quantum readiness terms, shipped UI

  • ML-DSA-65, Ed25519, hybrid JWT — as implemented.
  • Not a glossary-only promise.
  • See the readiness gauges.
Quantum Readiness
Purdue levels

Where CyberDragon is allowed to be.

LevelWhat lives thereCyberDragon posture
L0–L1Sensors, actuators, PLCs and safety instrumented systemsNever touched. No agents, no command plane, no active scanning.
L2HMIs, SCADA supervisory control, local historiansObserved passively through mirrored traffic only.
L3Site operations, engineering workstations, industrial DMZEdge deploys here on a SPAN port or hardware TAP.
L4–L5Enterprise enterprise, ERP, corporate identitySyslog, cloud telemetry, and identity events feed the same kill chain.

Protocols

OT parser names in the inspector

  • Modbus, DNP3, OPC-UA, MQTT.
  • Deep inspect is the screen the glossary is describing.
  • No PLC agent.
CyberDragon Protocol deep inspector
Framework shorthand

The standards named across this site.

Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
FAQ

Frequently asked questions.

Why does Purdue level matter for deployment?
It defines where collection is safe. CyberDragon Edge sits at L3 / industrial DMZ and never opens a command plane into L0–L2.
Is quantum-resilient the same as quantum-safe?
No, and we do not claim end-to-end quantum safety. Session identity tokens are hybrid-signed with ML-DSA-65 and Ed25519 today.

Start your 7-day free trial.

A dedicated CyberDragon tenant on your own traffic — not a slide deck. See kill-chain cyber defense on your network.